Pages

Banner 468

Showing posts with label router port forwarding tutorial. Show all posts
Showing posts with label router port forwarding tutorial. Show all posts
Sunday, 2 February 2014

10 tips for boosting your wireless router signal

3 comments
 
10 tips for boosting your wireless router signal
When it comes to "boosting" wireless speeds, there are actually two enhancements users typically seek: Distance and speed. It's great having a speedy wireless network, but if you only get great speed when you use a wireless client right next to the router and get no signal if you are 15 feet away, then speed doesn't mean so much. You need to boost the signal's range. If your device can barely open friends' Facebook pictures when you're in the same room as the router, then we're talking about problems with speed.
In general, speed and range issues can all be lumped together as performance issues. You want both your speed and range to be as robust as possible. There are several factors that can impact both aspects of performance.
Distance can certainly impede performance. You may have a room in your home or office that is simply too far from your wireless router. Even the way your home or office is structured could be a culprit when it comes to poor wireless performance. If the signals have to bounce around too many corners to reach your wireless devices, that can cause problems (although a technology in newer premium routers called beamforming can help direct a router's signal to wireless clients).

Interference with the signal can be big factor in performance, too. If you live in an apartment building, your home might be inundated with signals from everyone else's routers. Maybe structural interference is the culprit. If your washing machine and dryer are between your router and your laptop, that doesn't help. Maybe it's the software you're using. Routers need software updates just like everything else – and sometimes the firmware they initially ship with is improved with a later-released update.
These are just a few of the possible reasons your connection might be poor (or non-existent). Fortunately, there are many ways to extend your wireless signal, and most of them simply involve a bit of tweaking to your wireless network or adding some affordable components. In this article, we’ll walk you through ten of the most useful fixes for your connectivity woes.
Some of these suggestions require no additional hardware or software to purchase, while others may require a small or larger investment, depending on the particular performance problem you're experiencing. We’ll start off with free solutions, then move through the cheap to more expensive improvements.

1. Change the channel (free)

Not the TV's channel, but your router's. Wi-Fi routers operate on specific channels. When you set up a typical router, it usually chooses a certain channel by default. Some routers choose the least-crowded channel, but yours may not have. Check for yourself which Wi-Fi channel is the least crowded to boost the router's performance, perhaps boosting signal range. A good free tool to use is inSSIDer. Don't be put off by the graphs and excess information. What you want to focus on is the column "Channel." See how many routers in this area are on channel 6 in the image above? If your router is on the same channel, you want to switch it to a less-crowded one, like 4 or 1. You can change the channel of your router by going into its interface. All routers have different ways to access the interface, so check with your manufacturer on this score.


2. Update router firmware (free)

Updating router firmware is often overlooked by home users. Business networking devices usually display some sort of notification when newer software for the device is available for download. Consumer products such as home wireless routers, especially older routers, don't always offer this notification. Check often for firmware updates for your router. There is typically a section in the router's interface for upgrading the firmware. However, you often have to go to the router manufacturer's website and search for the firmware (most vendors make searching for firmware pretty easy) and then upload it through the router's interface. There's often accompanying release notes that tell you what the firmware helps to fix – and often the fixes are for connectivity problems.


3. Update adapter firmware (free)

Just like routers, network adapters on PCs and laptops are also subject to firmware updates. Remember, good wireless range and performance is dictated not just by the router but by the network adapter on clients (as well as other factors, but these are the two biggies.) Most laptops have on-board adapters. Go into your Network settings to find the name of the adapter (via the Control Panel in Windows) and then to that adapter manufacturer's site to make sure you have the latest firmware.


4. Change position (free)

Do you have your wireless router nestled up against your broadband modem tucked away in your entertainment centre in your basement that's converted into the family den? Well, move it if you have range issues. It isn’t necessary to have the router in close proximity to your modem. Ideally, a Wi-Fi router should be in a central location. You can purchase custom length Ethernet Cat 5 cable from any computer store (although if you do that, technically this is no longer a free option) if you need more flexibility in centrally positioning the router.


5. DD-WRT (free)

This one is for the more adventurous: DD-WRT is open source software for routers. It's known to ramp up router performance and extend the feature set beyond what typically comes with most routers. Not every router supports it, but the number of routers that are supported keeps growing. A word of warning, though – installing DD-WRT could possibly invalidate your router's warranty. Many manufacturers will not help you troubleshoot router issues once you have DD-WRT on them. Hence, this is not a recommended option for routers under warranty or in a business network.
There are also no guarantees that DD-WRT upgrades won't negatively affect a router. However, many users are finding it a free way to trick-out their routers. So, if you have an older, spare router laying around, or want to take the plunge to see if DD-WRT firmware helps your range issues on a newer router, check if it's supported on the DD-WRT site. Also note that it's not easy to remove DD-WRT from some routers without doing a lot research.


