ProSafe 16 AP Wireless Management System WMS5316 Reference Manual 350 East Plumeria Drive San Jose, CA 95134 USA October 2011 202-10601-04 v1.
ProSafe 16 AP Wireless Management System WMS5316 ©2011 NETGEAR, Inc. All rights reserved No part of this publication may be reproduced, transmitted, transcribed, stored in a retrieval system, or translated into any language in any form or by any means without the written permission of NETGEAR, Inc. Technical Support Thank you for choosing NETGEAR.
Table of Contents Chapter 1 Getting Started Logging In . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 Basic System Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 General Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 Time Settings. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9 IP Settings . . . . . . . . . . . .
ProSafe 16 AP Wireless Management System WMS5316 Guest Access Show . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35 Chapter 5 Monitoring Monitoring Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37 Access Point Status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37 Rogue Access Points . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37 Wireless Stations . . . . . . .
ProSafe 16 AP Wireless Management System WMS5316 Diagnostic Ping Screen . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .61 Using Discovery OUI . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .62 Appendix A Access Point Firmware Compatibility Compatible Access Point Supported Firmware Versions . . . . . . . . . . . . . .63 Controller Features and Access Point Compatibility . . . . . . . . . . . . . . . . .
1. Getting Started 1 The ProSafe 16 AP Wireless Management System WMS5316 allows you to manage up to 16 NETGEAR wireless access points on a LAN. You can use the wireless management system to: • Discover NETGEAR access points on the LAN. • Optimize wireless access point performance with centralized RF management, QoS, and load balancing. • Streamline security configuration tasks and set up guest access. • Monitor network usage.
ProSafe 16 AP Wireless Management System WMS5316 Logging In Note: For help installing the Wireless Management System, see the Installation Guide included in the package and on the Resource CD. To log in to the wireless management system you have to use a computer that is configured with a static IP address of 192.168.0.210 and a subnet mask of 255.255.255.0. Connect the computer to a LAN port on the wireless management system with an Ethernet cable. To log in: 1.
ProSafe 16 AP Wireless Management System WMS5316 Basic System Settings When you log in, the Configuration tab displays General Settings. General Settings To navigate to this screen, on the Configuration tab select System > Basic > General: The General Settings screen lets you configure the basic settings of your wireless management system. • Name: This unique value indicates the wireless management system name. By default, the name is wms5316.
ProSafe 16 AP Wireless Management System WMS5316 Time Settings On the Configuration tab, select System > Basic > Time Settings: This screen lets you configure the time-related settings of your wireless management system and managed access points. It has the following options: • Time Zone: Select the local time zone for your region or country. • Current Time: The current time at your location.
ProSafe 16 AP Wireless Management System WMS5316 • IP Subnet Mask: Enter the subnet mask value used on your LAN. The default value is 255.255.255.0. • Default Gateway: Enter the IP address of the gateway for your LAN. • Primary DNS Server: Enter the IP address of the primary Domain Name Server (DNS) that you want to use. • Secondary DNS Server: Enter the IP address of the secondary DNS that you want to use.
ProSafe 16 AP Wireless Management System WMS5316 Note: The untagged VLAN check box should be cleared only if the hubs or switches on your LAN support the VLAN (802.1Q) standard. Likewise, the untagged VLAN value should be changed only if the hubs and switches on your LAN support the VLAN (802.1Q) standard. Changing either of these values will result in a loss of IP connectivity if the hubs and switches on your network have not yet been configured with the corresponding VLANs.
ProSafe 16 AP Wireless Management System WMS5316 • VLAN: Enter the DHCP server VLAN ID. The range is between 1 and 4094. The DHCP server will service this VLAN. • IP Address: The IP address for the wireless management system in the specified VLAN; when the Use VLAN Interface check box is not selected, the wireless management system management IP/VLAN is used. • Subnet Mask: The subnet mask that will be assigned to the wireless clients by the DHCP server.
2. Access Point Discovery 2 You can discover supported NETGEAR access points on the LAN that can be managed by the wireless management system. See Appendix A, Access Point Firmware Compatibility for a list of compatible access points. The wireless management system supports Auto Discovery and IP Discovery. • Auto Discovery: Use this feature if the wireless management system and all access points on the LAN are in the same IP subnet. This is a Layer 2 discovery method.
