Subject to the terms and conditions set forth herein, Aphelion Communications Inc, Aphelion provides this Limited Warranty: Only to the person or entity that originally purchased the product from Aphelion or its authorized reseller or distributor. Limited Warranty: Aphelion warrants the hardware portion of the Aphelion...
Page 5
The customer must submit with the product as part of the claim a written description of the Hardware defect or Software non-conformance in sufficient detail to allow Aphelion to confirm the same, along with proof of purchase of the product (such as a copy of the dated purchase invoice for the product) if the product is not registered.
Page 6
Aphelion or become the property of Aphelion. Products shall be fully insured by the customer and ship back to Taiwan. Aphelion will not be held responsible for any packages that are lost in transit to Aphelion. The repaired or replaced packages will be shipped to the customer via DHL Ground or any common carrier selected by Aphelion.
Page 7
Aphelion product is connected with, loss of information or data contained in, stored on, or integrated with any product returned to Aphelion for warranty service) resulting from the use of the product, relating to warranty service, or arising out of any breach of this Limited Warranty, even if Aphelion has been advised of the possibility of such damages.
If you are a qualified distributor of Aphelion, you will be getting usernames and passwords for supporting online where you will find many useful application notes and FAQs.
This chapter describes Aphelion 600AG in brief for your applications 2.1. Features Aphelion 600AG is an outdoor intelligent sequential wireless access point (AP). With its powerful engineering design, Aphelion 600AG can form daisy chained wireless Hot Zones easily when engaging multiple Aphelion 600AGs together to meet the ever increasing needs of different network applications.
AP / AP Client / Bridge / Router Setting Support Dynamic WAN Interface assignments Provide AP/ client Operation Mode Including: Interface - Two AP Mode Application - One AP Mode and One Client Mode - Two Clients Mode Aphelion 600AG...
Page 11
802.11a : 54, 48, 36, 24, 18, 12, 9, 6Mbps, auto-fallback Rate IEEE 802.11a/b/g Mode Selection Enable / Disable Broadcast ESSID MAC Address Filtering Wireless Bandwidth Control of Wireless Client Other Setting DHCP Client / Server, Fixed IP Static Routing SNMP v1v2 Aphelion 600AG...
Page 12
DGT : 5.15 ~ 5.25GHz is not allowed to use. 5.25 ~ 5.35GHz is for indoor only. Japan : 5.15 ~ 5.35GHz for indoor only. Need to change the band to 4.9GHz. Do make sure the operation frequency of 600AG follows your local regulation. Some areas may have penalty when operating outdoor AP in a wrong frequency band.
802.11a/b/g Intelligent Sequential Outdoor Wireless AP Aphelion 600AG 802.11a/b/g Outdoor Wireless Access Point PoE Power Injector AC Power Cord IP67 Cat-5 Ethernet Cable MIL-C-5015 IP67 RS-232 Console Cable MIL-C-5015 Wall Mounting Kit & Screw Mast Mounting Kit & Screw CD: User Manual Quick Installation Guide 10.
Page 15
802.11a/b/g Intelligent Sequential Outdoor Wireless AP Top view of RF antenna connectors of 600AG RF antenna connectors are major interfaces on the top of Aphelion 600AG. They are two female N-type RF antenna connectors with special waterproof. Bottom view of power/signal connector port & console port of 600AG The port on right side of the photo is power/signal connector port.
Page 16
PDA that is running alignment / deployment tools program to analysis RF equipments. Note: Use this console connection only when configuring the Aphelion 600AG via the console. Power & Data Output Port Attach one end of the IP67 Cat-5 Ethernet cable to this port, and the other end of this Ethernet cable is to Ethernet port on the Aphelion 600AG.
Page 17
802.11a/b/g Intelligent Sequential Outdoor Wireless AP 3. AC Power Cord The AC Power Cord is to supply the 100~240V power for PoE Injector. 4. Cat-5 Ethernet cable with MIL-C-5015 connector The Cat-5 Ethernet cable with MIL-C-5015 IP67 is used to provide the path to deliver power for the outdoor unit and the data communication.
Page 18
802.11a/b/g Intelligent Sequential Outdoor Wireless AP 6. Mounting Kit The mounting kit is used to provide a good support for the outdoor unit and the flat panel antenna. Please follow the installation procedure to mount the outdoor unit and the flat panel antenna. The contents of the mounting kit are shown below.
802.11a/b/g Intelligent Sequential Outdoor Wireless AP 3.3. Outdoor Installation Aphelion 600AG can be mounted on walls or on an antenna mast as shown in the following: Step 1 Compose the holder of Aphelion 600AG Step 2 Connect the female end of the power cord into the PoE Injector, and connect the male end of the power cord into a power outlet.