6. Set up a second router as an access point or repeater (cheap)

You can set up just about any router as a wireless access point. To do so, you need to connect the second router's LAN port to the primary router's LAN port. On the second router, you will want to give it the same addressing information as the primary router. For example, if your primary router's IP address is 192.168.2.1 and its netmask is 255.255.255.0; then you could make the second router's IP 192.168.2.2 and use the same netmask. It's also important that you assign the same SSID and security on the second router, and turn DHCP off on the second one as well.
Newer routers make this process easier. If you have a second router that's only about a year old, most of them can be set to operate in "access point" or repeater mode. Configuring is as simple as clicking a button. Check with your router's manufacturer or documentation.


7. Antennas (cheap)

Newer routers are increasingly manufactured with internal antennas. There are some that still have or support external ones, and these antennas can often be upgraded. Consider a hi-gain antenna, which you can position so that the Wi-Fi signal goes in the direction you want. Hawking Technology offers the HAI15SC Hi-Gain Wireless Corner Antenna, which the company claims boosts wireless signal strength from a standard 2dBi to 15dBi. Antennas like these can attach to most routers that have external antenna connectors, and are relatively cheap upgrades.


8. Dedicated repeater/extender (more expensive)

Most major wireless networking vendors offer devices that act as repeaters or wireless extenders. While they can extend a Wi-Fi signal, they can be tricky to setup, and can cause interference with the signal. They can also be on the more expensive side. Note that if you choose this option the best bet is to use an access point made by the manufacturer of your router (see tip number 10 for further details).


9. New router/adapter (more expensive)

How about getting a new router and adapter(s) altogether? Upgrading your home network to one of the latest 802.11ac routers, or an 802.11n model using the 5GHz band should give a noticeable performance improvement. 2.4GHz is said to actually have greater range than the 5GHz band, but that only becomes apparent when supplying wireless coverage to large areas such as university campuses. In our testing, we’ve found that for smaller areas like a typical home network, 802.11n and the 5GHz band maintained better throughput than 2.4GHz with most routers, at greater distances. This is certainly a more expensive option, but if wireless connectivity is crucial for you, it's a plausible one. If you’re pondering an upgrade to an 802.11ac device, we’ve got a group test of seven such routers you might want to check out (our benchmarks here show the benefit of ac, and indeed the benefit of 5GHz over 2.4GHz). Bear in mind that if you get a new router, to take full advantage of the speeds possible you’ll need to update client adapters to the same standard as well.


10. Stick to a single vendor (more expensive)

Vendors are quick to point out that their devices will work with other vendor's products. But it just makes sense that Cisco network adapters will work better with Cisco routers; Belkin adapters work optimally with Belkin routers and so on. If possible, try to limit your network devices to one vendor – that means not only you


Readmore...

How to Boost a Router Signal

0 comments
 

Method 1 of 5: Look for Interference

  1. 1
    Replace devices in your home that can interfere with network traffic on the 2.4GHz frequency range. You can buy a wireless network analyzer to help you track down the source of interference. A sample of appliances that might be causing the problem include:
    • Cordless phones,
    • Microwave ovens.
      Boost a Router Signal Step 1Bullet2.jpg
    • Baby monitors.
    • Security alarms.
      Boost a Router Signal Step 1Bullet4.jpg
    • Television remote controls.
      Boost a Router Signal Step 1Bullet5.jpg
    • Automatic garage door openers.
      Boost a Router Signal Step 1Bullet6.jpg
    Ad
  2. 2
    Check your router's signal strength with these devices. Compare power levels when each device is on and off to determine if they are the cause of your signal problems.

Method 2 of 5: Switch Channels

  1. Boost a Router Signal Step 3.jpg
    1
    Change your signal channel. Routers can broadcast on a series of channels, between one and eleven. Change to a channel that will allow your router a clear signal between other wireless networks.
  2. 2
    Use a software utility to analyze which networks are using which channel and configure your system for an unused channel.

Method 3 of 5: 802.11n

  1. Boost a Router Signal Step 5.jpg
    1
    Change your router's network broadcast mode. Try to use the new 802.11n standard if your router supports it. The 802.11n standard offers far greater range and signal strength compared to 802.11 a/b/g.