ProSafe 16 AP Wireless Management System WMS5316 Auto Discovery Use Auto Discovery if the wireless management system and all access points on the LAN are in the same IP subnet. The process of Auto Discovery depends on how your access points are configured. To use Auto Discovery: 1. On the Configuration tab select Access Point Discovery. 2. Click Search. • The wireless management system searches for NETGEAR products on the LAN based on MAC address, and then identifies which are access points.
ProSafe 16 AP Wireless Management System WMS5316 IP Discovery Use IP Discovery to discover access points in a different IP network from the wireless management system. You can search for a maximum of 255 IP addresses at a time. NETGEAR recommends that you split up your search if you have access points in multiple networks. To use IP Discovery: 1. On the Configuration tab select Access Point Discovery, and then click the IP Discovery tab: 2.
ProSafe 16 AP Wireless Management System WMS5316 • If discovery results show unknown access points, it could be due to these reasons: - The access point is running an older version of firmware. Upgrade firmware as needed so that discovery can locate the access point. - The wireless management system located a NETGEAR access point that is not supported or located a NETGEAR device that is not an access point.
3. Wireless Configuration 3 You can configure centralized RF management and specify wireless settings in the Basic RF Management screen. If you use access point groups, you can use the Advanced Wireless Settings screen to customize wireless settings for each group.
ProSafe 16 AP Wireless Management System WMS5316 Configuring Centralized RF Management In this screen you can specify RF management settings. RF management, when run, optimizes the channel allocation for access points based on clients, user data traffic, and observed nearby RF environment of access points. 1. On the Configuration tab, select Wireless to display the following screen: 2. Specify the centralized RF management: • Centralized RF Management: The enable radio button is selected by default.
ProSafe 16 AP Wireless Management System WMS5316 point that supports wireless-n mode run in b/g mode in order to support clients that do not support wireless n technology. • 2.4GHz or 5GHz band selection: This selection affects only dual band access points that can be set to only one band at a time. You can use this field to specify which band the access point should use. Note: For dual concurrent access points, both radio modes are enabled by default. 4. Click Apply so that your changes take effect.
ProSafe 16 AP Wireless Management System WMS5316 4. Click Apply so that your changes take effect. Table 1. Advanced Wireless Settings Feature Setting Turn Radio On Disable this option to disable wireless access for the selected mode. To disable all wireless access through this access point, you have to turn off the 802.11b/g/n, as well as the 802.11a/n radios. Wireless Mode Specify the wireless mode for the access points.
ProSafe 16 AP Wireless Management System WMS5316 Table 1. Advanced Wireless Settings (continued) Feature Setting RIFS Transmission (11n only) Enable the Reduced Interframe Space (RIFS) option to allow transmission of successive frames at different transmit powers. Enabling RIFS can lead to better network performance. Enable Wi-Fi MultiMedia (WMM) Select this check box to ensure that applications that require better throughput and performance are provided special queues with higher priority.
ProSafe 16 AP Wireless Management System WMS5316 QoS for Managed Access Points To specify QoS settings: 1. On the Configuration tab select Wireless > Basic > QoS Settings: 2. Select the Apply to all groups check box to apply the settings to all managed access points. 3. Select either the 802.11b/bg/ng or 802.11a/na tab. 4. Enable the Wi-Fi MultiMedia (WMM) and WMM Powersave options. 5. Click Apply.
ProSafe 16 AP Wireless Management System WMS5316 Load Balancing Load balancing allows the wireless management system to distribute access point clients equally among access points. These settings are applied only to managed NETGEAR ProSafe access points that support load balancing. See Controller Features and Access Point Compatibility on page 63 for more information about which access points models support this feature.
ProSafe 16 AP Wireless Management System WMS5316 Advanced Load Balancing for Access Point Groups On the Configuration tab select Wireless > Advanced > Load Balancing: • Enable Load Balancing: Select this check box to allow the wireless management system to distribute access point clients equally among access points. • Max Clients per Access Point: The maximum number of wireless clients that can connect to the access point at one time.
