Subject to the terms and conditions set forth herein, Aphelion Communications Inc, Aphelion provides this Limited Warranty: Only to the person or entity that originally purchased the product from Aphelion or its authorized reseller or distributor. Limited Warranty: Aphelion warrants the hardware portion of the Aphelion...
Page 5
The customer must submit with the product as part of the claim a written description of the Hardware defect or Software non-conformance in sufficient detail to allow Aphelion to confirm the same, along with proof of purchase of the product (such as a copy of the dated purchase invoice for the product) if the product is not registered.
Page 6
Aphelion or become the property of Aphelion. Products shall be fully insured by the customer and ship back to Taiwan. Aphelion will not be held responsible for any packages that are lost in transit to Aphelion. The repaired or replaced packages will be shipped to the customer via DHL Ground or any common carrier selected by Aphelion.
Page 7
Aphelion product is connected with, loss of information or data contained in, stored on, or integrated with any product returned to Aphelion for warranty service) resulting from the use of the product, relating to warranty service, or arising out of any breach of this Limited Warranty, even if Aphelion has been advised of the possibility of such damages.
If you are a qualified distributor of Aphelion, you will be getting usernames and passwords for supporting online where you will find many useful application notes and FAQs.
This chapter describes Aphelion 500AG in brief for your applications 2.1. Features Aphelion 500AG is a multi-functional outdoor wireless AP bridge in which it can be deployed either as standalone mode or as an access point client. This 5GHz and 2.4GHz wireless bridge conforms to IEEE802.11 a/b/g standards and provides a highly reliable wireless point-to-point network solution for distant locations or a point-to-multipoint bridge.
Page 11
SNMP v1v2 SSID Support Enable / Disable Broadcast Support 64bit / 128bit /152bit Data Encryption Wireless Authentication type: Open System / Shared Key Security 802.1x Support 802.1x Client and Server RADIUS Support RADIUS Client Support MAC Address Filtering Aphelion 500AG...
Page 12
DGT : 5.15 ~ 5.25GHz is not allowed to use. 5.25 ~ 5.35GHz is for indoor only. Japan : 5.15 ~ 5.35GHz for indoor only. Need to change the band to 4.9GHz. Do make sure the operation frequency of 500AG follows your local regulation. Some areas may have penalty when operating outdoor AP in a wrong frequency band.
802.11a/b/g Multi-functional Outdoor Wireless AP Aphelion 500AG 802.11a/b/g Outdoor Wireless Access Point PoE Power Injector AC Power Cord IP67 Cat-5 Ethernet Cable MIL-C-5015 IP67 RS-232 Console Cable MIL-C-5015 Wall Mounting Kit & Screw Mast Mounting Kit & Screw CD: User Manual Quick Installation Guide 10.
Page 15
802.11a/b/g Multi-functional Outdoor Wireless AP Top view of RF antenna connectors of 500AG RF antenna connector is a major interface on the top of Aphelion 500AG. It is a female N-type RF antenna connector with special waterproof. Bottom view of power/signal connector port & console port of 500AG The port on right side of the photo is power/signal connector port.
Page 16
Alignment / Deployment tools program technicians analysis equipments. Note: Use this console connection only if you are configuring the Aphelion 500AG via the console. Power & Data Output Port Attach one end of the IP67 Cat-5 Ethernet cable to this port;...
Page 17
802.11a/b/g Multi-functional Outdoor Wireless AP 3. AC Power Cord The AC Power Cord is to supply the 100~240V power for PoE Power Injector. 4. Cat-5 Ethernet cable with MIL-C-5015 connector The Cat-5 Ethernet cable with MIL-C-5015 IP67 is used to provide the path to deliver power for the outdoor unit and the data communication.
Page 18
802.11a/b/g Multi-functional Outdoor Wireless AP 6. Mounting Kit The mounting kit is used to provide a good support for the outdoor unit and the flat panel antenna. Please follow the installation procedure to mount the outdoor unit and the flat panel antenna. The contents of the mounting kit are shown below.
802.11a/b/g Multi-functional Outdoor Wireless AP 3.3. Outdoor Installation Aphelion 500AG can be mounted on the wall or an antenna mast as shown in the following: Step 1 Compose the holder of Aphelion 500AG Step 2 Connect the female end of the power cord into the PoE Injector, and then connect the male end of the power cord into a power outlet.
Page 20
802.11a/b/g Multi-functional Outdoor Wireless AP Step 5 Connect MIL-C-5015 RJ-45 Ethernet cable into MIL-C-5015 Ethernet port at the bottom of the access point. Step 6: Connect RS-232 Cable(Console Port cable) to the Serial Port. Connect the other end of RS-232 (the black one or the one marked with a black dot)...