Method 4 of 5: Relocate

  1. Boost a Router Signal Step 6.jpg
    1
    Reposition your Router. Sometimes the solution is simple. All you have to do is find a new place to store your router.
    • Raise as far as possible to increase the effective broadcast range.
      Boost a Router Signal Step 6Bullet1.jpg
    • Place near the center of your house or apartment for wider coverage.
      Boost a Router Signal Step 6Bullet2.jpg
    • Move closer to the receivers, if possible.
      Boost a Router Signal Step 6Bullet3.jpg
    • Move away from any metal including metal shelving, filing cabinets and similar common objects.
      Boost a Router Signal Step 6Bullet4.jpg
    • Move away from cordless phones and microwaves, which operate on the same 2.4-Ghz frequency.
      Boost a Router Signal Step 6Bullet5.jpg
  2. 2
    Be aware of external interference. Move your unit as far away as possible from your next-door neighbor's WiFi router. In addition, if you're living in an apartment building, there might be multiple routers in operation too. Note: make sure you're using a different channel than everyone else.

Method 5 of 5: Upgrade

  1. Boost a Router Signal Step 8.jpg
    1
    Raise your transmit power. Check your router's documentation and configuration utility for the ability to change the Xmit power of your router: the amount of power it uses to transmit the signal. Generally, you can boost this number by up to 50mW. Keep in mind that you risk overheating or damaging your router.
  2. Boost a Router Signal Step 9.jpg
    2
    Replace the Antenna. Unscrew and replace the broadcast antenna on your router with a model that delivers more power. Not all routers allow for new antenna to be attached, but many do.
  3. Boost a Router Signal Step 10.jpg
    3
    Install a Repeater. A repeater is a piece of hardware that acts like a wireless network expander. The repeater takes the signal from your router and boosts it to increase the range.
    • Wireless repeaters are increasingly common and affordable and will probably be available in your local computer store, or on the Internet.
  4. Boost a Router Signal Step 11.jpg
    4
    Install a Wireless Amplifier. Attach a wireless amplifier, also known as a booster, directly to your router. A booster can be more affordable than a repeater as they only increase the strength of your existing signal, rather than the strength and range.
    • Use a bi-directional amplifier to increase both your inward and outbound speeds.
  5. Boost a Router Signal Step 12.jpg
    5
    Make a Reflector lulu with Tinfoil. Note that a tinfoil router may boost your signal, but will also make it more directional.
    • Cut a tinfoil circle with the tinfoil on the inside of a piece of paper or some cardboard large enough to wrap around the router. If you want to get fancier than this, cut a shallow parabola and put the hole for the antenna at the focal point.
      Boost a Router Signal Step 12Bullet1.jpg
    • Place the tinfoil circle over the router.
      Boost a Router Signal Step 12Bullet2.jpg
    • Place the antenna in the center of the circle or parabola.
      Boost a Router Signal Step 12Bullet3.jpg
Readmore...
Friday, 24 January 2014

How to setup Inbound/Outbound firewall

0 comments
 

How to setup Inbound/Outbound firewall rules on NETGEAR Modem router/gateways

Symptoms: 
  • Cannot connect or access LAN devices or applications from the Internet (i.e.: FTP server, HTTP server, Podcast server, etc...)
  • Cannot play online games through NETGEAR Modem Routers
  • The NETGEAR firewall prevented certain applications to work correctly over the Internet
Resolutions:

By default, the NETGEAR Firewall rules will block and prevent any unauthorized access to your Local Area Network (LAN).  Remote access to the LAN devices or applications will only be possible after an inbound or outbound firewall rule is added to the router/gateway.  Inbound firewall rules are set of rules that would allow or permit access to the LAN services from the Internet -- the default rule blocks all incoming service requests.  On the other hand, Outbound firewall rules would prevent or deny access to the Internet from the LAN devices -- the default rule allows all outgoing traffic. 
The steps below will show you how to configure inbound/outbound firewall rules:
1. Open Internet browser and access http://192.168.0.1 or http://www.routerlogin.com.  
2. Enter admin for username and password for password. If you have changed the default password, please enter your customized password when prompted.
3. On the left panel under Security (Content Filtering, for older devices) , click Firewall Rules
4. Click the Add button under the type of rule (Outbound or Inbound) that you would like to add.
5. Select the desired Service from the list.  If necessary, you can define a customized service.  To add a new customized Service, follow these steps:
    1. On the left panel, under Security (Content Filtering for older models), click Services.
    2. Click the Add Custom Service button.
    3. Create a Name for the new service
    4. Select the Type of protocol that the service will be using.
    5. Enter the Starting port and Ending port
    6. Click Apply to finish adding the new custom service.
6. Under Action, select the appropriate action for packets covered for this rule.
  • Note: To define the Schedule used in these selections, use the "Schedule" option listed on the Security or Content Filteringsection.
7. Under the Send to LAN server field, enter the IP address of the PC or Server on your LAN which will receive the inbound or outbound traffic covered by this rule.
8. Select an option for WAN Users. This setting determine which packets are covered by the rule, based on their source (WAN) IP address. Here are the options:
    • Any - All IP addresses are covered by this rule
    • Address range - If this option is selected, you must enter the "Start" and "Finish" fields
    • Single address - Enter the required address in the "Start" fields.
9. Select an option under Log. This determines whether packets covered by this rule are logged. Select the desired action.
    • Always - always log traffic considered by this rule, whether it matches or not. (This is useful when debugging your rules.)
    • Never - never log traffic considered by this rule, whether it matches or not.
    • Match - Log traffic only it matches this rule. (The action is determined by this rule.)
    • Not Match - Log traffic which is considered by this rule, but does not match (The action is NOT determined by this rule.)
10. Click on Apply button.