4.
ProSafe 16 AP Wireless Management System WMS5316 Security Profiles Lists Details of each wireless network are contained in a security profile. You can use the basic profile settings for access points, or the advanced profile settings for access point groups. Security Profiles List for Access Points This screen lets you edit up to eight security profiles per managed access point, depending on the number of profiles each access point supports. Separate profiles are applied to 802.11 b/bg/ng and 802.
ProSafe 16 AP Wireless Management System WMS5316 Editing a Security Profile To edit a security profile, select it on the Profile Settings screen, and then click Edit to go to the Edit Security Profile screen: • Name: A unique name for the security profile, up to 32 alphanumeric characters. Use meaningful names instead of the default names. The default profile names are Profile1, Profile2, and so on. • Wireless Network Name (SSID): The name of the wireless network associated with this profile.
ProSafe 16 AP Wireless Management System WMS5316 The following table shows the data encryption options based on network authentication. Network Authentication Data Encryption Description Open None. WEP. No encryption. Shared Key WEP. • 64-bit WEP encryption uses 40/64 bit encryption. • 128-bit WEP encryption uses 104/128 bit encryption. • 152-bit WEP is a proprietary mode that works only with other wireless devices that support this mode. Legacy 802.
ProSafe 16 AP Wireless Management System WMS5316 To view or change security profiles for a specific access point group: 1. On the Configuration tab select Security > Advanced > Profile Settings: 2. Each security profile specifies: • Profile Name: The unique profile name. This value can be up to 31 alphanumeric characters. • SSID: The SSID associated with this profile. • Security: The security standard, such as WPA-PSK, associated with the profile.
ProSafe 16 AP Wireless Management System WMS5316 To detect rogue access points: 1. On the Configuration tab select Security > Basic > Rogue Access Points: The wireless management system can support up to 512 total rogue access points from the Known and Unknown lists combined. 2. Enter the following information: • Import AP List from a file: This field allows you to import a list of approved access points from a saved file. This file has to be a simple text file with one MAC address per line.
ProSafe 16 AP Wireless Management System WMS5316 MAC Authentication for Access Points To set up MAC authentication: 1. On the Configuration tab, select Security > Basic > MAC Authentication: A maxiumum of 512 MAC addresses can be supported. 2. Select the Apply to all groups check box to apply the settings to all managed access points regardless of group. 3.
ProSafe 16 AP Wireless Management System WMS5316 Advanced MAC Authentication for Access Point Groups This lets you block network access privilege of the specified stations through a specific group of managed wireless access points. Note: Most networks do not require access point groups. See Chapter 1, Getting Started for more information about basic settings and advanced settings for access point groups. To set up MAC authentication for only the selected access point group: 1.
ProSafe 16 AP Wireless Management System WMS5316 - To move a wireless station from the Available Wireless Stations list to the Trusted Wireless Stations list, select it, and click Move. 6. Click Apply so that your changes take effect. Radius Server Settings If you are using a RADIUS server in your network for authentication, you have to configure Radius settings.
ProSafe 16 AP Wireless Management System WMS5316 4. Enter the authentication settings. • Re-authentication Time (Seconds): This is the time interval in seconds after which the supplicant will be authenticated again with the RADIUS server. The default interval is 3600 seconds. • Update Global Key Every (Seconds): Enable this option to have the global key changed according to the time interval specified. If enabled, enter the time interval you want to use. This option is enabled by default.
ProSafe 16 AP Wireless Management System WMS5316 3. Click Apply so that your changes take effect. Guest Access Show When guest access is configured, the wireless management system redirects the first HTTP (TCP, port 80) request to the default guest access screen. The last 512 IP accesses and entered email address are recorded. This screen displays the collected information.
5.
ProSafe 16 AP Wireless Management System WMS5316 Monitoring Summary This screen displays a read-only summary of the current managed access point status, rogue access points detected, current wireless stations connected, wireless management system information, and network usage. Clicking the individual sections leads to a new screen showing greater detail. Access Point Status This section displays status of managed access points. • Total Configured: Total number of managed access points.
