Setup guide
• connection time
• downloaded/uploaded traffic (bytes)
Universal Client feature may be used with HotSpot enabled-address method to provide IP network
services regardless of client computers' IP network settings
Specifications
Packages required: hotspot, dhcp (optional)
License required: level1 (Limited to 1 active user), level3 (Limited to 1 active user), level4
(Limited to 200 active users), level5 (Limited to 500 active users), level6
ip hotspot
Standards and Technologies: ICMP, DHCP
Hardware usage: Not significant
Related Documents
• Package Management
• IP Addresses and ARP
• IP Pools
• DHCP Client and Server
• AAA
• Firewall Filters
• Packet Marking (Mangle)
• Network Address Translation
• Connection Tracking and Service Ports
Description
Wandy HotSpot Gateway should have at least two network interfaces:
1. HotSpot interface, which is used to connect HotSpot clients
2. LAN/WAN interface, which is used to access network resources. For example, DNS and
RADIUS server(s) should be accessible
The diagram below shows a sample HotSpot setup.
The HotSpot interface should have an IP address assigned to it. To use dhcp-pool method, there
should be two IP addresses: one as the gateway for the temporary IP address pool used prior to
authentication, and second as the gateway for the permanent IP address pool used by authenticated
clients. Note, that you have to provide routing for these address pools, unless you plan to use
masquerading (source NAT). Physical network connection has to be established between the
HotSpot user's computer and the gateway. It can be wireless (the wireless card should be registered
to AP), or wired (the NIC card should be connected to a hub or a switch).
In dhcp-pool case, the arp mode of the HotSpot interface should be set to reply-only to prevent
network access using static IP addresses (the DHCP server should add static ARP entries for each
DHCP client). Note also that Universal Client feature can not be used with dhcp-pool method.
Introduction to HotSpot
HotSpot is a way to authorize users to access some network resources. It does not provide traffic
encryption. To log in, users may use almost any web browser (either HTTP or HTTPS protocol), so
they are not required to install additional software. The gateway is accounting the uptime and