This applies to:
     > Netgear MBR624GU, DGND3300, DGN2000, DG834G and DG834N.


Readmore...
Monday, 2 December 2013

How to Configure my Range Extender

0 comments
 

How to Configure my Range Extender

Suitable for: TL-WA730RE, TL-WA830RE
Before configuration, please get the right information of the Root Router as below:
Information of Root Router:
  •  LAN IP: 192.168.1.254
  •  SSID: 2WIRE_TEST
  •  Encryption Type: WPA2-PSK with AES
  •  Passphrase: testtplink
Preparation
  • Since the DHCP function on the Range Extender is disabled by default, we have to manually assign an IP address as 192.168.1.x to the computer to match the default IP address of the Range Extender. Please click here for detailed instruction. For TL-WA830RE, its LAN IP is 192.168.0.254, please assign 192.168.0.x for you computer.
  • Connect the computer to the Range Extender with an Ethernet cable. And disconnect the wireless from the root router.
Configuration on Range Extender :
1.    Log onto the Range Extender’s management page. Please click here for the detailed instruction;
2.    Click Network. Please make sure the Range Extender's IP address is in the same IP segment with the Root Router and avoid the IP conflict. In this instance, we can change the IP to "192.168.1.250". Then click Save.
Notice: If the root router is not in the IP segment 192.168.1.X, for example, it is 192.168.0.254.you need to change the IP of the Range Extender to 192.168.0.250. and after clicking on Save, please change the IP of your computer to 192.168.0.100. and then log in the Range Extender’s management page by using the new IP 192.168.0.250.
3.    Click Quick Setup, Click on Next->Wireless. Select Range Extender as the Operation Mode. Then click Search.
4.    Find the Root Router's SSID on the list, and then click Connect.
5.    Click Save.
 
6.    Click Wireless -> Wireless Security. Select WPA-PSK/WPA2-PSK, and Encryption AES. input the password "testtplink" in the PSK Password field. Then click Save. The Security settings on the Range Extender must be the same as the root router. Please contact the support of the router to check it if you are not sure.
After you go through all the above steps, the Range Extender should get working properly with the Root Router.
How to confirm:
Go to System Tools->Diagnosticin the IP address(or IP address/Domain Name) bar type in the root router’s IP 192.168.1.254, click on the Start on the bottom.
And the last step is to set the computer to obtain the IP addre
Readmore...
Wednesday, 13 November 2013

How to Portforward on Windows 7/8

0 comments
 
Hey guys

I'm going to show you how to portforward on Windows 8 / 7

Ok lets start !

{You maybe have to wait until all the images load !}



1.






2.






3.






4.






5.






6.






Save it and you are done !
Readmore...
Sunday, 6 October 2013

Open a port in Windows Firewall

0 comments
 

Open a port in Windows Firewall

If Windows Firewall is blocking a program and you want to allow that program to communicate through the firewall, you can usually do that by selecting the program in the list of allowed programs (also called the exceptions list) in Windows Firewall. To learn how to do this, see Allow a program to communicate through Windows Firewall.
However, if the program isn't listed, you might need to open a port. For example, to play a multiplayer game with friends online, you might need to open a port for the game so that the firewall allows the game information to reach your computer. A port stays open all the time, so be sure to close ports that you don't need open anymore.
  1. Open Windows Firewall by clicking the Start button Picture of the Start button, and then clicking Control Panel. In the search box, type firewall, and then click Windows Firewall.
  2. In the left pane, click Advanced settings. Administrator permission required If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
  3. In the Windows Firewall with Advanced Security dialog box, in the left pane, click Inbound Rules, and then, in the right pane, click New Rule.
  4. Follow the instructions in the New Inbound Rule wizard.
If you’re having trouble allowing other computers to communicate with your computer through Windows Firewall, you can try using the Incoming Connections troubleshooter to automatically find and fix some common problems.
Open the Incoming Connections troubleshooter by clicking the Start button Picture of the Start button, and then clicking Control Panel. In the search box, type troubleshooter, and then click Troubleshooting. Click View all, and then click Incoming Connections.
Readmore...
Wednesday, 7 August 2013