Page 20
802.11a/b/g Intelligent Sequential Outdoor Wireless AP Step 5 Connect MIL-C-5015 RJ-45 Ethernet cable into MIL-C-5015 Ethernet port on the back of the access point. Step 6: Connect RS-232 Cable(Console Port cable) to serial port. Connect the other end of RS-232 (the black one or the one marked with a black dot) to a serial port on a PC for setting up initial configuration;...
Page 21
802.11a/b/g Intelligent Sequential Outdoor Wireless AP Special Notice for Waterproof Installation Most of the problems for outdoor models are from the connector connections that loosen over time due to vibration or other forces, even allowing moisture to penetrate the connector and seriously affecting the data and radio signal transmit.
This chapter introduces SMT of Aphelion 600AG 4.1. Aphelion System Menu Tree (SMT) Aphelion 600AG main menu of the system menu tree (SMT) will appear after entering correct password of Aphelion 600AG (the default password is 0000). The main menu is organized into 4 major sections:...
12. Interface Configuration SMT-12 is for configure the Ethernet interface and two wireless interfaces in Aphelion 600AG. All the physical settings of the three interfaces are configured here. Each interface can be individually enable/disable. Note the message displayed at lower left-hand corner for more information for each selection item.
Page 24
802.11a/b/g Intelligent Sequential Outdoor Wireless AP When 600AG is configured as a bridge, the IP address of 600AG is set in the Ethernet interface. Depends on the system, DHCP server and gateway can also be set in SMT-12. When 600AG is configured as a router, the interface configuration looks slightly different and its DHCP is set in SMT-23 DHCP Configuration, and the gateway is set in SMT-13 Assign WAN interface.
Page 25
802.11a/b/g Intelligent Sequential Outdoor Wireless AP The following settings can be configured for the two wireless interfaces : - Operation Mode Each interface can be set as an access point (AP) or a wireless station (also called AP client (AC)). When the interface is an AP, it accepts connection requests from wireless clients, such as wireless internet cards in PC or WiFi phones.
Page 26
Setting the packet size to activate fragmentation. Frag Threshold can be set between 1 and 2312 bytes. - Link Rate Set the data link rate for 600AG. When it is set to AUTO, 600AG will use the maximum possible link rate to transmit the data. - MAX RF Distance 600AG can adjust the TTL of packets according to the given distance to improve the communication quality.
13. Assign WAN Interface One of the three interfaces can be specified as WAN and assign gateway. For example, when Ethernet is set as WAN, 600AG can serve two Hot Spots simultaneously. This function is only available when 600AG is operating in router mode.
600AG. The new password will take in place on the next login. In the case of forgotten password, the only way to enter SMT to control 600AG is by hard resetting the 600AG to factory default, detailed in Chapter 5 of this manual.
Asymmetrical bandwidth limit specifies download and upload rate of client connections. Once the bandwidth limit is enabled, the limitation applies to all clients that connect to the 600AG. For specific client connections, Aphelion system provides a table for network administrator to limit bandwidth of each individual client by MAC address.
Lease (M) is the maximum lease time. Each Ethernet or wireless interface can be the gateway of its own subnet. Hence there can be three subnet domains in one Aphelion 600AG in routing mode. This DHCP configuration is only available when 600AG is operating in router mode.
2. Static NAT (One to One Mapping) 3. Dynamic NAT (Many to Many Mapping) 4. Single Address NAT (PAT) This configuration in only available when 600AG is operating in router mode. Port Forwarding Server sets where internal IP addresses are mapped according to the TCP or UDP port are defined in this Port Forwarding NAT sub-menu.
Page 32
802.11a/b/g Intelligent Sequential Outdoor Wireless AP Static NAT In this menu, you will be able to map internal private IP address to a global WAN IP address. Dynamic NAT A range of internal IP address can be mapped to a range of global IP address. Basic Configuration...
25. SNMP configuration SNMP is configured here for simple network management. Aphelion 600AG supports all SNMP v1, v2 and v3. Aphelion has experience working with ILECs, CLECs, WISPs and MSOs, for customized MIB requirements, please contact support@aphelions.com for assistance.
AP. - WEP Aphelion 600AG supports 64-bit, 128-bit and 152-bit WEP key in both ASCII and HEX format. Do make sure the correctly number of digits/characters and format of WEP key as shown in the table are entered. Note that in HEX format, HEX number cannot start with “0”.
Page 35
802.11a/b/g Intelligent Sequential Outdoor Wireless AP - 802.1x EAP-TLS Both 64-bit and 128-bit WEP can be set for reauthentication period up to 65535 seconds. Two Eapol (EAP over LAN) versions are available. - 802.1x EAP-MD5 WEP Key of 64-bit, 128-bit and 152-bit in both ASCII and HEX format can be set for EAP-MD5.
