Marketing Flash Nomadix Key Features Overview. Introduction

Size: px
Start display at page:

Download "Marketing Flash Nomadix Key Features Overview. Introduction"

Transcription

1 Marketing Flash Nomadix Key Features Overview Introduction The Nomadix Public-access Gateways are stand-alone, dedicated network appliances placed at the edge solving key issues of connectivity, security, billing and roaming in Public-access networks. Nomadix offers 4 different platforms capable of serving a wide variety of venue types including airports, hotels, convention centers, college campuses and Wi-Fi HotSpots: AG2100 AG3000 AG5000 AG5000 Metro Based on the proven USG platform that has been successfully deployed in thousands of locations worldwide, the AG family of Gateways handles transparent connectivity, authentication, bandwidth shaping, and service placement supporting flexible configurations of up to 4,000 simultaneous users in a broadband-enabled environment. The AG5000 offers: Up to 2,000 simultaneous users Mobile Connectivity Advanced Security and Access Control Network-based Authentication Bandwidth Management Service Presentment Integration of a Nomadix Gateway into the network enables the rapid rollout of ubiquitous broadband Internet services in any public hot spot. The Nomadix offer a unique set of security and connectivity features for service providers needing to provide universal connectivity and network-based authentication and service presentment. Designed for smaller scale deployments, the AG2100 (max. 50 subscribers) and the AG3000 (max. 200 subscribers) are the platforms of choice. For larger deployments such as airports and larger hotels, the AG5000 platforms can support up to 2,000 subscribers and is the ideal product for these locations.

2 Table of Contents Introduction... 1 Table of Contents... 2 Listing of Nomadix Key Areas... 4 Plug and Play... 4 Dynamic Address Translation TM... 4 Dynamic Transparent Proxy Support... 5 STUN Support... 5 HTTPS Support... 5 Service Presentment... 5 Internal Web Server (IWS)... 6 Local Web Server... 7 External Web Server (EWS)... 7 Login Page Failover... 7 Information and Control Console (ICC)... 7 Explicit Logout pop-up window... 7 Portal Page Parameter Passing... 7 Goodbye URL Support... 8 Screen Size and JAVA Detect... 9 Splash Screen and Partner Image... 9 International Language Support... 9 End User VPN support inat TM Functionality inat TM UDP Packet Fragmentation Support Bandwidth management End User Bandwidth Management Wide Area Network side Bandwidth Management Simultaneous Authentication AAA MAC based Authentication Group Accounts IEEE 802.1x Support RADIUS (AAA) Proxy NAI Routing Smart Client Support RADIUS Re-authentication Idle User Management Cookie Placement ( Remember Me feature) RFC 1493 Cascading Support Billing Billing Options Duration-based Billing Stand-alone Billing PMS-support PMS Query support... 15

3 Post-paid PMS billing Credit Card payments Simultaneous billing time parameter IWS Max. billable unit support for PMS and Credit Card billing RADIUS based Billing RADIUS Attributes RADIUS counting Packets Sent/Received Nomadix RADIUS Vendor Specific Attributes (VSA) Free Access Monitoring Port-based Policies Security Selective Access Control Tracking Syslogs SSL support for Internal Web Server Increased Device Security URL Filtering Proxy ARP Support Security and Denial of Service Management Session Rate Limiting and MAC Filtering ICMP Blocking Secure XML End User IP address management Multiple DHCP Pools and Subnets IP Address Upsell SNMP Re-Direct SMTP Support for correctly configured subscribers DNS support for SMTP redirect Network Management Management Interfaces Static Port Mapping for Devices on Private IPs Location Identifier One click DAT TM session clearance Help Link at Login Screen Administrative Access policy setting Remote Authentication Testing Facility Easier Troubleshooting and Setup Centralized Management SNMP MIB High-Availability Fail-over Remote (central) Printer support Driverless Printing (Click 2 Print)... 23

4 Listing of Nomadix Key Areas Plug and Play Dynamic Address Translation TM Technical barriers have previously stood in the way of providing profitable, customerfriendly ubiquitous Internet access most notably, the expense and complication of reconfiguring every computer or device so it can access the Internet regardless of how it was originally configured. No client side software Transparent HTTP Proxy support (subscriber does not need to disable their proxies). DNS (Domain Name Server) Redirection (Subscriber s DNS request are redirected to a local server). SMTP server redirection support (subscriber s outgoing will be redirected to a local server). Nomadix patented Dynamic Address Translation (DAT ) function offers a true plugand-play solution that provides transparent broadband network connectivity covering every PC configuration (static IP, DHCP, DNS, and proxies), ensuring that everyone gets access to the Public-access hot spot or Visitor-based Network (VBN). In addition, Nomadix delivers additional advanced plug-n-play features that allow the seamless sending of , as well as the transparent usage of VPN services (IPSEC, PPTP) and popular applications such as NetMeeting in an address translated network. No client-side software or changes to the PC s configuration are required in order to get connected in an NSE-enabled network. Nomadix developed DAT to actively monitor every packet transmitted from each device to ensure each packet is correctly configured for the network that the computer is expecting. The result, every customer can get access to the network without having to reconfigure his computer, PDA or other Internet access device or load client-side software. DAT also ensures that a DNS server is always available to a user through the DNS redirection function. The DNS redirection function redirects a user s DNS requests to a

5 local DNS server closer to the customer s location. This improves the response time and enables true plug-and-play access when the subscriber s configured DNS server is behind a firewall or located on a private Intranet. Dynamic Transparent Proxy Support From 4.3 release, Gateways supports clients that dynamically change their browser s proxy status from non-proxy to proxy. Also, transparent proxy support has been enhanced by offering support for additional assigned port ranges (e.g. ports , 911). STUN Support The NSE Dynamic Address Translation (DAT) functionality has been enhanced to support the STUN Protocol and to conform to a restricted cone network address translation (NAT_ style of operation. HTTPS Support It is possible for the administrator to set the AG to pass-thru HTTPS traffic in addition to standard port 80 traffic without being redirected. Once access to a non-https address (such as a stock broker or bank) has been requested, the subscriber will then be redirected as usual. Service Presentment Once connected to the Public-access hot spot or VBN, a customer needs to be directed to a Web site for local or personalized services, or to establish an account and pay for services. For example, in an airport, a customer using an wireless LAN device can be presented with flight information. In a hotel, guests can be presented with local concierge services, network-based printing offers or other ecommerce content.

6 Nomadix has developed sophisticated web page redirection technology that allows the service provider to control the initial content experience prior and/or post authentication. Internal Web Server (IWS) The Nomadix Gateways contain an Internal Web Server that can deliver SSL encrypted web pages that come pre-configured for user authentication and authorization. All core parameters of these web pages (e.g. logos, text, font, colors) can be changed without any knowledge of HTML. A banner at the top of each Internal Web Server page is configurable and can contain the hot spot owner s logo or any other image they desire. Login or New Account Verify and Purchase Service Selection

7 Local Web Server This release introduces the Local Web Server capability which enables the NSE to host a limited number of web pages locally on its flash. These web pages can be served to the subscribers during pre-authentication or during post-authentication phase. These web pages can be updated remotely and uploaded using FTP on to the NSE. With this capability there is no need to have a dedicated web server on site if the requirement is to serve a few custom web pages to the end users. External Web Server (EWS) In External Web Server mode, the URL is defined where the graphics contents of the Home Page Redirect is stored. Login Page Failover For installations that use an External Web Server or a Portal Server to provision their Login and Authentication Pages to the subscribers, the Login Page Failover feature provides a way for administrators to configure secondary or tertiary Login Pages in case the primary Login Page becomes unavailable. This mechanism guarantees that the subscribers will have some way of authenticating themselves and accessing the Internet ifthe External and Portal Servers fail. Information and Control Console (ICC) The ICC drives a JAVA-based applet down to each customer s Internet Browser providing them with the ability to self-select services, upgrade their bandwidth and service plans in a real-time fashion. The existing JAVA-based ICC has been replaced with an HTML/Javascript version to enhance its performance and reduce browser compatibility issues while also allowing its distribution from a centralized location/server. (from 4.3 onwards) The ICC allows the premise owner or service provider to send custom messages and advertising directly to the screen of the customer. For credit card and PMS usage, the ICC displays a dynamic time field to inform customers of the time remaining on their account. Explicit Logout pop-up window The NSE lets the administrator define a simple HTML-based pop-up window for explicit logout that can be used as an alternative to the more fully featured ICC. The Pop Up Log-Out button contains the opportunity to display the elapsed/count-down time and one logo for intra-session service branding. (from 4.3 onwards) Portal Page Parameter Passing The Portal Page Redirect (PPR) feature of the Nomadix Gateways enables the Publicaccess network to intercept the browser s home page setting prior to authentication and redirect it to a new portal page determined by the service provider or premise owner.