Upgrade Cisco IOS on an Autonomous Access Point

0 comments
 

Introduction

This document shows how to upgrade a Cisco IOS® image on an autonomous access point through the GUI or CLI.

Prerequisites

Components Used

The information in this document is based on Cisco Aironet 1240AG Series Access Point that runs Cisco IOS Software Release12.3(8)JEA.
Note: This procedure is applicable for any autonomous access point.

Conventions

Refer to Cisco Technical Tips Conventions for more information on document conventions.

Background Information

The upgrade is performed in order to take advantage of the new features available in the new Cisco IOS image and to fix issues in the previous software version. It is usually performed as a part of regular maintenance task. You can use either the GUI or CLI to upgrade Cisco IOS on an access point.
These are the IP addresses used in this document:
  • The IP address of the TFTP server is 10.77.244.196
  • The IP address of the access point is 10.77.244.194
In this document, the AP is upgraded to Cisco IOS Software Release 12.4.10b-JA3(ED).

Upgrade Process

Upgrade Cisco IOS through the GUI

In this section, you are presented with the information on how to upgrade the access point through the GUI. Complete these steps:
  1. Check the current software version of the AP. Open a browser and type http://<ip address of the ap> in the address bar in order to log into the GUI. On the main page, click on the System Software menu from the left hand side. Choose the Software Upgrade option and check the current Cisco IOS version from the System Software Version field.
    Note: Refer to Cisco Software Downloads FAQ for information on how to download firmware from Cisco.com Downloads.
  2. From the software upgrade page, choose TFTP upgrade, as shown in Figure 1.
    Note: You can also check the Cisco IOS version from this screen.
  3. Enter the IP address of the TFTP server.
  4. Specify the name of the Cisco IOS software file to be upgraded in the Upgrade System Software Tar file field, as shown in Figure 1.
    Note: In order to have a smooth upgrade, do not change the original Cisco IOS filename. Leave the name as it was when you downloaded the file from cisco.com.
  5. Click the Upgrade button. A status window similar to the one shown in Figure 2 appears.
    This takes few minutes, and then the AP reboots once the upgrade is complete.
Figure 1 ios_upgrade1.gif
Figure 2 ios_upgrade2.gif

Upgrade Cisco IOS through the CLI

This section describes how to upgrade Cisco IOS on an access point through the CLI.
  1. Log into the access point through a Telnet session.
  2. You can download a new image file and choose to replace the current image or keep the current image.
    Note: Refer to Cisco Software Downloads FAQ for information on how to download firmware from Cisco.com Downloads.
    Note: The latter option is helpful when one of the Cisco IOS files are corrupted. You can work with the access point from the other image in the flash.
  3. If you choose to overwrite the existing file, issue the archive download-sw /overwrite /reload tftp://location/image-name command. The /overwrite option overwrites the software image in flash with the downloaded image. The /reload option reloads the system after you download the image unless the configuration is changed and not saved. For //location, specify the IP address of the TFTP server. For image name, specify the Cisco IOS filename that you plan to use to upgrade the access point. In this example, the command is archive download-sw /overwrite /reload tftp://10.77.244.194/c1240-k9w7-tar.124-10b.JA3.tar. As mentioned earlier, do not change the name of the Cisco IOS file. Leave it as the default. You find these logs during the successful file transfer:
    examining image...
    Loading c1240-k9w7-tar.124-10b.JA3.tar from 10.77.244.196 (via BVI1): !
    extracting info (275 bytes)
    Image info:
        Version Suffix: k9w7-.124-10b.JA3
        Image Name: c1240-k9w7-mx.124-10b.JA3
        Version Directory: c1240-k9w7-mx.124-10b.JA3
        Ios Image Size: 4813312
        Total Image Size: 5560832
        Image Feature: UNKNOWN
        Image Family: C1240
        Wireless Switch Management Version: 1.0
    Extracting files...
    c1240-k9w7-mx.124-10b.JA3/ (directory) 0 (bytes)
    c1240-k9w7-mx.124-10b.JA3/html/ (directory) 0 (bytes)
    c1240-k9w7-mx.124-10b.JA3/html/level/ (directory) 0 (bytes)
    -----------------Lines omitted ---------------------------
    ----------------------------------------------------------
    Deleting target version: flash:/c1240-k9w7-mx.124-10b.JA3...done.
    New software image installed in flash:/c1240-k9w7-mx.124-10b.JA3.
    Configuring system to use new image...done.
    Requested system reload in progress...
  4. If you choose to keep the existing file, issue the archive download-sw /leave-old-sw /reload tftp://location/image-name command. If there is not enough space to install the new image and keep the current running image, the download process stops, and an error message is displayed.
  5. The AP downloads the Cisco IOS file specified from the DHCP server and reloads with the new software.

