EasyManua.ls Logo

Nomadix AG3100 User Manual

Nomadix AG3100
294 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Page #1 background imageLoading...
Page #1 background image

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the Nomadix AG3100 and is the answer not in the manual?

Nomadix AG3100 Specifications

General IconGeneral
ModelAG 3100
CategoryGateway
Wireless Standard802.11a/b/g/n
Max Wireless Speed300 Mbps
FirewallYes
LAN Ports4
VPNYes

Summary

Introduction

About this Guide

Provides an overview of the Access Gateway's functionality and features for system administrators.

Organization

Chapter 1: Introduction

Introduces the features and benefits of the Nomadix Access Gateway.

Chapter 2: Installing the Access Gateway

Provides instructions for installing the hardware and software components of the Access Gateway.

Chapter 3: System Administration

Covers procedures for system administrators to manage and administer the Access Gateway.

Chapter 4: The Subscriber Interface

Details the Access Gateway's subscriber interface, authorization, and billing processes.

Chapter 5: Quick Reference Guide

Contains product reference information organized by topic for quick access.

Chapter 6: Troubleshooting

Offers guidance on resolving common hardware and software problems.

Appendix A: Technical Support

Provides information on how to obtain technical support from Nomadix.

Appendix B: Glossary of Terms

Explains terms directly related to Nomadix product technology.

Welcome to the Access Gateway

Product Configuration and Licensing

Explains the role of Nomadix Service Engine (NSE) software in Access Gateway products.

Key Features and Benefits

Platform Reliability

Highlights the Access Gateway's design as a network appliance for maximum uptime.

Local Content and Services

Details the Portal Page feature for user sign-up and login redirection.

Transparent Connectivity

Explains the Dynamic Address Translation (DAT) for seamless network access.

Billing Enablement

Access Control and Authentication

Ensures network security by controlling access until user authentication is complete.

Security

Discusses iNAT™ for VPN tunnels and Session Rate Limiting (SRL) for DoS protection.

5-Step Service Branding

Outlines a methodology for customizing the service provider's branding.

NSE Core Functionality

Access Control

Manages administrator access to network interfaces and incorporates a master access control list.

Bandwidth Management

Optimizes bandwidth usage for subscribers, ensuring fair distribution and quality of experience.

Billing Records Mirroring

Enables sending copies of billing records to external servers for backup and security.

Bridge Mode

Provides unconditional network access, making the Access Gateway transparent to the network.

Class-Based Queueing

Allows defining user classes for bandwidth prioritization and guaranteed minimum bandwidth.

Notes and Cautions

Command Line Interface (CLI)

A character-based interface for system administration and configuration.

Daylight Savings Time and IANA Time Zone Support

Configures system time with support for regional time zones and daylight savings adjustments.

Dynamic Address Translation™

Dynamic Transparent Proxy

Directs HTTP/HTTPS proxy requests through an internal proxy transparently to subscribers.

End User Licensee Count

Manages simultaneous user counts, with options for platform-dependent upgrades.

External Web Server Mode

Allows customers to use their own content for a richer subscriber environment.

Facebook Authentication

Provides a two-step process for facility guests to authenticate using their Facebook account.

Home Page Redirect

iNAT™

Intelligently supports multiple VPN connections simultaneously for seamless access.

Information and Control Console (ICC)

Internal Web Server

Offers an embedded web server for delivering stored web pages and custom branding.

International Language Support

Allows definition of displayed text in multiple languages for the Internal Web Server.

IP Upsell

Enables administrators to set up different DHCP pools for revenue generation opportunities.

IPv6 Device Management

Link Aggregation Control Protocol (LACP)

Creates dynamic port groupings to increase throughput and provide link redundancy.

Logout Pop-Up Window

Provides a pop-up window for explicit logout functions.

MAC Filtering

Enhances access control by blocking malicious users based on their MAC address.

Multi-Level Administration Support

Differentiates access levels between managers and operators for secure administration.