Page 21
802.11a/b/g Multi-functional Outdoor Wireless AP Special Notice for Waterproofing Installation Most of the problems for outdoor models are from connector connections that loosen over time due to vibration or other forces, even allowing moisture to penetrate the connector and seriously affecting the data and radio signal transmit.
This chapter introduces SMT of Aphelion 500AG 4.1. Aphelion System Menu Tree (SMT) Aphelion 500AG main menu of the system menu tree (SMT) will appear after entering correct password of Aphelion 500AG (the default password is 0000). The main menu is organized into four major sections:...
12. Interface Configuration SMT-12 is for configure the Ethernet interface and wireless interface in Aphelion 500AG. All the physical settings of both interfaces are configured here. Each interface can be individually enable/disable. Note the message displayed at lower left-hand corner for more information for each selection item.
Page 24
802.11a/b/g Multi-functional Outdoor Wireless AP When 500AG is configured as a bridge, the IP address of 500AG is set in the Ethernet interface. Depends on the system, DHCP server and gateway can also be set in SMT-12. When 500AG is configured as a router, the interface configuration looks slightly different and its DHCP is set in SMT-23 DHCP Configuration, and the gateway is set in SMT-13 Assign WAN interface.
Page 25
Setting the packet size to activate fragmentation. Frag Threshold can be set between 1 and 2312 bytes. - Link Rate Set the data link rate for 500AG. When it is set to AUTO, 500AG will use the maximum possible link rate to transmit the data. Basic Configuration...
802.11a/b/g Multi-functional Outdoor Wireless AP - MAX RF Distance 500AG can adjust the TTL of packets according to the given distance to improve the communication quality. It is recommended to set MAX RF Distance when the distance of point to point connection is greater than 7km.
802.11a/b/g Multi-functional Outdoor Wireless AP 14. Routing Configuration Up to 12 rules of static routes can be configured here. 4.3. Advanced Setting Under advanced settings, you will be able to configure the following: 21. System Password 22. Bandwidth Control 23. DHCP Configuration 24.
500AG. The new password will take in place on the next login. In the case of forgotten password, the only way to enter SMT to control 500AG is by hard resetting the 500AG to factory default, detailed in Chapter 5 of this manual.
Aphelion 500AG. Symmetrical bandwidth limit consolidates download and upload rate of each single client connection. Asymmetrical bandwidth limit specifies download and upload rate of client connections. Once the bandwidth limit is enabled, the limitation applies to all clients that connect to the 500AG. Basic Configuration...
Lease (M) is the maximum lease time. Each Ethernet or wireless interface can be the gateway of its own subnet. Hence there can be three subnet domains in one Aphelion 500AG in routing mode. This DHCP configuration is only available when 500AG is operating in router mode.
2. Static NAT (One to One Mapping) 3. Dynamic NAT (Many to Many Mapping) 4. Single Address NAT (PAT) This configuration in only available when 500AG is operating in router mode. Port Forwarding Server sets where internal IP addresses are mapped according to the TCP or UDP port are defined in this Port Forwarding NAT sub-menu.
Page 32
802.11a/b/g Multi-functional Outdoor Wireless AP Static NAT In this menu, you will be able to map internal private IP address to a global WAN IP address. Dynamic NAT A range of internal IP address can be mapped to a range of global IP address. Basic Configuration...
25. SNMP configuration SNMP is configured here for simple network management. Aphelion 500AG supports all SNMP v1, v2 and v3. Aphelion has experience working with ILECs, CLECs, WISPs and MSOs, for customized MIB requirements, please contact support@aphelions.com for assistance.
AP. - WEP Aphelion 500AG supports 64-bit, 128-bit and 152-bit WEP key in both ASCII and HEX format. Do make sure the correctly number of digits/characters and format of WEP key as shown in the table are entered. Note that in HEX format, HEX number cannot start with “0”.
Page 35
802.11a/b/g Multi-functional Outdoor Wireless AP - 802.1x EAP-TLS Both 64-bit and 128-bit WEP can be set for reauthentication period up to 65535 seconds. Two Eapol (EAP over LAN) versions are available. - 802.1x EAP-MD5 WEP Key of 64-bit, 128-bit and 152-bit in both ASCII and HEX format can be set for EAP-MD5.