Verify

On the TFTP server, check to see if you receive logs about this file transfer. If you use tftpd32 as your TFTP server software, you can see these logs for a successful transfer of the Cisco IOS file to AP:
Read request for file <c1240-k9w7-tar.123-8.JEA2.tar>. Mode octet [18/08 17:10:14.562]
<c1240-k9w7-tar.123-8.JEA2.tar>: sent 10021 blks, 5130240 bytes in 89 s. 0 blk resent [18/08 17:11:42.812]
Once the new image is downloaded, the access point automatically reloads. At this time, the connection to the access point is lost. Login to the AP again. On the GUI, use the System Software menu in order to verify if the new software is loaded. If you use the CLI, you can check this with the show version command. Look at the first line that reads Cisco IOS software in order to check to see if the AP has the upgraded image.

Troubleshoot

Troubleshooting Procedure

If the upgrade is not successful, complete these checks:
  1. Make sure that the TFTP server is reachable from the access point. Check the IP address assignment on the AP and the TFTP server.
  2. Disable any firewall to see if it blocks the TFTP port udp 69. Determine whether you have any ACL defined on the network that prevents TFTP service.
  3. Ensure that the Cisco IOS file is present in the root directory of the TFTP server. The root directory is also called the current directory of the TFTP server.
  4. Ensure that you download the appropriate image for a particular model of the access point. Otherwise the download algorithm on the AP rejects the image and displays an error.
  5. Make sure that the access point meets the memory requirements specified for the image in the downloads page. If there is not sufficient space in the flash to hold the Cisco IOS file, it produces an error message.
  6. If you use the GUI to upgrade the AP, make sure the browser is supported. During the upgrade process, a status pop-up window appears. Make sure that the browser allows pop-up windows from the AP to appear. Microsoft Internet Explorer (IE) 6.0 or later is a supported browser. Refer to the Using the Web-Browser Interface section of Cisco IOS Software Configuration Guide for Cisco Aironet Access Points Cisco IOS Releases 12.4(10b)JA and 12.3(8)JEC for more information on the supported browser.
  7. Sometimes due to the unsuccessful upgrade process, the AP gets stuck in ap: mode and the permission denied error message appears. Refer to the Troubleshooting section of Cisco IOS Software Configuration Guide for Cisco Aironet Access Points Cisco IOS Releases 12.4(10b)JA and 12.3(8)JEC in order to reload the Cisco IOS on the AP.
Readmore...

Configuring a Wireless LAN Connection

0 comments
 

Configuring a Wireless LAN Connection


The Cisco 850 and Cisco 870 series routers support a secure, affordable, and easy-to-use wireless LAN solution that combines mobility and flexibility with the enterprise-class features required by networking professionals. With a management system based on Cisco IOS software, the Cisco routers act as access points, and are Wi-Fi certified, IEEE 802.11a/b/g-compliant wireless LAN transceivers.
You can configure and monitor the routers using the command-line interface (CLI), the browser-based management system, or Simple Network Management Protocol (SNMP). This chapter describes how to configure the router using the CLI. Use the interface dot11radio global configuration CLI command to place the device into radio configuration mode.
See the Cisco Access Router Wireless Configuration Guide for more detailed information about configuring these Cisco routers in a wireless LAN application.
Figure 9-1 shows a wireless network deployment.
Figure 9-1 Wireless Connection to the Cisco Router

1
Wireless LAN (with multiple networked devices)
2
Cisco 850 or Cisco 870 series access router connected to the Internet
3
VLAN 1
4
VLAN 2

In the configuration example that follows, a remote user is accessing the Cisco 850 or Cisco 870 series access router using a wireless connection. Each remote user has his own VLAN.
Configuration Tasks
Perform the following tasks to configure this network scenario:
A configuration example showing the results of these configuration tasks is provided in the "Configuration Example" section.