Multi-WAN Interface Management

Supports independently configurable WAN interfaces for ISP resource allocation and load balancing.

NTP Support

PayPal

Allows internet access billing to be managed via PayPal accounts or credit cards.

Portal Page Redirect

Contains logic for redirecting pages before or after the authentication process.

RADIUS-driven Auto Configuration

Provides an effortless method for configuring devices using existing RADIUS infrastructure.

RADIUS Client

Offers an integrated RADIUS client for tracking and billing users based on connection data.

RADIUS Proxy

Realm-Based Routing

Provides NAI routing capabilities for multiple service providers sharing a HotSpot location.

Remember Me and RADIUS Re-Authentication

Stores login cookies and RADIUS credentials for seamless reconnections without re-login.

Secure Management

Utilizes IPSec tunneling with strong data encryption for secure network device management.

Secure Socket Layer (SSL)

Secure XML API

Allows user administration and processing of XML commands from external sources.

Session Rate Limiting (SRL)

Limits user sessions to reduce the risk of Denial of Service attacks.

Session Termination Redirect

Smart Client Support

Supports authentication mechanisms used by various Smart Client providers.

SNMP Nomadix Private MIB

Allows viewing and managing SNMP objects on the Access Gateway.

Static Port Mapping

Sets up port mapping to forward packets to a specific IP and port number on the subscriber side.

Tri-Mode Authentication

Offers multiple authentication models for flexibility in end-user and operator support.

URL Filtering

Restricts access to specified websites based on administrator-defined URLs.

Walled Garden

Web Management Interface (WMI)

Allows remote management of Access Gateways via a graphical web interface.

Weighted Fair Queueing

Allocates bandwidth proportionally to users or groups, providing a fallback for over-subscription.

Optional NSE Modules

Load Balancing

Balances Internet traffic across multiple WAN/ISP connections for optimized distribution and failover.

Hospitality Module

Provides interfaces for Property Management Systems (PMS) for in-room guest billing.

High Availability Module

Offers enhanced network uptime and service availability through Fail-Over functionality.

Network Architecture (Sample)

Multiple Unit Clustering

Identifying the Resident Gateway in a Cluster Environment

Explains how to determine the resident gateway for a given MAC address within a cluster.

Load Balancing and Link Failover

Definitions and Concepts

Defines Load Balancing, Link Aggregation, and Link Failover processes.

ISP link Selection Criteria

Factors influencing ISP selection for outgoing traffic in load balancing scenarios.

User-Based ISP Selection versus Random ISP Selection

Compares user-based ISP selection with random selection based on load conditions.

Link Availability Detection Method and Time

Traffic Balancing and Weighting

Balances traffic between links based on subscriber numbers and ISP connection speeds.

Load Rebalancing upon Link Recovery

Details actions taken when a previously failed ISP link becomes available again.

Load Balancing and Failure Considerations

Discusses key factors to consider when implementing load balancing and failover.

Load Balancing across Multiple Low Speed Links

Failover to Standby ISP Link

Utilizes a low-cost wireless backup ISP service only when the main circuit is unavailable.

Separate Guest HSIA and Admin ISP Links, with Failover Between Each ISP Link

Guest HSIA Failover Only, to Admin Network

Uses the Admin network as a backup link if the Guest HSIA ISP link fails.

Sharing Guest HSIA Network and Hotel Admin Network Among Multiple ISP Links

Connects multiple ISP links to share aggregate bandwidth between guest and admin networks.

Load Balancing With Users Connected to a Preferred ISP Link

Online Help (WebHelp)

Notes, Cautions, and Warnings

Installing the Access Gateway

Installation Workflow

Provides a flowchart detailing the steps for installing and configuring the Access Gateway.

Powering Up the System

Details the procedure for establishing a direct cable connection and powering up the system.

User Manual and Documentation

Locates product user manuals, documentation, and support files available online.

Start Here

LCD Messages

Describes the system information displayed on the Access Gateway's LCD panel.

Configuration

Step 1a: Static WAN IP Configuration

Guides through configuring the WAN port with static IP address settings.