8 When redirecting the customer to a new home page, the original home page (Origin Server) is passed as a parameter to the new home page so the customer can still access their default home page after the local or personalized page has been presented. The Home Page Redirect (HPR) feature of the Nomadix Gateways allow the service provider to display a post-authentication web page tailored either to the users location (e.g. Train Schedules for HotSpot at Waterloo Station) or the user himself (e.g. Welcome John Smith here is your personalized home page for the HotSpot Service). The Gateways contain a comprehensive HTTP page redirection logic that allows for a page redirect before (aka Portal Page Redirect) and/or after the authentication process (aka Home Page Redirect). A defined set of parameters to the portal page redirection logic allows an External Web Server to perform a redirection based on: VLAN ID Subscriber MAC address Externally hosted RADIUS login failure page This means that the network administrator can now perform location-specific service branding (e.g. for an airport lounge) from a centralized web server. Radius Home Page Redirect This feature allows the Gateway to receive a Nomadix VSA from the RADIUS server for URL redirect. This feature provides a method for each user to be redirected to a different site upon login based on a RADIUS attribute. Goodbye URL Support From 4.3 release, Nomadix has created a 5 th step in Service Branding for Operators and other Public-access network operators; the Goodbye Page. The 5 steps in Service Branding now capable in a Nomadix-enabled network include the following: 1. Initial Flash Page branding. 2. Initial Portal Page Redirect (Pre-Authentication). Typically, this is used to redirect the user to a venue-specific welcome and login page. 3. Home Page Redirect (Post-Authentication). This redirect page can be set to the individual user (as part of the RADIUS Reply message, the URL is received by the Nomadix Access Gateway) or set to re-display itself at freely configurable intervals. 4. The ICC contains multiple opportunities for the Operator to display its branding or the branding of partners during the user session. 5. The Goodbye page is a post session page that can either be defined as a RADIUS VSA or be driven by the internal web server in the NSE. Using the Internal Web Server option means that this functionality is available for other post-paid billing mechanisms (e.g. post-paid PMS) as well. This IWS page displays the details of the user s connection such as: - IP address of the user - Type of AAA - Start/Stop time - Bytes sent/received - Freely configurable Hypertext link (in case the ISP wants to link the user back to a sign-up/help page page) The Nomadix 5-Step Service Branding Methodology

9 Screen Size and JAVA Detect In order to better support PDAs and other handheld devices, the Nomadix Gateways contain functionality that will automatically format the IWS pages to a screen size that is optimal for the particular device. Since most PDAs today do not support JAVA applets, the Gateway will also contain the necessary intelligence to prevent inconclusive JAVA error messages caused by the IWS. Splash Screen and Partner Image Allow the display of the You are being connected screen and Partner Image even when AAA is turned off. International Language Support Nomadix supports international customers by providing translations of the Information and Control Console (ICC) into Japanese, Chinese, French, German and Spanish. The AG platform allows all IWS text to be freely configurable/translatable. This includes both the text in the IWS dialog boxes and the text on the IWS buttons (e.g. Enter, Back, etc).

10 End User VPN support inat TM Functionality The inat TM feature measurably improves the connection success rate of multiple VPN tunnels to the same termination device, while optimizing the usage of available public IP addresses. It uniquely supports users with static private (e.g x.x) or public (different subnet) IP addresses without any client IP setting changes It dynamically adjusts the mode of address translation during the user s session depending on the packet type inat TM dramatically heightens the reusability factor of costly public IP addresses ( only use them when you need them ), while maintaining the security benefits of traditional address-translation technologies inat TM UDP Packet Fragmentation Support (From version 4.3). Nomadix recently added support for UDP fragmentation within inat to provide more seamless support for certificate-based VPN connections. End User Bandwidth Management Bandwidth management The Bandwidth Management feature of the Nomadix Gateway enables service providers to limit bandwidth usage on a per device (MAC Address/User) basis. This ensures every user has a quality experience by placing a bandwidth ceiling on each device accessing the network so every user gets a fair share of the available bandwidth. The bandwidth for each device can be defined asymmetrically for both upstream and downstream data transmissions. The service provider can also allow the individual user to increase or decrease their bandwidth and/or change their IP address type (private vs. public) dynamically without having to disconnect or re-establish a new session. Wide Area Network side Bandwidth Management The Nomadix Gateway can also manage the WAN Link traffic providing complete bandwidth management through the Public-access hot spot. Bandwidth Management shapes traffic going over the WAN link to prevent its over-utilization. The Gateway queues traffic from overly busy instances in time, and send the packets over the WAN Link when a lull in traffic occurs. Simultaneous Authentication

11 AAA A Nomadix-enabled network can automatically authenticate, authorize, track, and bill users for broadband access. Customers can be identified and billed according to their Media Access Control (MAC) address, username/password, and/or port identification number. The Authentication, Authorization and Accounting (AAA) module of the Gateway offers various tracking, billing and security features for Web based self-provisioning, including RADIUS Authentication, Authorization and Accounting as well as credit card billing. The AG also supports an open XML Interface for control and integration with other network components. The Nomadix Gateway also simultaneously supports various proprietary and standardsbased authentication methods such as IEEE 802.1x and client-based solutions such as those provided by Boingo Wireless, ipass and GRIC the goal of which is to automate the authentication process rendering the wholesale service provider transparent and enabling Global Roaming across wireless LAN networks at the client level. MAC based Authentication The NSE already supports authentication for Web-based Universal Access Method (UAM) clients and IEEE 802.1x clients. This release adds another method known as MAC authentication. MAC authentication makes it possible for devices that do not support a browser (like PSP, VoIP phones etc.) to be authenticated based on the device MAC address. With this unique methodology, these devices can be automatically authenticated against a RADIUS server using their MAC addresses while simultaneously supporting other types of subscribers, via UAM or IEEE 802.1x. Group Accounts The NSE now supports group accounts or concurrent logins. Administrators can create a special group account with a group username and password. Group members can then login using these credentials. This feature is useful when giving out access to groups of users for special occasions. IEEE 802.1x Support Nomadix supports the IEEE 802.1x standard for port-based authentication x is a standard for port-based Access Control that can be used by LAN access concentrators (such as wireless Access Points, switches, hubs, etc.) to turn ports (points where the clients connect to the concentrator) on and off based on the authentication state of the client In order to deploy 802.1x in a network, support for the standard must be present in the client computer (via Windows XP), the point of aggregation (e.g. Access Point) and in the RADIUS server. Also note that many companies are coming out with their own 802.1x clients and that Microsoft is planning patches to most of its Operating Systems to support 802.1x The Nomadix Gateway can now take the place of the Authenticator in an 802.1x enabled network which is a function typically done by an Access Point or some other

12 LAN access concentrator. By becoming the Authenticator, the Nomadix Gateway allows the deployment of lower costs, non-802.1x enabled Access Points but still derive the benefits of 802.1x within the network. It also allows the administrator to deploy a network that can support both 802.1x enabled clients and non-802.1x enabled clients simultaneously. Edge-driven WISP Roaming RADIUS (AAA) Proxy The purpose of the RADIUS or AAA Proxy functionality in the NSE is to relay authentication and accounting packets between the parties performing the authentication process. Different realms can be set up to directly channel RADIUS messages to the various RADIUS servers. This functionality can be effectively deployed to: Support a wholesale WISP model directly from the edge without the need for any centralized AAA proxy infrastructure Support EAP authenticators (e.g. WLAN Access Point) on the subscriber-side of the NSE to transparently proxy all EAP types (e.g. TLS, SIM) and to allow for the distribution of per-session keys to EAP authenticators and supplicants. NAI Routing Complementing the RADIUS Proxy functionality in the NSE is the ability to route RADIUS messages depending on the Network Access Identifier (NAI). Both prefix (e.g. ISP/username@ISP.net) and suffix-based (username@isp.net) NAI routing mechanisms are supported. Together, the RADIUS Proxy and NAI Routing further support the deployment of the Wholesale Wi-Fi model allowing multiple providers to service one location. Smart Client Support Nomadix supports various broadband Smart Clients being sold to Enterprise users. Support is provided for Smart Clients from ipass, GRIC and Boingo. ipass Generic Interface Specification (GIS) is supported (from 4.3 onwards). Support for all these types of authentication mechanisms enables the concept of global roaming where one bill can follow a mobile professional where ever they travel A dedicated White Paper explaining this new functionality is available from Nomadix tech support. RADIUS Re-authentication Nomadix RADIUS Re-authentication feature supports multiple MAC addresses per UN/PW combination. This enhances the user-friendliness of this feature for users with multiple PCs that only want to use one login. The RADIUS Re-Authentication buffer contained within the NSE has been expanded (from 48) to 720 hours, thus allowing an even more seamless and transparent connection experience for repeat users. (from 4.3 onwards)