Note The procedures in this chapter assume that you have already configured basic router features as well as PPPoE or PPPoA with NAT. If you have not performed these configurations tasks, see Chapter 1 "Basic Router Configuration," Chapter 3 "Configuring PPP over Ethernet with NAT," and Chapter 4 "Configuring PPP over ATM with NAT," as appropriate for your router. You may have also configured DHCP, VLANs, and secure tunnels.

Configure the Root Radio Station

Perform these steps to create and configure the root radio station for your wireless LAN, beginning in global configuration mode:

 
Command
Purpose
Step 1 
interface name number
Example:
Router(config)# interface dot11radio 0
Router(config-if)# 
Enters interface configuration mode for the radio interface.
Step 2 
broadcast-key [vlan vlan-id] change seconds
Example:
Router(config-if)# broadcast-key vlan 1 
change 45
Router(config-if)# 
Specifies the time interval, in seconds, between rotations of the broadcast encryption key used for clients.
Note Client devices using static Wired Equivalent Privacy (WEP) cannot use the access point when you enable broadcast key rotation—only wireless client devices using 802.1x authentication (such as Light Extensible Authentication Protocol [LEAP], Extensible Authentication Protocol-Transport Layer Security [EAP-TLS], or Protected Extensible Authentication Protocol [PEAP]) can use the access point.
Note This command is not supported on bridges.
Step 3 
encryption method algorithm key
Example:
Router(config-if)# encryption vlan 1 mode 
ciphers tkip
Router(config-if)# 
Specifies the encryption method, algorithm, and key used to access the wireless interface.
The example uses the VLAN with optional encryption method of data ciphers.
Step 4 
ssid name
Example:
Router(config-if)# ssid cisco
Router(config-if-ssid)# 
Creates a Service Set ID (SSID), the public name of a wireless network.
Note All of the wireless devices on a WLAN must employ the same SSID to communicate with each other.
Step 5 
vlan number
Example:
Router(config-if-ssid)# vlan 1
Router(config-if-ssid)# 
Binds the SSID with a VLAN.
Step 6 
authentication type
Example:
Router(config-if-ssid)# authentication open
Router(config-if-ssid)# authentication 
network-eap eap_methods
Router(config-if-ssid)# authentication 
key-management wpa
Sets the permitted authentication methods for a user attempting access to the wireless LAN.
More than one method can be specified, as shown in the example.
Step 7 
exit
Example:
Router(config-if-ssid)# exit
Router(config-if)# 
Exits SSID configuration mode, and enters interface configuration mode for the radio interface.
Step 8 
speed rate
Example:
Router(config-if)# basic-1.0 basic-2.0 
basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 
36.0 48.0 54.0
Router(config-if)# 
(Optional) Specifies the required and allowed rates, in Mbps, for traffic over the wireless connection.
Step 9 
rts [retries | threshold]
Example:
Router(config-if)# rts threshold 2312
Router(config-if)# 
(Optional) Specifies the Request to Send (RTS) threshold or the number of times to send a request before determining the wireless LAN is unreachable.
Step 10 
power [client | local] [cck [number | maximum] | ofdm [number | maximum]]
Example:
Router(config-if)# power local cck 50
Router(config-if)# power local ofdm 30
Router(config-if)# 
(Optional) Specifies the radio transmitter power level.
See the Cisco Access Router Wireless Configuration Guide for available power level values.
Step 11 
channel [number | least-congested]
Example:
Router(config-if)# channel 2462
Router(config-if)# 
(Optional) Specifies the channel on which communication occurs.
See the Cisco Access Router Wireless Configuration Guide for available channel numbers.
Step 12 
station-role [repeater | root]
Example:
Router(config-if)# station-role root
Router(config-if)# 
(Optional) Specifies the role of this radio interface.
You must specify at least one root interface.
Step 13 
exit
Example:
Router(config-if)# exit
Router(config)# 
Exits interface configuration mode, and enters global configuration mode.