Step 1b: DHCP Client Configuration

Guides through configuring the WAN port using DHCP client settings.

Step 1c: PPPoE Dynamic IP Client Configuration

Guides through configuring a PPPoE connection with dynamic IP address assignment.

Step 1d: PPPoE Static IP Client Configuration

Guides through configuring a PPPoE connection with static IP address assignment.

Step 2: Entering Your Location Information

Details required location information for obtaining the license key.

Step 3: Retrieving Your License Key

Explains the process of accepting the EULA to retrieve the license key from the server.

Step 4: Configuring the System

Covers disabling subscriber-side HTTP to enable Web Management Interface access.

Step 5: Configuring AG DHCP Server Settings

Details the configuration of the Access Gateway's DHCP Server settings.

The Management Interfaces (CLI and Web)

Making Menu Selections and Inputting Data with the CLI

Explains how to make menu selections and input data using the Command Line Interface (CLI).

Menu Organization (Web Management Interface)

Describes the organization of menus within the Web Management Interface (WMI).

Inputting Data – Maximum Character Lengths

Online Documentation and Help

Establishing the Start Up Configuration

Assigning Login User Names and Passwords

Guides on assigning unique login user names and passwords for secure administration.

Setting the SNMP Parameters (optional)

Details setting up SNMP communities and identifiers for network management.

Configuring the WAN interface

Provides step-by-step instructions to configure the main WAN interface.

Enabling the Logging Options (recommended)

Explains how to enable system and AAA logging for error messages and activity records.

Configuration Menu

Defining the AAA Services {AAA}

Guides on setting up AAA (Authentication, Authorization, and Accounting) service options.

Enabling Dynamic Multiple Subnet Support (Subnets)

Allows creation of flexible IP pool solutions to meet demands of complex networks.

Displaying Your Configuration Settings {Summary}

Provides a summary listing of all current configuration settings for review.

System Administration

Network Info Menu

Accesses menus for monitoring network connections, routings, protocols, and statistics.

Port-Location Menu

Accesses menus for managing port-location assignments, including VLAN tags.

Subscriber Administration Menu

Accesses menus for managing subscriber profiles and connections.

Subscriber Interface Menu

Accesses menus for defining the subscriber interface appearance and content.

System Menu

Accesses menus for managing login names, passwords, and system configurations.

Choosing a Remote Connection

Using the Web Management Interface (WMI)

Provides a powerful and flexible web interface for network administrators.

Using an SNMP Manager

Allows remote management using an SNMP client manager (e.g., HP OpenView).

Using a Telnet Client

Provides simple terminal emulation for interacting with the Command Line Interface (CLI).

Logging In

About Your Product License

Configuration Menu

Defining the AAA Services {AAA}

Guides on setting up AAA (Authentication, Authorization, and Accounting) service options.

XML Interface

Allows the Access Gateway to accept and process XML commands from external sources.

Enabling or disabling Print Billing Command

Supports Driverless Print servers for subscriber room billing for printing documents.

AAA Passthrough Port feature, as required

802.1x Authentication Support feature, as required

Enables 802.1x authentication support, requiring AAA and RADIUS to be enabled.

Origin Server (OS) parameter encoding for Portal Page and EWS feature, as required

Enables Origin Server parameter encoding for Portal Page and External Web Server features.

Enable failover to Internal Web Server Authentication

Allows failover to Internal Web Server Authentication if Portal Page/External Web Server is unreachable.

Enable or disable Port Based Billing Policies

Allows individual configuration of billing methods and plans for each port.

Enable or disable HTTPS Redirection

Adds a security exception to the browser to allow certificate validity for HTTPS redirection.

Enable or disable Facebook Login

Enabling AAA Services with the Internal Web Server

Enabling AAA Services with an External Web Server

Redirects subscriber login requests to an external server in EWS mode for authentication.

Establishing Secure Administration {Access Control}

Access Control

Configurable Ports

Allows entry of Telnet Port and HTTP or HTTPS Port for configurable network access.