ProSafe 16 AP Wireless Management System WMS5316 Wireless Stations This section displays the count of the wireless stations currently associated with managed access points. • open: Wireless stations connected to managed access points using security profiles configured with open mode. • wep: Wireless stations connected to managed access points using security profiles configured with WEP. • wpa: Wireless stations connected to managed access points using security profiles configured with WPA security.
ProSafe 16 AP Wireless Management System WMS5316 Access Point Status On the Monitoring tab select Summary > Advanced > Access Point Status: The access point status screen displays a read-only status summary of managed access points. Each access point entry specifies: • Status: Access point connection and configuration status. • Group: Group configured for the access point. Group 1 is the default setting for unassigned access points. • Access Point: NetBIOS name of the access point.
ProSafe 16 AP Wireless Management System WMS5316 Access Point Status Details From the Access Point Status screen, click the Details button to display this screen: Click the Refresh button to update access point statistics and information. The Access Point Status screen displays details of an access point that includes configuration settings, current wireless settings, current clients, and current traffic statistics. • Access Point Name: The access point’s NetBIOS name.
ProSafe 16 AP Wireless Management System WMS5316 • Security: The mode of security configured for the profile. • VLAN: VLAN configured for the security profile. Client Information This section displays client station information for the access point. • MAC: Wireless MAC address of the access point client. • SSID: Wireless SSID configured on the managed access point to which the client connects. • Channel: The channel that the client is using to connect. • Mode: The mode (802.11 b/bg/ng or 802.
ProSafe 16 AP Wireless Management System WMS5316 Network Usage Statistics On the Monitoring tab select Summary > Advanced > Network Usage to display this screen: Scroll down to view wireless statistics. The screen displays plots of average received and transmitted network traffic per managed access point. Three different plots show Ethernet, wireless 802.11 b/bg/ng, and wireless 802.11 a/na mode traffic separately. Click the Refresh button to update the plots.
ProSafe 16 AP Wireless Management System WMS5316 • Click the Refresh button to update the connectivity status. • Click the Apply button to save the location of the access points on the floor displayed floor map. DHCP Leases The DHCP Lease screen displays current DHCP clients that have been allocated IP addresses. On the Monitoring tab select Summary > Advanced > DHCP Leases: This screen displays information about the DHCP lease provided by DHCP server on the wireless management system.
ProSafe 16 AP Wireless Management System WMS5316 Monitoring Rogue Access Points On the Monitoring tab select Rogue Access Point. You can view rogue or unknown access points. To display the list of unknown rogue access points, On the Monitoring tab, select Rogue Access Point > Unknown: Click Refresh to update the access point list, or click Export to save the list to a file.
6. Configuring Access Point Groups 6 Most networks do not need access point groups. Access point groups are useful if completely separate networks share a single LAN. For example, a shopping mall might need access point groups if several businesses share a LAN, but each business has its own network.
ProSafe 16 AP Wireless Management System WMS5316 Managed Access Point List On the Configuration tab, select Access Point Groups to display the Managed Access Point List: This screen shows details of each controlled access point. You can edit the connection settings for specific access points. Each access point entry shows: • IP: The IP address of the access point. • Model: The access point model. • Name: The name you specify for the access point.
ProSafe 16 AP Wireless Management System WMS5316 Editing Access Point Information • IP: The IP address of the managed access point. • Model: The access point model. The field cannot be modified; it is set when the access point is added to the list. • Name: The user name for logging in to the access point. This field is not modifiable. • Password: The password for the access point.
ProSafe 16 AP Wireless Management System WMS5316 Access Point Groups This screen displays details of each access point in a configured group managed by the wireless management system. You can rename a group and add or delete other managed access points from the group. On the Configuration tab, select Access Point Groups: • To change group members, click the Edit button. • To add access points to the group, select the access points. They will be synchronized to the settings you specified for the group.
7.
ProSafe 16 AP Wireless Management System WMS5316 User Management The User Management screen lets you add and remove users. The user name admin is the default user name with administrative privileges and cannot be removed. On the Maintenance tab select User Management: 1. Fill in the following fields: • User Name: Add the name of the user. • Password: Type a new user password. • Retype Password: Retype the new user password to confirm.