13 Idle User Management There is an option to force Credit Card and PMS subscribers to enter a username and password when they purchase Internet Access. Nomadix allows the network administrator to set a policy to force the user to login after being idle even if they are coming in from the same MAC address. Cookie Placement ( Remember Me feature) This feature allows the IWS to store an encrypted Login Cookie in the browser to "Remember me" using UN/PW/NAI between Access Points, thus creating a better user experience in wireless networks. RFC 1493 Cascading Support From a network architecture perspective, it is common practice to cascade multiple DSLAMs or switches together so a service provider or property owner can increase the port density of the in-building access concentration equipment. Certain Nomadix Gateways are capable supporting up to fifty (50) RFC 1493 compliant DSLAMs, TUT MDU Lite, HR and LR DSLAMs that are cascaded together to correctly perform port location. Nomadix also supports any RFC 1493 compliant 3COM/ RC Networks device that is designed in a cascaded or parallel configuration. In a cascaded configuration, one central switch may control several secondary switches in order to obtain network related information. Thus, the Nomadix Gateway will be able to query the primary switch to retrieve MIB information from the primary switch and any secondary switches. In a parallel configuration, the switches act as peers to one another and will send distinct MIB queries to the Gateway. Billing Options Nomadix provides a very rich set of billing features. 1. Local billing features Connection to Hotel Property Management System for bill to my room Internal AG database for ad-hoc creation of UN/PW 2. Central billing features Credit Card payments (cleared by a remote Credit Card broker) RADIUS Duration-based Billing Billing The purpose of this feature is to let hotels create billing plans that work in a similar fashion to pre-paid telephone cards. This means an Operator can set the Internal Web Server (IWS) of the NSE to let users online for time x over period y. Standard billing plans (time x = period y) can be used concurrently. For example, multiple plans with flexible billing event options can be rolled out such as:

14 - Plan A: 24 hours, 256kbit/s downstream, 128kbit/s upstream, public IP address, $15 - Plan B: 8 hours to be used over 5 days, 512kbit/s downstream, 256kbit/s upstream, private IP address, $35 - Plan C: 1 week, 1mbit/s downstream, 1mbit/s upstream, public IP address, $99 In addition to credit card billing, Property Management Systems used by hotels are also supported along with the internal data base of the NSE and billing via Nomadix secure XML API. Stand-alone Billing From version 4.3 of the NSE, Gateway supports the option to let the administrator create a set of user profiles (Username, Password, Duration, Bandwidth Up, Bandwidth Down) in the internal database and then start the count down timer upon user login. This functionality has also been added to the NSE s secure XML API. Applications of this functionality can be found in the hospitality arena, as well as in smaller scale stand-alone Public-access networks (e.g. hospitals). PMS-support Nomadix continues to provide certified interoperability with the largest number of property management systems (PMS) in the market. The Nomadix Gateway interoperates with all HOBIC protocol based PMS system, all PMS systems used by Hilton, PMS protocol used in the NH Hotel Group, the Xeta Virtual XL TM call accounting system, Ramesys ImagInn TM, Marriott s proprietary PMS solution, System 21 PMS and igets.net. It also offers post-paid usage-based PMS billing and a private DNS logout option 2-Way OnQ (System 21) Compliance (From version 4.3) The NSE s proven Micros POS emulation interface has been adapted to be interoperable with Hilton Corporation s OnQ PMS system. OnQ is quickly replacing all legacy PMS installations within Hilton North America (H1, H2) and currently Nomadix is the only Gateway vendor that has both approved 1-Way (i.e. posting only, generally used in wired networks) and 2-Way interfaces (i.e. query and post, specifically developed to support Wi-Fi-enabled hotel networks). Galaxy PMS Support (From version 4.3) This release offers a 2-way interface to the Galaxy PMS system. Micros FIAS Interface Compliance (From version 4.3) Nomadix has extended its existing interfaces to the popular Micros Fidelio PMS system to include three new interfaces. These interfaces have been tested and approved by Micros Fidelio. In detail, the new interfaces are: - TCP/IP interface for PMS post messages to Micros Fidelio Opera - Serial FIAS-compliant post interface

15 - Serial FIAS-compliant extension to the existing Micros POS (i.e. 2-Way) emulation. The new interface includes the option to define a third query field (i.e. reservation number) to enhance security in wireless high-speed Internet access networks in hotels. PMS Query support Nomadix is able to query most popular PMS systems for confirmation of the name and room number of the hotel guest/s. In essence, the Gateway will be a clone of a popular Micros POS system. This will allow the hotel to seamlessly deploy wireless networks or, alternatively, use low-cost wired access concentration equipment (e.g. certain HPNA gateways, DSLAMs, CMTS solutions or even plain hubs) that either do not support port-id or do so in a proprietary format that Nomadix does not currently support and still be able to bill directly to the room. As with standard posting interfaces, most PMS vendors are likely to charge additional fees for the PMS query interface. This feature was developed based on the Micros Specification for 1700/2000/3700/4700/8700 system software (Part Number: ). PMS solution vendors that have informed Nomadix about their interoperability with the above specification include Micros, Hilton (H1, H2, System 21), HIS, Marriott and GETS. Post-paid PMS billing Nomadix first implemented post-paid PMS billing logic to support the proprietary NH PMS interface. Now, this billing logic has been extended to support all existing PMS interfaces (e.g. all five HOBIC versions, Marriott, Micros Fidelio, etc.). With the new functionality, the hotel guest now has the option to terminate his connection (via the ICC) and be only billed for the actual time he/she was online. Credit Card payments Advanced functionality, such as integration with on-line secure credit card based selfprovisioning, allows the customer to setup a credit or time based pre-paid account. Also, in order to support a revenue splitting business model between access providers and service provider, an integrated Billing Mirror capability is provided that performs logging of customer s billing activities to more than one server. This allows BT to perform adhoc, pay-per-use service creation a critical function to grow its customer base. Simultaneous billing time parameter IWS Nomadix has support for multiple simultaneous billing plans using PMS or Credit Card AAA. For example, a hotel can now offer an hourly plan (e.g. $2) and a daily plan (e.g. $15) at the same time without any External Web Server based XML scripts. Incentive-based Billing: Promotional/discount code support for PMS and Credit Card billing. This functionality offers you the opportunity to provide price incentives to preferred customer groups

16 Max. billable unit support for PMS and Credit Card billing In conjunction with the Minimum billable unit support, the Maximum billable unit support allows you to define a range of values that the end-user can enter to purchase access, thus preventing user complaints RADIUS based Billing Nomadix has an integrated RADIUS client allowing the service provider to track or bill based upon number of connections, location of the connection, bytes sent and received, connect time, etc. The customer database can exist in a central RADIUS Server, along with associated attributes for each user. When a customer connects into the network, the RADIUS client authenticates the customer with the RADIUS Server, applies associated attributes stored in that customer s profile, and logs their activity (including bytes transferred, connect time, etc.). Our RADIUS implementation also handles vendorspecific attributes (VSAs) required by the emerging class of wireless service providers like BT and others that want to enable more advanced services and billing schemes such as a fixed per device per month connectivity fee. RADIUS Attributes RADIUS Attributes are available to enhance the flexibility of the Nomadix Gateway. These new RADIUS attributes include: NAS-IP Address NAS-Port-Type Acct-Session-ID EAP-Packet Message-Authenticator State Acct-Interim-Interval Acct-Output-Packets Acct-Input-Packets Called-Station-ID Calling-Station-ID RADIUS counting Packets Sent/Received The RADIUS Accounting Start Packets Sent and Received values can be reset to zero after login which gives the network administrator the option of either counting or not counting Walled Garden traffic Nomadix RADIUS Vendor Specific Attributes (VSA) Time-based session timeout. (to terminate a session once a specified time period has been reached) Specified as date and time (e.g. 24:00/30 July 2003). This enhances the usability of the product for pre-paid card visitor-based broadband networks. Volume-Based Session Timeout (to terminate a session once a specified data volume has been reached)

17 Log-Off-URL (to allow the placement of a Log-Off-URL e.g on an external portal page) Reject-Message (to allow the customization of reject messages); Session-Terminate-End-Of-Day (to allow business policies terminating the session at midnight of every day) Subnet (to allocate a specific subnet to a user) Please see RADIUS Overview Specification for additional details on the AG RADIUS implementation Free Access Monitoring Nomadix is able to send usage information of free access or non-authenticated users to external servers similar to the existing billing mirror feature. Port-based Policies The Port Location capabilities on the NSE have been enhanced. It is now possible to define a policy per port. The billing methods (RADIUS, Credit Card, PMS, L2TP Tunneling) and the billing plans available on each port can now be individually configured. A practical application of this feature is to have a hotel guest room with a plan that is for $9.99 a day with and ability to bill to the room using the property management system (PMS) billing and have a hotel meeting room with a plan of $14.99 an hour with Credit Card billing. Security Selective Access Control The Nomadix Gateways can be used to create a walled garden, allowing visitors to access the network to predetermined Web sites, services or applications even though they may not have subscribed to the broadband Internet service. A Nomadix-enabled network provides up to 300 IP pass-through addresses and allows the service provider to enforce security based upon whether or not the customer has been authenticated. The walled garden can be used to push local content and services providing a custom experience dependent upon the public hot spot owner. By allowing selective access control to the network before the customer authenticates themselves, service selection and Web based self-provisioning can be provided in a standard, efficient, low cost and convenient way that does not depend upon the transport technology (wired or wireless). Tracking Syslogs The NSE now supports Tracking Syslogs. This is a part of the Nomadic Lawful Intercept compliance strategy. The Tracking Syslogs can be enabled to monitor all the port assignments for the users accessing a public network. These tracking logs enable trace-back to a particular MAC address and Username based on port and IP information available to an external site that has been attacked, hacked or used in an illegal fashion.