Block network-side interfaces

Provides options to block Telnet, Web Management, FTP, and SSH access for network interfaces.

Block subscriber-side interfaces

Provides options to block Telnet, Web Management, FTP, and SSH access for subscriber interfaces.

General Protocol Restrictions and Allowances

Allows SSLv2 and SSLv3, with TLS always permitted.

Defining Automatic Configuration Settings {Auto Configuration}

Enabling Auto Configuration

Drives automatic configuration of Nomadix devices via RADIUS and FTP for fast roll-outs.

Setting Up Bandwidth Management {Bandwidth Management}

Bandwidth Management

Manages subscriber bandwidth, defined in Kbps for upstream and downstream transmissions.

Group Bandwidth Limit Policy

Assigns a common bandwidth rate limiting policy to a group of subscriber devices.

Group Bandwidth Limit Policy – Operation

Explains how the NSE maintains and applies group bandwidth policies based on RADIUS ID.

Group Bandwidth Limit Policy – Current Table

Displays the group bandwidth policy ID in the Current Subscribers table.

Establishing Billing Records “Mirroring” {Bill Record Mirroring}

Sends copies of billing records to external servers for backup and transaction security.

Class-Based Queueing

To Enable and Configure Class-Based Queueing

Guides on enabling and configuring Class-Based Queueing for bandwidth management.

Assigning Users to a Class

Explains the four methods for assigning users to a particular class.

Clustering {Clustering}

To enable NSE Clustering

Guides on enabling NSE Clustering by configuring the total number of gateways and gateway number.

Configuring Destination HTTP Redirection {Destination HTTP Redirection}

Provides DNS-triggered redirection of HTTP requests to one or more configured portal page URLs.

Managing the DHCP service options {DHCP}

DHCP Settings

Configures DHCP services, including DHCP Server and DHCP Relay settings for IP assignment.

DHCP Options from RFC 2132

Allows configuration of DHCP options as defined in RFC 2132 for subscriber network configuration.

DHCP Dynamic Enable and Disable

Enables or disables DHCP dynamic enable and disable functionality without requiring a reboot.

Setting the DNS Options

Sets up DNS parameters, including host name, domain, and primary/secondary DNS servers.

Enabling DNSSEC Support

Adds authentication and integrity capability to DNS systems using DNSSEC support.

Managing the Dynamic DNS Options {Dynamic DNS}

Sets up Dynamic DNS (DDNS) options for automatic IP address updates.

Ethernet Ports/WAN

Enabling Fast Forwarding

Enhances overall system throughput and bandwidth with Fast Forwarding mode.

Interface Monitoring

Defining IPSec Tunnel Settings {IPSec}

Adding a new IPSec tunnel peer

Guides on adding a new IPSec tunnel peer or modifying existing ones.

Managing IPSec Security Policies

Allows adding or modifying IPSec security policies from the IPSec Tunnel Settings screen.

Load Balancing

Configuration

Configures load balancing settings, including failover modes and link availability criteria.

Establishing Your Location {Location}

Sets up the system location information for network configuration.

Managing the Log Options {Logging}

System Logging

Enables system logging using the standard SYSLOG protocol to send message logs.

AAA Log

Enables AAA logging for AAA functions, sending activity logs to a specified server.

Enabling MAC Authentication {MAC Authentication}

Assigning Passthrough Addresses {Passthrough Addresses}

Assigning a PMS Service {PMS}

Property Management System Settings

Setting Up Port Locations {Port-Location}

Port-Location Settings

Sets properties for each room from the subscriber side of the Access Gateway.

Add a Port-Location Assignment

Guides on adding a port-location assignment for rooms, apartments, or buildings.

Updating a Port-Location Assignment

Details how to update existing port-location assignments by modifying their fields.

Exporting Port-Location Assignments {Export}

Exports current port-location assignments to a “location.txt” file for backup.

Finding Port-Location Assignments by Description {Find by Description}

Finds port-location assignments based on their unique description for review.