Page 36
802.11a/b/g Intelligent Sequential Outdoor Wireless AP Both TKIP and CCMP encryption are available for WPA-PSK. Pre-shared key of 8 to 63 characters are required. Group Rekey Interval can be set up to 65536 seconds. Two Eapol version are available. - WPA-EAP Both TKIP and CCMP encryption are available for WPA-EAP.
Page 37
802.11a/b/g Intelligent Sequential Outdoor Wireless AP - MAC Address Filtering Aphelion 600AG can control the client connection by accepting or blocking the traffic from devices of specific MAC addresses. - RADIUS RADIUS settings for 802.1x protocol authenticating with the remote RADIUS server for authenticating, authorization and accounting are set in this menu.
33. Firmware Upgrade 34. System reboot 31. Configuration management The configuration of 600AG can be backed-up or restored by using TFTP here. In a daisy chained sequential configurations, it is recommended to backup all configurations before uploading/upgrading firmware. You may name your configuration file in any ways you like.
Page 39
802.11a/b/g Intelligent Sequential Outdoor Wireless AP The configuration of Aphelion 600AG can be reset to factory default by using this menu. Basic Configuration...
Page 40
802.11a/b/g Intelligent Sequential Outdoor Wireless AP 32. Security File Management For running EAP_TLS secure connection, network administrators may need to able to upload User Certificate, Root Certificate and RSA Key file to the system. In this menu, system allowed administrators to upload these Certificate files through TFTP server to the access point.
Page 41
802.11a/b/g Intelligent Sequential Outdoor Wireless AP 33. Firmware Upgrade New firmware can be uploaded to 600AG by either TFTP or FTP. Upgrading firmware from FTP server may need username and password for login. Upgrading progress will show on the menu. Please do not shutdown the system during the upgrading process to prevent unexpected system failure.
802.11a/b/g Intelligent Sequential Outdoor Wireless AP 34. System Reboot Reboot 600AG from SMT without disconnecting power cable or changing any connection. Certain configurations require system reboot to take place, such as configuration restore. 4.5. System Monitoring SMT-41 ~ 45 provides system monitoring for 600AG. The following sections introduce each menu : 41.
Page 43
41. Interface Link Status Real-time link statuses of all interfaces are shown in the menu. - System Up Time Display how long 600AG has been operating since last boot-up. - Temperature The temperature inside the waterproof housing. - Interface Status Indicate the interface is ENABLE or DISABLE.
Since the signal level at AP is defined by the user, Signal Level is only available when the interface is set as an AC. 42. Connecting Client List MAC addresses of all clients associate with AP wireless interface on 600AG are shown here. Basic Configuration...
802.11a/b/g Intelligent Sequential Outdoor Wireless AP 43. System Log Aphelion 600AG provides seven system log levels (Level1=DEBUG Level2=EMERGENCY Level3=ALERT Level4=CRITICAL Level5=ERROR Level8=WARNING Level7=NOTICE Level8=INFO) to indicate the level of attention needed for each log. Through setting Syslog server IP address, all system log will send back to the specific log server for centralizing monitoring all Aphelion devices in the network.
802.11a/b/g Intelligent Sequential Outdoor Wireless AP 44. System Information System Information summarizes all the configuration and hardware information of the 600AG. Basic Configuration...
802.11a/b/g Intelligent Sequential Outdoor Wireless AP 45. Command Line In this menu, Aphelion System provides s few commands for network administrators doing the debug when manage. - alt Alignment tool. alt wireless AC displays the real-time Link Quality, RSSI (receive signal strength indication) and Noise Level continuously. alt is similar to the information in SMT-41, and only available when the wireless is configured as AC.
Page 48
802.11a/b/g Intelligent Sequential Outdoor Wireless AP - tracert Trace the remote destination IP address to view the routing path. - ver Display the firmware version and the minimum downgradable version of the current firm ware. - debug Enable debug mode (by typing debug 1 in command line) displays real-time syslog in command line.
LAN of 192.168.1.0/24 is used as example to demonstrate how to configure two Aphelion APs for point to point connection in bridge mode. The figure is the topology for this point to point connection with appropriate IP addresses for APs and PCs.
Page 50
IP addresses, ESSID, operation frequency and swap AP/AC. It is recommended to set MAX RF Distance when the distance between the two Aphelion 600AGs is greater than 7km. - Make sure Wireless Trunk is disabled, and Wireless 2 interface is either disable or connect to other devices.