18 The tracking logs carry the following information. 1) Time Stamp 2) Source IP 3) Source Port 4) Destination IP 5) Destination Port 6) Translated IP 7) Translated Port 8) User Details a. MAC Address b. Local IP assigned c. Type of user (RADIUS, PMS, Credit Card, XML, Admin Added...) d. Username (if available) A Sample Tracking Log example: :11:29 Local1.Info INFO [HSG v ] LI : IN-->: FRI JUN 24 00:57: Site Name S( /3562), D( /3478), X( /5003), non-proxy, 00:90:27:78:81:00, RADIUS, IPASS/0U0000 SSL support for Internal Web Server This feature allow for the creation of an end-to-end encrypted link between the Noamdix Gateway and the clients by enabling the IWS to display pages under a secure link. This is important when transmitting AAA information in a wireless network, in particular when using RADIUS. Adding SSL support to the Gateway s functionality will also mean that the service provider will have to obtain a digital certificate from VeriSign to create HTTPS pages. Charges for the certificate depend on the encryption level (40bit or 128 bit) and generally range from approx. $350 to $900. Instructions on how to obtain such certificates will be furnished by Nomadix. Increased Device Security The Nomadix Gateways now incorporates a master access control list that checks the source (IP address) of administrator logins. This allows an administrator login only if a match is made with the master list contained on the product. If a match is not made, the login is denied, even if a correct login name and password are supplied. The access control list supports up to 50 entries in the form of a specific IP address. URL Filtering The Nomadix Gateway can now restrict access to up to 300 specified websites based on URLs defined by the administrator. URL filtering will block access to a list of sites and/or domains entered by the administrator via three ways: Host IP address (e.g ) Host DNS name (e.g. DNS domain name (e.g. *.yahoo.com, meaning all sites under the yahoo.com hierarchy, e.g. finance.yahoo.com, sports.yahoo.com, etc).

19 The system administrator will be able to dynamically add or remove specific IP addresses and domain names to be filtered for each property allowing service providers and property owners to restrict certain sites from being visited, i.e. pornography, gambling, etc. Proxy ARP Support Network administrators can enable simultaneous network security and same subnet VoIP communication with the flexible proxy ARP definition feature. Changes in the WMI enable the easy configuration of the Proxy ARP functionality Security and Denial of Service Management Session Rate Limiting and MAC Filtering Session Rate Limiting (SRL) and MAC Address Filtering provide enhancements to Nomadix Access Control technology; significantly reducing the risks of Denial of Service attacks by allowing administrators to throttle the number sessions any one user can take over a given time period and if necessary, then block a malicious user. ICMP Blocking This release of the NSE now contains the option to block all ICMP traffic from pending or non authenticated users that are destined to addresses other than those defined in the pass-through (walled garden) list. Please note that the default setting for this option is off since ICMP pass-through is a useful end-user troubleshooting feature and also required by certain smart clients (e.g. GRIC). Secure XML This feature allows the Operator to use Nomadix popular XML API using the built-in SSL certificate functionality in the NSE so parameters passed between the Gateway and the centralized web server are secured via SSL. Multiple DHCP Pools and Subnets End User IP address management Subnets and DHCP pool scopes can be assigned a number by a variety of methods such as:

20 Location ID (e.g. via VLAN ID) Nomadix RADIUS VSA ( Subnet ) Administratively assigned The Nomadix Gateways have two separate DHCP pools that can be defined. The first pool of addresses will contain private addresses; the second will contain public addresses. This feature allows a service provider to keep a centralized pool of public IP addresses at the NOC and use the Gateway to distribute private IP addresses. When a subscriber selects a service plan with a public pool address, Nomadix will associate their MAC address with their public IP address for the duration of the service level agreement. This feature also allows the administrator to set two different DHCP pools for the same physical LAN. Multi-subnet support allows you to: Use non-contiguous public DHCP pools. For example, if you need to provide Internet access to 1,000 DHCP users and only have non-contiguous Class C pools, you can now define these separate pools in the Nomadix gateway Use mixed public and private pools to meet the requirements of a varied network topology as well as customer sets (residential vs. business). For example, all residential users will get a private IP address and be address translated, whereas all business customers will get a public IP and not be address translated Differentiate your customers depending on their location. For example, you may want to place all users in one building in the same VLAN and provision all their IP address from a dedicated pool Allocate different lease times to different users dependent on the peak usage patterns of the network Keep all devices (e.g. Access Points) on a separate public subnet that will not get address translated IP Address Upsell IP Upsell provides another method of revenue generation for the service provider by allowing the upsell of added services by purchasing public IP addresses. SMTP Support for correctly configured subscribers SNMP Re-Direct The administrator could set the Nomadix Gateway to pass all SMTP traffic through the SMTP relay server independent of the PC s settings. DNS support for SMTP redirect This functionality allows you to use DNS load balancing for your SMTP servers Management Interfaces The following interfaces are supported Network Management

21 Command Line Interface (CLI), i.e. A terminal session directly connected via a serial cable. Telnet session, i.e. Similar to CLI but remotely done Web Management Interface (WMI) i.e. Remotely through any Web Browser. FTP (File Transfer Protocol)., i.e For managing files in the flash of the Nomadix Access Gateway SNMP (Simple Network Management Protocol) Using stander networking tools. Web Management Interface (WMI) and Command Line Interface (CLI) interfaces are synchronized in several key areas (e.g. dmac, Current, URL filtering). This expands the management options for network administrators. Now most of the commonly used configuration options are available in both the WMI and CLI. The CLI displays the bytes sent and received for every MAC address The number of simultaneous operator logins has been extended to 3. This aligns the feature with most carrier help desk operations. In order to ease the initial setup and ongoing configuration of the NSE, the Subscriber Side Configuration UI feature allows administrators to access the configuration interfaces (WMI, CLI, TELNET, SFTP, and SSH) from the Subscriber/LAN side of the NSE. Prior to this feature, the only way to get access to the configuration interface was through the Network/WAN interface. This is particularly useful for the wireless gateway, and can facilitate substantial savings in time and effort in implementing installation and configuration changes. Static Port Mapping for Devices on Private IPs This feature allows the network administrator to setup a port mapping scheme that forwards packets received on a specific port to a particular static IP (typically private and mis-configured) and port number on the subscriber side of the NSE. The advantage for the network administrator is that free private IP addresses can be used to manage devices (such as Access Points) on the subscriber side of the NSE without setting them up with Public IP addresses. Location Identifier The purpose of this feature is to aid in the management and monitoring of multiple NSE devices via a browser by placing the Location information of the NSE device in the corner of the WMI screen. This allows the administrator to quickly identify which location he is viewing when multiple browser windows are open. One click DAT TM session clearance Network administrators can now clear all existing DAT TM sessions without rebooting the device to overcome any potential session limitation issues Help Link at Login Screen The Internal Web Server Login page will now allow a Help link that is configurable by the Administrator

22 Administrative Access policy setting The Network Administrator will now be able to define two levels of administrative access Manager Level: Read, Write and Reboot access to all configuration screens Operator Level: Read only access to all configuration screens This provides the ability for a desk clerk to be able to view the status of the Gateway without risking damaging configuration changes It will also provide a Management Access history which details the last 500 entry logs of administrative access Remote Authentication Testing Facility Nomadix provides a "secure" web page (password protected) that enables an administrator to type a username/password that commands the Gateway to send a RADIUS Access-Request to the RADIUS Server following the same basic rules as if it was from a subscriber. The Gateway would send a meta-refresh HTTP page (displaying "Please wait...") until it displays an error/success message (accept, reject, timeout, internal failure) result. This enables an administrator to test the back-end RADIUS implementation remotely Easier Troubleshooting and Setup The Nomadix Gateways platform now allows complete and unconditional access to devices on the subscriber side with its Bridge Mode feature. When Bridge Mode is enabled, it is effectively transparent to the network in which it is located, allowing clusters of switches (especially Cisco Systems switch clusters) to be managed using STP (Spanning Tree Protocol). All packets are unmodified and can be forwarded in both directions (except those addressed to the Gateway s network side port). Bridge Mode provides easier troubleshooting of the network by removing the Gateway from the network without physically taking it out of the rack. Centralized Management The Nomadix Gateways enable system administrators to upgrade the firmware for all Gateways in their network from a new, stand-alone Centralized Management Application. This supports a simple, easy, remote upgrading of the Gateways to new releases of code.

23 SNMP MIB The Nomadix SNMP MIB includes MIB objects for all relevant configuration parameters. Fail-over High-Availability Many large scale highly prominent networks (e.g. tradeshows, convention centers, etc.) require Fail-over support for all devices in the Public-access network. From 4.3 release of the NSE, the Gateway allows two Nomadix Gateways to act as siblings, where one device will take up the users should the other device become disconnected from the network. As part of this functionality, the settings (except IP addresses) between the two devices will be synchronized automatically. Driverless Printing (Click 2 Print) Remote (central) Printer support Nomadix partnered with Peerless Systems to create a driverless printing solution to allow subscribers to print documents via an Internet Browser without having to make any configuration or driver changes to the subscriber s computer. Peerless Systems has added XML support to their Print Server to communicate with the Nomadix Gateway to allow for billing integration. The Click 2 Print driverless printing solution: Supports printing web pages and offers a print preview option; Allows the print server to be centrally placed in-building or at the NOC to control multiple properties Supports a wide variety of file formats Driverless printing creates another revenue source for the property owner by providing printing services 24 hours a day without requiring the guest to make any configuration changes to their computer.