Finding Port-Location Assignments by Location {Find by Location}

Finds port-location assignments based on their specified location for review.

Finding Port-Location Assignments by Port {Find by Port}

Finds port-location assignments based on their specified port (VLAN ID) for review.

Deleting Port-Location Assignments

Deletes particular port-location assignments from the system.

Enabling Facebook Login for a Port Location

Enables Facebook login for a specific port location for authentication.

Importing Port-Location Assignments {Import}

Subscriber Administration Menu

Adding Subscriber Profiles {Add}

Adds subscriber profiles to the database for authorized user management.

Adding a Device Type Profile

Adds a device profile to the subscriber database for management.

Adding a Group Type Profile

Adds a group account profile to the subscriber database for management.

Subscriber Intra-Port Communication

Deleting Subscriber Profiles by MAC Address {Delete by MAC}

Deleting Subscriber Profiles by User Name {Delete by User}

Deletes a subscriber profile from the database based on its user name.

Displaying the Currently Allocated DHCP Leases {DHCP Leases}

Lists currently active DHCP leases on the system's DHCP server.

Finding Subscriber Profiles by MAC Address {Find by MAC}

Finding Subscriber Profiles by User Name {Find by User}

Finds a subscriber profile based on its user name for statistics review.

Listing Subscriber Profiles {List Profiles}

Displays a list of authorized subscriber profiles based on user names and MAC addresses.

Subscriber Interface Menu

Defining the Billing Options {Billing Options}

Establishes various billing plans and rates, including messages and appearance settings.

Setting Up the Information and Control Console {ICC Setup}

Configures how the Information and Control Console (ICC) is displayed to subscribers for options.

Defining Languages {Language Support}

Defining Languages {Language Support}

Enable Serving of Local Web Pages {Local Web Server}

Importing the Factory Defaults {Factory}

Defining the Fail Over Options {Fail Over}

Viewing the History Log {History}

Establishing ICMP Blocking Parameters {ICMP}

Blocks ICMP traffic from pending or non-authenticated users for network security.

Importing Configuration Settings from the Archive File {Import}

Establishing Login Access Levels {Login}

Defining the MAC Filtering Options {MAC Filtering}

Utilizing Packet Capturing {Packet Capture}

Rebooting the System {Reboot}

Routing Tables {Routing}

Allows configuration of static routes and selection of WAN interfaces for specific network destinations.

Establishing Session Rate Limiting {Session Limit}

Adding/Deleting Static Ports {Static Port-Mapping}

Sets up or deletes static port-mapping schemes for forwarding packets to specific internal devices.

Updating the Access Gateway Firmware {Upgrade}

The Subscriber Interface

Overview

Provides an overview of the Subscriber Interface and its role in authorization and billing.

Authorization and Billing

Enables plug-and-play access to broadband networks with powerful billing support functionality.

The AAA Structure

Explains the Authentication, Authorization, and Accounting (AAA) module's functionality.

Internal and External Web Servers

Describes Web servers acting as login interfaces for subscribers and the network.

Language Support

Supports multiple Asian and European languages for the subscriber interface and web management.

Home Page Redirection

Configures redirection of valid subscribers to a Web portal or home page.

Subscriber Management

Subscriber Management Models

Outlines models for managing subscribers, including Free Access, MAC Address, and User Name.

Quick Reference Guide

Web Management Interface (WMI) Menus

Lists and explains menus within the Access Gateway's Web Management Interface.

Configuration Menu Items

Lists and describes items found within the Configuration menu.

Network Info Menu Items

Lists and describes items found within the Network Info menu.

Port-Location Menu Items

Lists and describes items found within the Port-Location menu.

Subscriber Administration Menu Items

Lists and describes items found within the Subscriber Administration menu.

Subscriber Interface Menu Items

Lists and describes items found within the Subscriber Interface menu.

System Menu Items

Alphabetical Listing of Menu Items (WMI)

Lists menu items alphabetically with their corresponding menu location.

Related product manuals