Configure Bridging on VLANs

Perform these steps to configure integrated routing and bridging on VLANs, beginning in global configuration mode:

 
Command or Action
Purpose
Step 1 
bridge [number | crb | irb |mac-address-table]
Example:
Router(config)# bridge irb
Router(config)# 
Specifies the type of bridging.
The example specifies integrated routing and bridging.
Step 2 
interface name number
Example:
Router(config)# interface vlan 1
Router(config)# 
Enters interface configuration mode.
We want to set up bridging on the VLANs, so the example enters the VLAN interface configuration mode.
Step 3 
bridge-group number
Example:
Router(config)# bridge-group 1
Router(config)# 
Assigns a bridge group to the interface.
Step 4 
bridge-group number parameter
Example:
Router(config)# bridge-group 1 
spanning-disabled
Router(config)# 
Sets other bridge parameters for the bridging interface.
Step 5 
interface name number
Example:
Router(config)# interface bvi 1
Router(config)# 
Enters configuration mode for the virtual bridge interface.
Step 6 
bridge number route protocol
Example:
Router (config) # bridge 1 route ip
Router(config)# 
Specifies the protocol for the bridge group.
Step 7 
ip address address mask
Example:
Router(config)# ip address 10.0.1.1 
255.255.255.0
Router(config)# 
Specifies the address for the virtual bridge interface.
Repeat Step 2 through Step 7 above for each VLAN that requires a wireless interface.

Configure Radio Station Subinterfaces

Perform these steps to configure subinterfaces for each root station, beginning in global configuration mode:

 
Command
Purpose
Step 1 
interface type number
Example:
Router(config)# interface dot11radio 0.1
Router(config-subif)# 
Enters subinterface configuration mode for the root station interface.
Step 2 
description string
Example:
Router(config-subif)# description Cisco open
Router(config-subif)# 
Provides a description of the subinterface for the administrative user.
Step 3 
encapsulation dot1q vlanID [native | second-dot1q]
Example:
Router(config-subif)# encapsulation dot1q 1 
native
Router(config-subif)# 
Specifies that IEEE 802.1Q (dot1q) encapsulation is used on the specified subinterface.
Step 4 
no cdp enable
Example:
Router(config-subif)# no cdp enable
Router(config-subif)# 
Disables the Cisco Discovery Protocol (CDP) on the wireless interface.
Step 5 
bridge-group number
Example:
Router(config-subif)# bridge-group 1
Router(config-subif)# 
Assigns a bridge group to the subinterface.
Note When the bridge-group command is enabled, the following commands are automatically enabled, and cannot be disabled. If you disable these commands you may experience an interruption in wireless device communication.
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
Step 6 
exit
Example:
Router(config-subif)# exit
Router(config)# 
Exits subinterface configuration mode, and enters global configuration mode.
Repeat these steps to configure more subinterfaces, as needed.

Configuration Example

The following configuration example shows a portion of the configuration file for the wireless LAN scenario described in the preceding sections.
!
bridge irb
!
interface Dot11Radio0
 no ip address
 !
 broadcast-key vlan 1 change 45
 !
 !
 encryption vlan 1 mode ciphers tkip 
 !
 ssid cisco
    vlan 1
    authentication open 
	wpa-psk ascii 0 cisco123
    authentication key-management wpa
 !
 ssid ciscowep
    vlan 2
    authentication open 
 !
 ssid ciscowpa
    vlan 3
    authentication open 
 !
 speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
 rts threshold 2312
 power local cck 50
 power local ofdm 30
 channel 2462
 station-role root
!
interface Dot11Radio0.1
 description Cisco Open
 encapsulation dot1Q 1 native
 no cdp enable
 bridge-group 1
 bridge-group 1 subscriber-loop-control
 bridge-group 1 spanning-disabled
 bridge-group 1 block-unknown-source
 no bridge-group 1 source-learning
 no bridge-group 1 unicast-flooding
!
interface Dot11Radio0.2
 encapsulation dot1Q 2
 bridge-group 2
 bridge-group 2 subscriber-loop-control
 bridge-group 2 spanning-disabled
 bridge-group 2 block-unknown-source
 no bridge-group 2 source-learning
 no bridge-group 2 unicast-flooding
!
interface Dot11Radio0.3
 encapsulation dot1Q 3
 bridge-group 3
 bridge-group 3 subscriber-loop-control
 bridge-group 3 spanning-disabled
 bridge-group 3 block-unknown-source
 no bridge-group 3 source-learning
 no bridge-group 3 unicast-flooding
!
interface Vlan1
 no ip address
 bridge-group 1
 bridge-group 1 spanning-disabled
!
interface Vlan2
 no ip address
 bridge-group 2
 bridge-group 2 spanning-disabled
!
interface Vlan3
 no ip address
 bridge-group 3
 bridge-group 3 spanning-disabled
!
interface BVI1
 ip address 10.0.1.1 255.255.255.0
!
interface BVI2
 ip address 10.0.2.1 255.255.255.0
!
interface BVI3
 ip address 10.0.3.1 255.255.255.0
!
Readmore...