Copyright 2011 Nomadix, Inc. All Rights Reserved. 30851 Agoura Road Suite 102 Agoura Hills, CA 91301 USA www.nomadix.com. White Paper 230-1039-001

Copyright 2011 Nomadix, Inc. All Rights Reserved. 30851 Agoura Road Suite 102 Agoura Hills, CA 91301 USA www.nomadix.com. White Paper 230-1039-001 Nomadix Service Engine Hospitality Application Copyright 2011 Nomadix, Inc. All Rights Reserved. 30851 Agoura Road Suite 102 Agoura Hills, CA 91301 USA www.nomadix.com 230-1039-001 Sheet 2 of 5 Introduction

More information

Application Note Secure Enterprise Guest Access August 2004

Application Note Secure Enterprise Guest Access August 2004 Application Note Secure Enterprise Guest Access August 2004 Introduction More and more enterprises recognize the need to provide easy, hassle-free high speed internet access to people visiting their offices,

More information

HotSpot Gateway Copyright 2005 Nomadix, Inc. All Rights Reserved.

HotSpot Gateway Copyright 2005 Nomadix, Inc. All Rights Reserved. HotSpot Gateway Copyright 2005 Nomadix, Inc. All Rights Reserved. This product also includes software developed by: The University of California, Berkeley and its contributors; Carnegie Mellon University,

More information

Enterprise Wireless LAN. Key Features. Benefits. Hotspot/Service Gateway Series

Enterprise Wireless LAN. Key Features. Benefits. Hotspot/Service Gateway Series Key Features Comprehensive Wireless Internet Access Solution Zero Configuration IP Plug and Play Unique Ticket Printer for Easy Service and Accounting Web-based User Authentication, Account Monitoring,

More information

White Paper. Copyright 2011 Nomadix, Inc. All Rights Reserved. Thursday, January 05, 2012

White Paper. Copyright 2011 Nomadix, Inc. All Rights Reserved. Thursday, January 05, 2012 Choosing the Right Partners for Your Metro HotZone Copyright 2011 Nomadix, Inc. All Rights Reserved. Thursday, January 05, 2012 30851 Agoura Road Suite 102 Agoura Hills, CA 91301 USA www.nomadix.com Sheet

More information

Controller Management

Controller Management Controller Management - Setup & Provisioning - 1 PRONTO SERVICE CONTROLLER (PN-CPP-A-1422) 2 PSC Key Features Fully interoperable with IEEE802.11b/g compliant products External AP support and management

More information

Access Gateway ACCESS GATEWAY

Access Gateway ACCESS GATEWAY Access Gateway Copyright 2012 Nomadix, Inc. All Rights Reserved. This product also includes software developed by: The University of California, Berkeley and its contributors; Carnegie Mellon University,

More information

N4100/ VSG-1200 V2 Hotspot/Service Gateway Series. A Complete Hospitality Solution with Wireless LAN, Internet Access and Billing System.

N4100/ VSG-1200 V2 Hotspot/Service Gateway Series. A Complete Hospitality Solution with Wireless LAN, Internet Access and Billing System. Comprehensive wireless Internet access solution Zero Configuration IP Plug and Play Unique ticket printer for easy service and accounting Web-based user authentication, account monitoring and billing profiles

More information

Firewall VPN Router. Quick Installation Guide M73-APO09-380

Firewall VPN Router. Quick Installation Guide M73-APO09-380 Firewall VPN Router Quick Installation Guide M73-APO09-380 Firewall VPN Router Overview The Firewall VPN Router provides three 10/100Mbit Ethernet network interface ports which are the Internal/LAN, External/WAN,

More information

How To Configure A Kiwi Ip Address On A Gbk (Networking) To Be A Static Ip Address (Network) On A Ip Address From A Ipad (Netware) On An Ipad Or Ipad 2 (

How To Configure A Kiwi Ip Address On A Gbk (Networking) To Be A Static Ip Address (Network) On A Ip Address From A Ipad (Netware) On An Ipad Or Ipad 2 ( UAG715 Support Note Revision 1.00 August, 2012 Written by CSO Scenario 1 - Trunk Interface (Dual WAN) Application Scenario The Internet has become an integral part of our lives; therefore, a smooth Internet

More information

Configuring SSL VPN on the Cisco ISA500 Security Appliance

Configuring SSL VPN on the Cisco ISA500 Security Appliance Application Note Configuring SSL VPN on the Cisco ISA500 Security Appliance This application note describes how to configure SSL VPN on the Cisco ISA500 security appliance. This document includes these

More information

WiNG5 CAPTIVE PORTAL DESIGN GUIDE

WiNG5 CAPTIVE PORTAL DESIGN GUIDE WiNG5 DESIGN GUIDE By Sriram Venkiteswaran WiNG5 CAPTIVE PORTAL DESIGN GUIDE June, 2011 TABLE OF CONTENTS HEADING STYLE Introduction To Captive Portal... 1 Overview... 1 Common Applications... 1 Authenticated

More information

Initial Access and Basic IPv4 Internet Configuration

Initial Access and Basic IPv4 Internet Configuration Initial Access and Basic IPv4 Internet Configuration This quick start guide provides initial and basic Internet (WAN) configuration information for the ProSafe Wireless-N 8-Port Gigabit VPN Firewall FVS318N

More information

Enterprise Wireless LAN. Key Features. Benefits. Hotspot/Service Gateway Series

Enterprise Wireless LAN. Key Features. Benefits. Hotspot/Service Gateway Series Key Features Comprehensive wireless Internet access solution Zero Configuration IP plug and play Unique ticket printer for easy service and accounting Web-based user authentication, account monitoring,

More information

SonicWALL Clean VPN. Protect applications with granular access control based on user identity and device identity/integrity

SonicWALL Clean VPN. Protect applications with granular access control based on user identity and device identity/integrity SSL-VPN Combined With Network Security Introducing A popular feature of the SonicWALL Aventail SSL VPN appliances is called End Point Control (EPC). This allows the administrator to define specific criteria

More information

Multi-Homing Dual WAN Firewall Router

Multi-Homing Dual WAN Firewall Router Multi-Homing Dual WAN Firewall Router Quick Installation Guide M73-APO09-400 Multi-Homing Dual WAN Firewall Router Overview The Multi-Homing Dual WAN Firewall Router provides three 10/100Mbit Ethernet

More information

Chapter 8 Router and Network Management

Chapter 8 Router and Network Management Chapter 8 Router and Network Management This chapter describes how to use the network management features of your ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN. These features can be found by

More information

Chapter 15: Advanced Networks

Chapter 15: Advanced Networks Chapter 15: Advanced Networks IT Essentials: PC Hardware and Software v4.0 1 Determine a Network Topology A site survey is a physical inspection of the building that will help determine a basic logical

More information

RAD-Series RADIUS Server Version 7.1

RAD-Series RADIUS Server Version 7.1 RAD-Series RADIUS Server Version 7.1 Highly Customizable RADIUS Server for Controlling Access & Security in Wireless & Wired Networks Interlink Networks RAD-Series Authentication Authorization, and Accounting

More information

642 523 Securing Networks with PIX and ASA

642 523 Securing Networks with PIX and ASA 642 523 Securing Networks with PIX and ASA Course Number: 642 523 Length: 1 Day(s) Course Overview This course is part of the training for the Cisco Certified Security Professional and the Cisco Firewall

More information

Barracuda Link Balancer

Barracuda Link Balancer Barracuda Networks Technical Documentation Barracuda Link Balancer Administrator s Guide Version 2.2 RECLAIM YOUR NETWORK Copyright Notice Copyright 2004-2011, Barracuda Networks www.barracuda.com v2.2-110503-01-0503

More information

Mikrotik Router OS - Setup and Configuration Guide for Aradial Radius Server

Mikrotik Router OS - Setup and Configuration Guide for Aradial Radius Server Mikrotik Router OS - Setup and Configuration Guide for Aradial Radius Server 2012 Aradial This document contains proprietary and confidential information of Aradial and Spotngo and shall not be reproduced

More information

White Paper 230-1040-001. Copyright 2011 Nomadix, Inc. All Rights Reserved. Thursday, January 05, 2012

White Paper 230-1040-001. Copyright 2011 Nomadix, Inc. All Rights Reserved. Thursday, January 05, 2012 Nomadix Service Engine Enterprise Guest Access Application Copyright 2011 Nomadix, Inc. All Rights Reserved. Thursday, January 05, 2012 30851 Agoura Road Suite 102 Agoura Hills, CA 91301 USA www.nomadix.com

More information

Break Internet Bandwidth Limits Higher Speed. Extreme Reliability. Reduced Cost.