ProSafe 16 AP Wireless Management System WMS5316 To change the password: 1. Type the old password. (The default password for the user name admin is password.) 2. Type a new password, and type it again in the Repeat New Password field to confirm it. 3. Be sure to record it in a secure location. 4. Click Apply so that your changes take effect, or click Cancel to keep the current password.
ProSafe 16 AP Wireless Management System WMS5316 Note: Restoring the factory default settings of the wireless management system does not restore the settings of the access points that are managed by the wireless management system. To restore the wireless management system settings to factory defaults: 1. Select Yes. 2. Click Apply to restore factory default settings. After restoring factory default settings, the wireless management system restarts. This takes about 1 minute.
ProSafe 16 AP Wireless Management System WMS5316 1. Select the group of access points to be rebooted using the tabs. Access points not assigned to a specific group belong to Group 1. 2. Select the Yes radio button. 3. Click Apply to reboot the access points in the selected group. SNMP You can use SNMP for the wireless management system or advanced SNMP for access point groups.
ProSafe 16 AP Wireless Management System WMS5316 SNMP for Access Point Groups Enable SNMP to allow the SNMP network management software, such as HP OpenView, to monitor the managed access points by using SNMPv1/v2 protocol. These settings are only applied only on ProSafe access points that support SNMP. Use the Group tab to select the settings for a specified group of access points. The access points that have not been assigned any group share the settings of Group 1.
ProSafe 16 AP Wireless Management System WMS5316 Remote Management You can enable SSH or Telnet in order to remotely log in to the controller or access point groups. Remote Console for the Wireless Management System From the Maintenance tab select Remote Management > System > Remote Console: 1. Select the radio button for SSH or Telnet: • Secure Shell (SSH): If set to Enable, the wireless management system will allow remote access by using Secure Shell.
ProSafe 16 AP Wireless Management System WMS5316 Session Timeout If a session times out, the user is redirected to the login window for password verification. To specify the length of the session timeout for the wireless management system: 1. In the Timeout (minutes) field, specify number of minutes before an active HTTP/HTTPS login session expires. 2. Click Apply to save your change.
ProSafe 16 AP Wireless Management System WMS5316 3. On the Maintenance tab select Upgrade > System Upgrade: 4. On the Upgrade screen, click Browse. 5. Locate and select the file you downloaded. 6. Click Apply to send the software to the wireless management system. This loads the new software into the wireless management system and causes the wireless management system to restart.
ProSafe 16 AP Wireless Management System WMS5316 downloading an upgrade file, you might need to unzip (uncompress) it before upgrading the access point. WARNING! Once you click Upload, do not interrupt the process of sending the software to the access point and restarting the access point. 2. Download the new software for a specific access point model to upgrade. 3. If not done automatically, uncompress the downloaded file. If included, read the Release Notes before continuing. 4.
ProSafe 16 AP Wireless Management System WMS5316 Backing Up Configuration Settings Once you have the wireless management system working correctly, you should back up the information to have it available if something goes wrong. When you back up the settings, they are saved as a file on your computer. To back up the wireless management system settings: 1. On the Maintenance tab select Upgrade > Backup: 2. Click the Backup button to create a backup file of the current settings: 3.
ProSafe 16 AP Wireless Management System WMS5316 WARNING! Do not try to go online, turn off the wireless management system, shut down the computer, or do anything else until it finishes restarting! When the Test light turns off, wait a few more seconds before doing anything with the wireless management system. Downloading Wireless Management System Logs You can download logs collected on the wireless management system.
ProSafe 16 AP Wireless Management System WMS5316 Access Point Logs The Access Points Log screen displays managed access point system activity. Select one of the managed access points to display the system log. You can refresh the screen by using the Refresh button. Diagnostic Ping Screen This screen provides a way to verify ping connectivity from the wireless management system to a managed access point. Select a managed access point from the drop-down list.