Page 36
802.11a/b/g Multi-functional Outdoor Wireless AP - WPA-PSK Both TKIP and CCMP encryption are available for WPA-PSK. Pre-shared key of 8 to 63 characters are required. Group Rekey Interval can be set up to 65536 seconds. Two Eapol version are available. - WPA-EAP Both TKIP and CCMP encryption are available for WPA-EAP.
Page 37
802.11a/b/g Multi-functional Outdoor Wireless AP - MAC Address Filtering Aphelion 500AG can control the client connection by accepting or blocking the traffic from devices of specific MAC addresses. - RADIUS RADIUS settings for 802.1x protocol authenticating with the remote RADIUS server for authenticating, authorization and accounting are set in this menu.
33. Firmware Upgrade 34. System reboot 31. Configuration management The configuration of 500AG can be backed-up or restored by using TFTP here. In a daisy chained sequential configurations, it is recommended to backup all configurations before uploading/upgrading firmware. You may name your configuration file in any ways you like.
Page 39
802.11a/b/g Multi-functional Outdoor Wireless AP The configuration of Aphelion 500AG can be reset to factory default by using this menu. Basic Configuration...
Page 40
802.11a/b/g Multi-functional Outdoor Wireless AP 32. Security File Management For running EAP_TLS secure connection, network administrators may need to able to upload User Certificate, Root Certificate and RSA Key file to the system. In this menu, system allowed administrators to upload these Certificate files through TFTP server to the access point.
Page 41
802.11a/b/g Multi-functional Outdoor Wireless AP 33. Firmware Upgrade New firmware can be uploaded to 500AG by either TFTP or FTP. Upgrading firmware from FTP server may need username and password for login. Upgrading progress will show on the menu. Please do not shutdown the system during the upgrading process to prevent unexpected system failure.
802.11a/b/g Multi-functional Outdoor Wireless AP 34. System Reboot Reboot 500AG from SMT without disconnecting power cable or changing any connection. Certain configurations require system reboot to take place, such as configuration restore. 4.5. System Monitoring SMT-41 ~ 45 provides system monitoring for 500AG. The following sections introduce each menu : 41.
Page 43
41. Interface Link Status Real-time link statuses of all interfaces are shown in the menu. - System Up Time Display how long 500AG has been operating since last boot-up. - Temperature The temperature inside the waterproof housing. - Interface Status Indicate the interface is ENABLE or DISABLE.
Since the signal level at AP is defined by the user, Signal Level is only available when the interface is set as an AC. 42. Connecting Client List MAC addresses of all clients associate with AP wireless interface on 500AG are shown here. Basic Configuration...
802.11a/b/g Multi-functional Outdoor Wireless AP 43. System Log Aphelion 500AG provides seven system log levels (Level1=DEBUG Level2=EMERGENCY Level3=ALERT Level4=CRITICAL Level5=ERROR Level8=WARNING Level7=NOTICE Level8=INFO) to indicate the level of attention needed for each log. Through setting Syslog server IP address, all system log will send back to the specific log server for centralizing monitoring all Aphelion devices in the network.
802.11a/b/g Multi-functional Outdoor Wireless AP 44. System Information System Information summarizes all the configuration and hardware information of the 500AG. Basic Configuration...
802.11a/b/g Multi-functional Outdoor Wireless AP 45. Command Line In this menu, Aphelion System provides s few commands for network administrators doing the debug when manage. - alt Alignment tool. alt wireless AC displays the real-time Link Quality, RSSI (receive signal strength indication) and Noise Level continuously. alt is similar to the information in SMT-41, and only available when the wireless is configured as AC.
Page 48
802.11a/b/g Multi-functional Outdoor Wireless AP - ver Display the firmware version and the minimum downgradable version of the current firm ware. - debug Enable debug mode (by typing debug 1 in command line) displays real-time syslog in command line. - dfs Dynamic Frequency Selection is to avoid the AP using the same channel as military radars.
LAN of 192.168.1.0/24 is used as example to demonstrate how to configure two Aphelion APs for point to point connection in bridge mode. The figure is the topology for this point to point connection with appropriate IP addresses for APs and PCs.
Page 50
- This is an example for point to point configuration. Depends on your system, you may use different IP addresses, ESSID, operation frequency and swap AP/AC. It is recommended to set MAX RF Distance when the distance between the two Aphelion 500AGs is greater than 7km. Application Notes...
Page 51
802.11a/b/g Multi-functional Outdoor Wireless AP SMT Configuration Step by Step SMT-11 System General Setup AphelionA AphelionB SMT-12 Interface Configuration AphelionA AphelionB Application Notes...