Break Internet Bandwidth Limits Higher Speed. Extreme Reliability. Reduced Cost. Break Internet Bandwidth Limits Higher Speed. Extreme Reliability. Reduced Cost. Peplink. All Rights Reserved. Unauthorized Reproduction Prohibited Presentation Agenda Peplink Balance Pepwave MAX Features

More information

Cisco AnyConnect Secure Mobility Solution Guide

Cisco AnyConnect Secure Mobility Solution Guide Cisco AnyConnect Secure Mobility Solution Guide This document contains the following information: Cisco AnyConnect Secure Mobility Overview, page 1 Understanding How AnyConnect Secure Mobility Works, page

More information

Step-by-Step Configuration

Step-by-Step Configuration Step-by-Step Configuration Kerio Technologies Kerio Technologies. All Rights Reserved. Printing Date: August 15, 2007 This guide provides detailed description on configuration of the local network which

More information

DSL-2600U. User Manual V 1.0

DSL-2600U. User Manual V 1.0 DSL-2600U User Manual V 1.0 CONTENTS 1. OVERVIEW...3 1.1 ABOUT ADSL...3 1.2 ABOUT ADSL2/2+...3 1.3 FEATURES...3 2 SPECIFICATION...4 2.1 INDICATOR AND INTERFACE...4 2.2 HARDWARE CONNECTION...4 2.3 LED STATUS

More information

Innominate mguard Version 6

Innominate mguard Version 6 Innominate mguard Version 6 Configuration Examples mguard smart mguard PCI mguard blade mguard industrial RS EAGLE mguard mguard delta Innominate Security Technologies AG Albert-Einstein-Str. 14 12489

More information

LevelOne. User Manual. FBR-1430 VPN Broadband Router, 1W 4L V1.0

LevelOne. User Manual. FBR-1430 VPN Broadband Router, 1W 4L V1.0 LevelOne FBR-1430 VPN Broadband Router, 1W 4L User Manual V1.0 Table of Contents CHAPTER 1 INTRODUCTION... 1 VPN BROADBAND ROUTER FEATURES... 1 Internet Access Features... 1 Advanced Internet Functions...

More information

Guideline for setting up a functional VPN

Guideline for setting up a functional VPN Guideline for setting up a functional VPN Why do I want a VPN? VPN by definition creates a private, trusted network across an untrusted medium. It allows you to connect offices and people from around the

More information

pfsense Captive Portal: Part One

pfsense Captive Portal: Part One pfsense Captive Portal: Part One Captive portal forces an HTTP client to see a special web page, usually for authentication purposes, before using the Internet normally. A captive portal turns a web browser

More information

Wireless Cable Gateway CG3100Dv3

Wireless Cable Gateway CG3100Dv3 Wireless Cable Gateway CG3100Dv3 User Manual 350 East Plumeria Drive San Jose, CA 95134 USA October 2011 202-10942-01 v1.0 2011 NETGEAR, Inc. All rights reserved No part of this publication may be reproduced,

More information

ActivIdentity 4TRESS AAA Web Tokens and SSL VPN Fortinet Secure Access. Integration Handbook

ActivIdentity 4TRESS AAA Web Tokens and SSL VPN Fortinet Secure Access. Integration Handbook ActivIdentity 4TRESS AAA Web Tokens and SSL VPN Fortinet Secure Access Integration Handbook Document Version 1.1 Released July 16, 2012 ActivIdentity 4TRESS AAA Web Tokens and SSL VPN Fortinet Secure Access

More information

Management Software. Web Browser User s Guide AT-S106. For the AT-GS950/48 Gigabit Ethernet Smart Switch. Version 1.0.0. 613-001339 Rev.

Management Software. Web Browser User s Guide AT-S106. For the AT-GS950/48 Gigabit Ethernet Smart Switch. Version 1.0.0. 613-001339 Rev. Management Software AT-S106 Web Browser User s Guide For the AT-GS950/48 Gigabit Ethernet Smart Switch Version 1.0.0 613-001339 Rev. A Copyright 2010 Allied Telesis, Inc. All rights reserved. No part of

More information

Multi-Homing Security Gateway

Multi-Homing Security Gateway Multi-Homing Security Gateway MH-5000 Quick Installation Guide 1 Before You Begin It s best to use a computer with an Ethernet adapter for configuring the MH-5000. The default IP address for the MH-5000

More information

Clientless SSL VPN Users

Clientless SSL VPN Users Manage Passwords, page 1 Username and Password Requirements, page 3 Communicate Security Tips, page 3 Configure Remote Systems to Use Clientless SSL VPN Features, page 3 Manage Passwords Optionally, you

More information

LifeSize Transit Deployment Guide June 2011

LifeSize Transit Deployment Guide June 2011 LifeSize Transit Deployment Guide June 2011 LifeSize Tranist Server LifeSize Transit Client LifeSize Transit Deployment Guide 2 Firewall and NAT Traversal with LifeSize Transit Firewalls and Network Address

More information

SSL-VPN 200 Getting Started Guide

SSL-VPN 200 Getting Started Guide Secure Remote Access Solutions APPLIANCES SonicWALL SSL-VPN Series SSL-VPN 200 Getting Started Guide SonicWALL SSL-VPN 200 Appliance Getting Started Guide Thank you for your purchase of the SonicWALL SSL-VPN

More information

7.1. Remote Access Connection

7.1. Remote Access Connection 7.1. Remote Access Connection When a client uses a dial up connection, it connects to the remote access server across the telephone system. Windows client and server operating systems use the Point to

More information

How To Connect To Bloomerg.Com With A Network Card From A Powerline To A Powerpoint Terminal On A Microsoft Powerbook (Powerline) On A Blackberry Or Ipnet (Powerbook) On An Ipnet Box On

How To Connect To Bloomerg.Com With A Network Card From A Powerline To A Powerpoint Terminal On A Microsoft Powerbook (Powerline) On A Blackberry Or Ipnet (Powerbook) On An Ipnet Box On Transport and Security Specification 15 July 2015 Version: 5.9 Contents Overview 3 Standard network requirements 3 Source and Destination Ports 3 Configuring the Connection Wizard 4 Private Bloomberg Network

More information

Chapter 9 Monitoring System Performance

Chapter 9 Monitoring System Performance Chapter 9 Monitoring System Performance This chapter describes the full set of system monitoring features of your ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN. You can be alerted to important

More information

Gigabit SSL VPN Security Router

Gigabit SSL VPN Security Router As Internet becomes essential for business, the crucial solution to prevent your Internet connection from failure is to have more than one connection. PLANET is the ideal to help the SMBs increase the

More information

User Manual. Page 2 of 38

User Manual. Page 2 of 38 DSL1215FUN(L) Page 2 of 38 Contents About the Device...4 Minimum System Requirements...5 Package Contents...5 Device Overview...6 Front Panel...6 Side Panel...6 Back Panel...7 Hardware Setup Diagram...8

More information

Cisco RV180 VPN Router

Cisco RV180 VPN Router Data Sheet Cisco RV180 VPN Router Secure, high-performance connectivity at a price you can afford. Figure 1. Cisco RV180 VPN Router (Front Panel) Highlights Affordable, high-performance Gigabit Ethernet

More information

NAC Guest. Lab Exercises

NAC Guest. Lab Exercises NAC Guest Lab Exercises November 25 th, 2008 2 Table of Contents Introduction... 3 Logical Topology... 4 Exercise 1 Verify Initial Connectivity... 6 Exercise 2 Provision Contractor VPN Access... 7 Exercise

More information

TW100-BRV204 VPN Firewall Router

TW100-BRV204 VPN Firewall Router TW100-BRV204 VPN Firewall Router Cable/DSL Internet Access 4-Port Switching Hub User's Guide Table of Contents CHAPTER 1 INTRODUCTION... 1 TW100-BRV204 Features... 1 Package Contents... 3 Physical Details...

More information

Unified Access Point Administrator's Guide

Unified Access Point Administrator's Guide Unified Access Point Administrator's Guide Product Model: DWL-3600AP DWL-6600AP DWL-8600AP Unified Wired & Wireless Access System Release 2.0 November 2011 Copyright 2011. All rights reserved. November

More information

How To Set Up A Cisco Rv110W Wireless N Vpn Network Device With A Wireless Network (Wired) And A Wireless Nvv (Wireless) Network (Wireline) For A Small Business (Small Business) Or Remote Worker

How To Set Up A Cisco Rv110W Wireless N Vpn Network Device With A Wireless Network (Wired) And A Wireless Nvv (Wireless) Network (Wireline) For A Small Business (Small Business) Or Remote Worker Cisco RV110W Wireless-N VPN Firewall Simple, Secure Connectivity for the Small Office/Home Office Figure 1 Cisco RV110W Wireless-N VPN Firewall The Cisco RV110W Wireless-N VPN Firewall provides simple,

More information

Prestige 202H Plus. Quick Start Guide. ISDN Internet Access Router. Version 3.40 12/2004

Prestige 202H Plus. Quick Start Guide. ISDN Internet Access Router. Version 3.40 12/2004 Prestige 202H Plus ISDN Internet Access Router Quick Start Guide Version 3.40 12/2004 Table of Contents 1 Introducing the Prestige...3 2 Hardware Installation...4 2.1 Rear Panel...4 2.2 The Front Panel

More information

BR-6624. Load Balancing Router. Manual

BR-6624. Load Balancing Router. Manual BR-6624 Load Balancing Router Manual TABLE OF CONTENTS 1: INTRODUCTION...1 Internet Features...1 Other Features...3 Package Contents...4 Physical Details...4 2: BASIC SETUP...8 Overview...8 Procedure...8

More information

Broadband Router ALL1294B

Broadband Router ALL1294B Broadband Router ALL1294B Broadband Internet Access 4-Port Switching Hub User's Guide Table of Contents CHAPTER 1 INTRODUCTION... 1 Broadband Router Features... 1 Package Contents... 3 Physical Details...