Page 51
802.11a/b/g Intelligent Sequential Outdoor Wireless AP SMT-12 Interface Configuration AphelionA AphelionB It is recommended to confirm all the configurations are correct and properly saved by using SMT-44 System Information. If directional antennas are used for Application Notes...
802.11a/b/g Intelligent Sequential Outdoor Wireless AP this point to point application, please check if the antennas are aligned properly by using SMT-41 Interface Link Status or the command alt in SMT-45 Command Line. Router Mode When using point to point to connect two LANs together, router mode configuration is required.
Page 53
AP/AC. It is recommended to set MAX RF Distance when the distance between the two Aphelion 600AGs is greater than 7km. - Aphelion 600AG is set as a router, so each interface (Ethernet and wireless) needs to have its own IP addresses.
Page 54
802.11a/b/g Intelligent Sequential Outdoor Wireless AP SMT-13 Interface Configuration AphelionA AphelionB It is recommended to confirm all the configurations are correct and properly saved by using SMT-44 System Information. If directional antennas are used for this point to point application, please check if the antennas are aligned properly by using SMT-41 Interface Link Status or the command alt in SMT-45 Command Line.
600AG back to factory default without entering SMT, there is a reset button on the PCB inside the waterproof housing for hard reset. The reset button can be pressed any time after 600AG has enabled all the interface and shows “Enable interface ath1” on the boot log when accessing 600AG with console.
“ver” in SMT-45 Command Line. The easiest way to upgrade Aphelion 600AG is through the use of SMT and Trivial File Transfer Protocol (TFTP). A PC is made as the TFTP server, and connected to Aphelion AP via the DATA IN port on the PoE unit.
Page 57
802.11a/b/g Intelligent Sequential Outdoor Wireless AP demonstrate the upgrade procedure with TFTP. The IP address and subnet mask of PC can be either configured through Internet Protocol (TCP/IP) selection in Network Neighborhood or your usual way. The AP is configured to 192.168.0.2 with subnet mask of 255.255.255.0...
Page 58
802.11a/b/g Intelligent Sequential Outdoor Wireless AP Enter the IP address of the TFTP server, 192.168.0.1 and the firmware image file 600-v0_982.img in the fields indicated in the circles. Do use the exact file name because it is case sensitive. Move the cursor to the last selection “Upgrade new firmware? “...
Page 59
802.11a/b/g Intelligent Sequential Outdoor Wireless AP system backup. Please be patient and keep the power on all the time until the SMT main menu appear on the screen. If the upgrade is unsuccessful, the following upgrade new firmware fail message will appear.
802.11a/b/g Intelligent Sequential Outdoor Wireless AP Appendix I. Antenna concepts and Installations I.1. Basic Terminology - Transmit Power The RF power coming out of the antenna port of a transmitter. It excludes the signal loss of the coaxial cable or the gain of the antenna, and is measured in dBm, Watts or milli-Watts - Receiver Sensitivity The weakest RF signal level (usually in negative dBm) that a radio needs to...
A larger Fade Margin indicates a stronger signal for connection, and a negative Fade Margin indicates connection fail. Here is an example of Aphelion 600G with 12 dBi antenna (neglect the cable loss in this case). From the specification of Aphelion 600AG :...
802.11a/b/g Intelligent Sequential Outdoor Wireless AP II. Wireless Security Concept II.1. Security for 802.11 Network Security for 802.11 networks can be simplified into two main components: authentication and encryption. WEP (Wired Equivalent Privacy) is part of the system security of 802.11, and its goals are to provide confidentiality and data integrity, and to protect access to the network infrastructure by rejecting all non-WEP packets.
802.11a/b/g Intelligent Sequential Outdoor Wireless AP Transport Layer Security (EAP-TLS) or EAP Tunneled Transport Layer Security (EAP-TTLS), which defines how t he authentication takes place. The software supporting the specific EAP type resides on the authentication server and within the operating system or application software on the client devices.
802.11a/b/g Intelligent Sequential Outdoor Wireless AP A typical use for EAP-MD5 CHAP is to authenticate the credentials of remote access clients by using user name and password security systems. You can also use EAP-MD5 CHAP to test EAP interoperability. - LEAP (Cisco Lightweight EAP) Cisco LEAP is a mutual authentication algorithm that supports dynamic derivation of session keys.
Page 65
802.11a/b/g Intelligent Sequential Outdoor Wireless AP telecommunication networks. In large networks, security information can be scattered throughout the network on different devices. RADIUS allows user information to be stored on one host, minimizing the risk of security loopholes. All authentication and access to network services is managed by the host functioning as the RADIUS server.
Need help?
Do you have a question about the 600AG and is the answer not in the manual?
Questions and answers