802.11a/b/g Multi-functional Outdoor Wireless AP It is recommended to confirm all the configurations are correct and properly saved by using SMT-44 System Information. If directional antennas are used for this point to point application, please check if the antennas are aligned properly by using SMT-41 Interface Link Status or the command alt in SMT-45 Command Line.
Page 53
AP/AC. It is recommended to set MAX RF Distance when the distance between the two Aphelion 500AGs is greater than 7km. - Aphelion 500AG is set as a router, so each interface (Ethernet and wireless) needs to have its own IP addresses.
Page 54
802.11a/b/g Multi-functional Outdoor Wireless AP SMT Configuration Step by Step SMT-11 System General Setup AphelionA AphelionB SMT-12 Interface Configuration AphelionA AphelionB SMT-13 Interface Configuration AphelionA AphelionB Application Notes...
5.2. Hard Reset to Factory Default In the case of forgotten system password or any other situations that require setting 500AG back to factory default without entering SMT, there is a reset button on the PCB inside the waterproof housing for hard reset.
802.11a/b/g Multi-functional Outdoor Wireless AP The reset button can be pressed any time after 500AG has enabled all the interface and shows “Enable interface ath0” on the boot log when accessing 500AG with console. 5.3. Firmware Upgrade As Aphelion always strives to achieve total customer satisfaction, new features and functions are designed from time to time.
Page 57
802.11a/b/g Multi-functional Outdoor Wireless AP The easiest way to upgrade Aphelion 500AG is through the use of SMT and Trivial File Transfer Protocol (TFTP). A PC is made as the TFTP server, and connected to Aphelion AP via the DATA IN port on the PoE unit.
Page 58
802.11a/b/g Multi-functional Outdoor Wireless AP Use the space bar to move the cursor. Press ESC and save the change before exit SMT-12. Make sure the firmware image file, for example 500-v0_982.img, is in your TFTP upload/download directory. Then go to SMT-33 Firmware Upgrade. Enter the IP address of the TFTP server, 192.168.0.1 and the firmware image file...
Page 59
802.11a/b/g Multi-functional Outdoor Wireless AP After the firmware has downloaded to the AP successfully, a message will show at the bottom of the screen indicating the percentage of the upgrading. Please follow the instruction to reboot the AP to make the new firmware take place.
Page 60
802.11a/b/g Multi-functional Outdoor Wireless AP Please press “N” to make the cursor active again. Double check if the TFTP server is up and set in the same net scope with the AP. Also check if the firmware image file is in the appropriate directory and all the fields in SMT-33 are entered correctly.
802.11a/b/g Multi-functional Outdoor Wireless AP Appendix I. Antenna concepts and Installations I.1. Basic Terminology - Transmit Power The RF power coming out of the antenna port of a transmitter. It excludes the signal loss of the coaxial cable or the gain of the antenna, and is measured in dBm, Watts or milli-Watts - Receiver Sensitivity The weakest RF signal level (usually in negative dBm) that a radio needs to...
A larger Fade Margin indicates a stronger signal for connection, and a negative Fade Margin indicates connection fail. Here is an example of Aphelion 600G with 12 dBi antenna (neglect the cable loss in this case). From the specification of Aphelion 500AG :...
802.11a/b/g Multi-functional Outdoor Wireless AP II. Wireless Security Concept II.1. Security for 802.11 Network Security for 802.11 networks can be simplified into two main components: authentication and encryption. WEP (Wired Equivalent Privacy) is part of the system security of 802.11, and its goals are to provide confidentiality and data integrity, and to protect access to the network infrastructure by rejecting all non-WEP packets.
802.11a/b/g Multi-functional Outdoor Wireless AP The software supporting the specific EAP type resides on the authentication server and within the operating system or application software on the client devices. The AP acts as a "pass through" for 802.1x messages, which means that you can specify any EAP type without needing to upgrade an 802.1x- compliant AP.
802.11a/b/g Multi-functional Outdoor Wireless AP A typical use for EAP-MD5 CHAP is to authenticate the credentials of remote access clients by using user name and password security systems. You can also use EAP-MD5 CHAP to test EAP interoperability. - LEAP (Cisco Lightweight EAP) Cisco LEAP is a mutual authentication algorithm that supports dynamic derivation of session keys.
Page 66
802.11a/b/g Multi-functional Outdoor Wireless AP telecommunication networks. In large networks, security information can be scattered throughout the network on different devices. RADIUS allows user information to be stored on one host, minimizing the risk of security loopholes. All authentication and access to network services is managed by the host functioning as the RADIUS server.
Need help?
Do you have a question about the 500AG and is the answer not in the manual?
Questions and answers