ProSafe 16 AP Wireless Management System WMS5316 Using Discovery OUI The wireless management system discovers NETGEAR access points on the LAN from the OUI (Organizationally Unique Identifier) of their unique MAC addresses. The first half of the MAC address is the OUI. Usually, the wireless management system identifies the OUI without incident during discovery. OUIs are allocated to businesses that produce products with MAC addresses.
A. Access Point Firmware Compatibility A Compatible Access Point Supported Firmware Versions Access Point Model Supported Firmware Security Profiles per Radio Max Station Load Balancing Auto Channel WNDAP350 WNDAP350_V2.0.27 8 Yes Yes WNDAP360 WNDAP360_V2.0.7 8 Yes Yes WNAP210 WNAP210_V2.0.27 8 Yes Yes WNAP320 WNAP320_V2.0.3 8 Yes Yes WG103 WG103_V2.0.37 8 Yes No For the latest firmware images, visit the NETGEAR support website: http://www.netgear.com.
B. Factory Default Settings B You can use Reset option to restore the wireless management system to its factory default settings (see Restoring Factory Default Settings on page 51). The wireless management system will return to the factory configuration settings shown in the following table. Feature Login Local network (LAN) Default Behavior User login URL http:192.168.0.250 User name (case-sensitive) admin Login password (case-sensitive) password LAN IP 192.168.0.250 Subnet mask 255.255.255.
C. Notification of Compliance NETGEAR Wired Products C Certificate of the Manufacturer/Importer It is hereby certified that the ProSafe™ 16 AP Wireless Management System WMS5316 has been suppressed in accordance with the conditions set out in the BMPT-AmtsblVfg 243/1991 and Vfg 46/1992. The operation of some equipment (for example, test transmitters) in accordance with the regulations may, however, be subject to certain restrictions. Please refer to the notes in the operating instructions.
ProSafe 16 AP Wireless Management System WMS5316 For complete DoC please visit the NETGEAR EU Declarations of Conformity website at: http://kb.netgear.com/app/answers/detail/a_id/11621/ EDOC in Languages of the European Community Cesky [Czech] NETGEAR Inc. tímto prohlašuje, že tento Radiolan je ve shode se základními požadavky a dalšími príslušnými ustanoveními smernice 1999/5/ES. Dansk [Danish] Undertegnede NETGEAR Inc.
ProSafe 16 AP Wireless Management System WMS5316 EDOC in Languages of the European Community Slovensko [Slovenian] NETGEAR Inc. izjavlja, da je ta Radiolan v skladu z bistvenimi zahtevami in ostalimi relevantnimi določili direktive 1999/5/ES. Slovensky [Slovak] NETGEAR Inc. týmto vyhlasuje, že Radiolan spĺňa základné požiadavky a všetky príslušné ustanovenia Smernice 1999/5/ES. Suomi [Finnish] NETGEAR Inc.
ProSafe 16 AP Wireless Management System WMS5316 ProSafe™ 16 AP Wireless Management System Tested to Comply with FCC Standards FOR HOME OR OFFICE USE PY306100037 Modifications made to the product, unless expressly approved by NETGEAR, Inc., could void the user's right to operate the equipment.
Index access point supported 63 upgrading 56 upgrading access point firmware 57 A access point groups 48 WLAN settings 19 access point system logs 61 access points adding 16 discovery 13, 15 discovery results 15 passwords 16 rogue 29, 37 status 37, 39, 40 supported firmware 63 upgrading firmware 57 access, guest 34 adding access points 16 authentication, MAC 30 Auto Discovery 14 G general settings 8 groups 48 editing access point information 47 IP settings 47 MAC authentication 32 guest access 34 show 35
ProSafe 16 AP Wireless Management System WMS5316 network usage statistics 42 timeout 56 trademarks 2 O OUI Discovery 62 U P untagged VLANs 10 upgrading firmware 56 passwords 7 changing 50 for access points 16 ping 61 V VLANS 10 VLANs 10, 11 Q W QoS 21, 22 wireless access point groups 19 wireless centralized RF management 18 wireless station status 38 R RADIUS server configuration 33, 34 rebooting 51, 52 remote console 55 remote console for access point groups 55 remote management 55 resetting 5