More information

Load Balancer LB-2. User s Guide

Load Balancer LB-2. User s Guide Load Balancer LB-2 User s Guide TABLE OF CONTENTS 1: INTRODUCTION...1 Internet Features...1 Other Features...3 Package Contents...4 Physical Details...4 2: BASIC SETUP...8 Overview...8 Procedure...8 3:

More information

UIP1868P User Interface Guide

UIP1868P User Interface Guide UIP1868P User Interface Guide (Firmware version 0.13.4 and later) V1.1 Monday, July 8, 2005 Table of Contents Opening the UIP1868P's Configuration Utility... 3 Connecting to Your Broadband Modem... 4 Setting

More information

Professional Integrated SSL-VPN Appliance for Small and Medium-sized businesses

Professional Integrated SSL-VPN Appliance for Small and Medium-sized businesses Professional Integrated Appliance for Small and Medium-sized businesses Benefits Clientless Secure Remote Access Seamless Integration behind the Existing Firewall Infrastructure UTM Security Integration

More information

Cisco RV 120W Wireless-N VPN Firewall

Cisco RV 120W Wireless-N VPN Firewall Cisco RV 120W Wireless-N VPN Firewall Take Basic Connectivity to a New Level The Cisco RV 120W Wireless-N VPN Firewall combines highly secure connectivity to the Internet as well as from other locations

More information

Nokia Siemens Networks. CPEi-lte 7212. User Manual

Nokia Siemens Networks. CPEi-lte 7212. User Manual Nokia Siemens Networks CPEi-lte 7212 User Manual Contents Chapter 1: CPEi-lte 7212 User Guide Overview... 1-1 Powerful Features in a Single Unit... 1-2 Front of the CPEi-lte 7212... 1-2 Back of the CPEi-lte

More information

Steps for Basic Configuration

Steps for Basic Configuration 1. This guide describes how to use the Unified Threat Management appliance (UTM) Basic Setup Wizard to configure the UTM for connection to your network. It also describes how to register the UTM with NETGEAR.

More information

How To Use A Cisco Wvvvdns4400N Wireless-N Gigabit Security Router For Small Businesses

How To Use A Cisco Wvvvdns4400N Wireless-N Gigabit Security Router For Small Businesses Cisco WRVS4400N Wireless-N Gigabit Security Router Cisco Small Business Routers Highlights Secure, high-speed wireless network access for small business Gigabit Ethernet connections enable rapid transfer

More information

VPN Solution Guide Peplink Balance Series. Peplink Balance. VPN Solution Guide. http://www.peplink.com - 1 - Copyright 2015 Peplink

VPN Solution Guide Peplink Balance Series. Peplink Balance. VPN Solution Guide. http://www.peplink.com - 1 - Copyright 2015 Peplink Peplink Balance http://www.peplink.com - 1 - Copyright 2015 Peplink Introduction Introduction Understanding Peplink VPN solutions Peplink's VPN is a complete, seamless system that tightly integrates your

More information

Cisco RV220W Network Security Firewall

Cisco RV220W Network Security Firewall Cisco RV220W Network Security Firewall High-Performance, Highly Secure Connectivity for the Small Office The Cisco RV220W Network Security Firewall lets small offices enjoy secure, reliable, wired and

More information

Router configuration manual for I3 Micro Vood 322

Router configuration manual for I3 Micro Vood 322 Router configuration manual for I3 Micro Vood 322 v1.0 1 (25) Table of contents 1 LED BEHAVIOUR... 4 1.1 POWER... 4 1.2 STATUS... 4 1.3 WAN... 4 1.4 LAN... 4 1.5 PHONE 1 VOIP... 4 1.6 PHONE 1 HOOK... 4

More information

LevelOne WBR-3405TX. User`s Manual. 11g Wireless AP Router

LevelOne WBR-3405TX. User`s Manual. 11g Wireless AP Router LevelOne WBR-3405TX 11g Wireless AP Router User`s Manual Contents 1. Overview...4 1.1 Product Feature...4 1.2 System Requirements...4 1.3 Applications...4 2. Getting Start...5 2.1 Know the 11g Wireless

More information

Protecting the Home Network (Firewall)

Protecting the Home Network (Firewall) Protecting the Home Network (Firewall) Basic Tab Setup Tab DHCP Tab Advanced Tab Options Tab Port Forwarding Tab Port Triggers Tab DMZ Host Tab Firewall Tab Event Log Tab Status Tab Software Tab Connection

More information

Chapter 1 Configuring Basic Connectivity

Chapter 1 Configuring Basic Connectivity Chapter 1 Configuring Basic Connectivity This chapter describes the settings for your Internet connection and your wireless local area network (LAN) connection. When you perform the initial configuration

More information

Mobility Task Force. Deliverable F. Inventory of web-based solution for inter-nren roaming

Mobility Task Force. Deliverable F. Inventory of web-based solution for inter-nren roaming Mobility Task Force Deliverable F Inventory of web-based solution for inter-nren roaming Version 1.1 Authors: Sami Keski-Kasari , Harri Huhtanen Contributions: James

More information

SonicWALL PCI 1.1 Implementation Guide

SonicWALL PCI 1.1 Implementation Guide Compliance SonicWALL PCI 1.1 Implementation Guide A PCI Implementation Guide for SonicWALL SonicOS Standard In conjunction with ControlCase, LLC (PCI Council Approved Auditor) SonicWall SonicOS Standard

More information

Broadband Router User s Manual

Broadband Router User s Manual Broadband Router User s Manual Table of Contents Chapter 1 Introduction...4 1.1 The Broadband Router......4 1.2 Physical Features of Broadband Router...4 1.3 Non-Physical Features of Broadband Router..

More information

Cisco RV110W Wireless-N VPN Firewall

Cisco RV110W Wireless-N VPN Firewall Data Sheet Cisco RV110W Wireless-N VPN Firewall Simple, Secure Connectivity for the Small Office/Home Office Figure 1. Cisco RV110W Wireless-N VPN Firewall The Cisco RV110W Wireless-N VPN Firewall provides

More information

Cisco RV110W Wireless-N VPN Firewall

Cisco RV110W Wireless-N VPN Firewall Data Sheet Cisco RV110W Wireless-N VPN Firewall Simple, Secure Connectivity for the Small Office/Home Office Figure 1. Cisco RV110W Wireless-N VPN Firewall The Cisco RV110W Wireless-N VPN Firewall provides

More information

NETASQ MIGRATING FROM V8 TO V9

NETASQ MIGRATING FROM V8 TO V9 UTM Firewall version 9 NETASQ MIGRATING FROM V8 TO V9 Document version: 1.1 Reference: naentno_migration-v8-to-v9 INTRODUCTION 3 Upgrading on a production site... 3 Compatibility... 3 Requirements... 4

More information

MN-700 Base Station Configuration Guide

MN-700 Base Station Configuration Guide MN-700 Base Station Configuration Guide Contents pen the Base Station Management Tool...3 Log ff the Base Station Management Tool...3 Navigate the Base Station Management Tool...4 Current Base Station

More information

A Guide to New Features in Propalms OneGate 4.0

A Guide to New Features in Propalms OneGate 4.0 A Guide to New Features in Propalms OneGate 4.0 Propalms Ltd. Published April 2013 Overview This document covers the new features, enhancements and changes introduced in Propalms OneGate 4.0 Server (previously

More information

How to Configure a DIR-120 Broadband Router

How to Configure a DIR-120 Broadband Router CONTENTS About This User s Guide...iv Before You Start...iv Installation Notes...v Installation Information...vi INTRODUCTION... 1 Router Description and Operation...1 Front Panel...3 Rear Panel...4 CONNECTING

More information

Chapter 2 Connecting the FVX538 to the Internet

Chapter 2 Connecting the FVX538 to the Internet Chapter 2 Connecting the FVX538 to the Internet Typically, six steps are required to complete the basic connection of your firewall. Setting up VPN tunnels are covered in Chapter 5, Virtual Private Networking.

More information

Wireless Broadband Router. Manual

Wireless Broadband Router. Manual Wireless Broadband Router Manual 1 Introduction... 4 Features... 4 Minimum Requirements... 4 Package Content... 4 Note... 4 Get to know the Broadband Router... 5 Back Panel... 5 Front Panel... 6 Setup

More information

SonicOS 5.9 / 6.0.5 / 6.2 Log Events Reference Guide with Enhanced Logging

SonicOS 5.9 / 6.0.5 / 6.2 Log Events Reference Guide with Enhanced Logging SonicOS 5.9 / 6.0.5 / 6.2 Log Events Reference Guide with Enhanced Logging 1 Notes, Cautions, and Warnings NOTE: A NOTE indicates important information that helps you make better use of your system. CAUTION:

More information

ECB1220R. Wireless SOHO Router/Client Bridge

ECB1220R. Wireless SOHO Router/Client Bridge Wireless SOHO Router/Client Bridge 2.4GH 802.11 b/g 54Mbps PRODUCT DESCRIPTION ECB-1220R is a 2.4GHz 802.11b/g broadband Wi-Fi Router with advanced AP/Client Bridge/Repeater functions. So you could implement

More information

Gigabit Content Security Router

Gigabit Content Security Router Gigabit Content Security Router As becomes essential for business, the crucial solution to prevent your connection from failure is to have more than one connection. PLANET is the Gigabit Content Security

More information

TW100-BRF114 Firewall Router. User's Guide. Cable/DSL Internet Access. 4-Port Switching Hub

TW100-BRF114 Firewall Router. User's Guide. Cable/DSL Internet Access. 4-Port Switching Hub TW100-BRF114 Firewall Router Cable/DSL Internet Access 4-Port Switching Hub User's Guide Table of Contents CHAPTER 1 INTRODUCTION...1 TW100-BRF114 Features...1 Package Contents...3 Physical Details...

More information

About Firewall Protection

About Firewall Protection 1. This guide describes how to configure basic firewall rules in the UTM to protect your network. The firewall then can provide secure, encrypted communications between your local network and a remote

More information

Using SonicWALL NetExtender to Access FTP Servers

Using SonicWALL NetExtender to Access FTP Servers SSL-VPN Using SonicWALL NetExtender to Access FTP Servers Problem: Using NetExtender to access an FTP Server on the LAN segment of a SonicWALL PRO 4060. Solution: Perform the following setup steps. Step

More information

Copyright 2006 Comcast Communications, Inc. All Rights Reserved.

Copyright 2006 Comcast Communications, Inc. All Rights Reserved. ii Copyright 2006 Comcast Communications, Inc. All Rights Reserved. Comcast is a registered trademark of Comcast Corporation. Comcast Business IP Gateway is a trademark of Comcast Corporation. The Comcast

More information

Using IEEE 802.1x to Enhance Network Security

Using IEEE 802.1x to Enhance Network Security Using IEEE 802.1x to Enhance Network Security Table of Contents Introduction...2 Terms and Technology...2 Understanding 802.1x...3 Introduction...3 802.1x Authentication Process...3 Before Authentication...3

More information

Chapter 4 Managing Your Network

Chapter 4 Managing Your Network Chapter 4 Managing Your Network This chapter describes how to perform network management tasks with your ADSL2+ Modem Wireless Router. Backing Up, Restoring, or Erasing Your Settings The configuration

More information

Public Internet Access Done the Right Way

Public Internet Access Done the Right Way Public Internet Access Done the Right Way Supports 500 concurrent logins by default and up to 800 via license upgrade Integrated account generator, Web-based authentication portal and billing system Supports

More information

Endpoint Security VPN for Mac

Endpoint Security VPN for Mac Security VPN for Mac E75 Release Notes 8 April 2012 Classification: [Protected] 2012 Check Point Software Technologies Ltd. All rights reserved. This product and related documentation are protected by

More information

Cisco RV215W Wireless-N VPN Router

Cisco RV215W Wireless-N VPN Router Data Sheet Cisco RV215W Wireless-N VPN Router Simple, Secure Connectivity for the Small Office and Home Office Figure 1. Cisco RV215W Wireless-N VPN Router The Cisco RV215W Wireless-N VPN Router provides

More information

Load Balancing Router. User s Guide

Load Balancing Router. User s Guide Load Balancing Router User s Guide TABLE OF CONTENTS 1: INTRODUCTION... 1 Internet Features... 1 Other Features... 3 Package Contents... 4 Physical Details... 4 2: BASIC SETUP... 8 Overview... 8 Procedure...

More information

Enabling WISPr (Hotspot Services) in the ZoneDirector

Enabling WISPr (Hotspot Services) in the ZoneDirector A P P L I C A T I O N N O T E Enabling WISPr ( Services) in the Introduction This document describes the WISPr support (hotspot service) for. Unauthenticated users: The users who have not passed authentication

More information

A Division of Cisco Systems, Inc. Broadband Router. with 2 Phone Ports. Voice Installation and Troubleshooting Guide RTP300. Model No.

A Division of Cisco Systems, Inc. Broadband Router. with 2 Phone Ports. Voice Installation and Troubleshooting Guide RTP300. Model No. A Division of Cisco Systems, Inc. Broadband Router with 2 Phone Ports Voice Installation and Troubleshooting Guide Model No. RTP300 Copyright and Trademarks Specifications are subject to change without

More information

Design and Implementation Guide. Apple iphone Compatibility

Design and Implementation Guide. Apple iphone Compatibility Design and Implementation Guide Apple iphone Compatibility Introduction Security in wireless LANs has long been a concern for network administrators. While securing laptop devices is well understood, new

More information

ADSL MODEM. User Manual V1.0

ADSL MODEM. User Manual V1.0 ADSL MODEM User Manual V1.0 CONTENTS 1.OVERVIEW... 3 1.1 ABOUT ADSL... 3 1.2 ABOUT ADSL2/2+... 3 1.3 FEATURES... 3 2 SPECIFICATION... 4 2.1 INTERFACE INTRODUCTION... 4 2.1.1 INDICATOR AND INTERFACE...

More information

OSBRiDGE 5XLi. Configuration Manual. Firmware 3.10R

OSBRiDGE 5XLi. Configuration Manual. Firmware 3.10R OSBRiDGE 5XLi Configuration Manual Firmware 3.10R 1. Initial setup and configuration. OSBRiDGE 5XLi devices are configurable via WWW interface. Each device uses following default settings: IP Address:

More information

Features Description Benefit AP-7131N support Adaptive AP Support for the AP7131N-GR and AP7131N- GRN

Features Description Benefit AP-7131N support Adaptive AP Support for the AP7131N-GR and AP7131N- GRN Release Notes for RFS7000 v4.1.0.0-040gr Contents 1. Introduction to New Features 2. Features Added for FIPS Compliance 3. Features Disabled or Modified for FIPS Compliance 4. Firmware Versions & Compatibility

More information

DEPLOYMENT GUIDE Version 1.1. Deploying the BIG-IP LTM v10 with Citrix Presentation Server 4.5

DEPLOYMENT GUIDE Version 1.1. Deploying the BIG-IP LTM v10 with Citrix Presentation Server 4.5 DEPLOYMENT GUIDE Version 1.1 Deploying the BIG-IP LTM v10 with Citrix Presentation Server 4.5 Table of Contents Table of Contents Deploying the BIG-IP system v10 with Citrix Presentation Server Prerequisites

More information

108Mbps Super-G TM Wireless LAN Router with XR USER MANUAL

108Mbps Super-G TM Wireless LAN Router with XR USER MANUAL 108Mbps Super-G TM Wireless LAN Router with XR USER MANUAL Contents 1. Overview...1 1.1 Product Feature...1 1.2 System Requirements...1 1.3 Applications...1 2. Getting Start...2 2.1 Know the 108Mbps Wireless

More information

Chapter 12 Supporting Network Address Translation (NAT)

Chapter 12 Supporting Network Address Translation (NAT) [Previous] [Next] Chapter 12 Supporting Network Address Translation (NAT) About This Chapter Network address translation (NAT) is a protocol that allows a network with private addresses to access information

More information

V310 Support Note Version 1.0 November, 2011

V310 Support Note Version 1.0 November, 2011 1 V310 Support Note Version 1.0 November, 2011 2 Index How to Register V310 to Your SIP server... 3 Register Your V310 through Auto-Provision... 4 Phone Book and Firmware Upgrade... 5 Auto Upgrade... 6

More information

ACADEMIA LOCAL CISCO UCV-MARACAY CONTENIDO DE CURSO CURRICULUM CCNA. SEGURIDAD SEGURIDAD EN REDES. NIVEL I. VERSION 2.0

ACADEMIA LOCAL CISCO UCV-MARACAY CONTENIDO DE CURSO CURRICULUM CCNA. SEGURIDAD SEGURIDAD EN REDES. NIVEL I. VERSION 2.0 ACADEMIA LOCAL CISCO UCV-MARACAY CONTENIDO DE CURSO CURRICULUM CCNA. SEGURIDAD SEGURIDAD EN REDES. NIVEL I. VERSION 2.0 Module 1: Vulnerabilities, Threats, and Attacks 1.1 Introduction to Network Security

More information

Chapter 4 Customizing Your Network Settings

Chapter 4 Customizing Your Network Settings . Chapter 4 Customizing Your Network Settings This chapter describes how to configure advanced networking features of the Wireless-G Router Model WGR614v9, including LAN, WAN, and routing settings. It

More information