4IPNET HSG260 User manual

V1.20
HSG Series
Wireless Hotspot Gateway

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
i
Copyright & Disclaimer
Copyright
The contents of this publication may not be reproduced in any part or as a whole, stored, transcribed
in an information retrieval system, translated into any language, or transmitted in any form or by any
means, mechanical, magnetic, electronic, optical, photocopying, manual, or otherwise, without the
prior written permission of 4IPNET, INC.
Disclaimer
4IPNET, INC. does not assume any liability arising out the application or use of any products, or
software described herein. Neither does it convey any license under its parent rights not the parent
rights of others. 4IPNET further reserves the right to make changes in any products described herein
without notice. The publication is subject to change without notice.
Trademarks
4IPNET (4ipnet) is a registered trademark of 4IPNET, INC. Other trademarks mentioned in this
publication are used for identification purposes only and may be properties of their respective
owners.

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
ii
Table of Contents
1Before You Start ............................................................................................................1
1.1 Preface .....................................................................................................................................................1
1.2 Document Conventions .........................................................................................................................1
1.3 Package Checklist...................................................................................................................................2
2System Overview and Getting Started ................................................................3
2.1 Introduction of the Hotspot Gateway HSG Series.............................................................................3
2.2 System Concept ......................................................................................................................................3
2.3 The HSG Series Hardware Overview...................................................................................................4
2.4 System Requirement..............................................................................................................................8
2.5 Installation Steps....................................................................................................................................8
2.6 Access Web Management Interface.....................................................................................................9
3Incorporate HSG gateway to the Network......................................................11
3.1 Network Requirement .........................................................................................................................11
3.2 Configure WAN Port............................................................................................................................11
3.2.1 Static IP ........................................................................................................................................................12
3.2.2 Dynamic.......................................................................................................................................................12
3.2.3 PPPoE ..........................................................................................................................................................13
3.2.3 PPTP.............................................................................................................................................................14
3.3 Internet Connection Detection...........................................................................................................15
3.4 WAN Bandwidth Control ....................................................................................................................16
3.5 What is a Service Zone.........................................................................................................................17
3.5.1 Port Role Assignment.................................................................................................................................18
3.5.2 Planning Your Internet Network..............................................................................................................20
3.5.3 Configure Zone Network ...........................................................................................................................21
4Let Your Network Be a Wireless Network ...................................................23
4.1 System Wireless General Settings......................................................................................................23
4.2 Zone Wireless Settings ........................................................................................................................25
4.3 Zone Wireless Security ........................................................................................................................28
4.4 Wireless Layer 2 firewall .....................................................................................................................30
4.4.1 Generic Firewall Rules ...............................................................................................................................31
4.4.2 Predefined and Custom Service Protocols ..............................................................................................35
4.4.3 Advanced .....................................................................................................................................................36
5Who Can Access the Network ............................................................................37
5.1 Type of Users ........................................................................................................................................37
5.1.1 Local...........................................................................................................................................................38
5.1.2 RADIUS .....................................................................................................................................................41
5.1.3 On-Demand User .....................................................................................................................................45
5.1.4 Free Authentication .................................................................................................................................56

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
iii
5.2 User Login .............................................................................................................................................57
5.2.1 Default Authentication ............................................................................................................................57
5.2.2 Login with Postfix ....................................................................................................................................57
5.2.3 An Example of User Login ......................................................................................................................57
6 Restrain the Users......................................................................................................................60
6.1 Black List ...............................................................................................................................................60
6.2 Group .....................................................................................................................................................62
6.3 Policy......................................................................................................................................................62
6.3.1 Schedule ....................................................................................................................................................64
6.3.2 Firewall ......................................................................................................................................................65
6.3.3 QoS Profile ................................................................................................................................................68
6.3.4 Routing ......................................................................................................................................................69
6.3.5 User Privilege............................................................................................................................................72
7 Access Network without Authentication..........................................................................73
7.1 DMZ......................................................................................................................................................73
7.2 Virtual Server........................................................................................................................................75
7.3 Privilege List .........................................................................................................................................76
7.3.1 Privilege IP...................................................................................................................................................77
7.3.2 Privilege MAC .............................................................................................................................................78
7.3.3 Privilege IPv6 ..............................................................................................................................................78
7.4 Disable Authentication in Public Zone..............................................................................................79
8 User Login and Logout.............................................................................................................80
8.1 Before Login..........................................................................................................................................80
8.1.1 Login with SSL.............................................................................................................................................80
8.1.2 Internal Domain Name with Certificate..................................................................................................81
8.1.3 Walled Garden ............................................................................................................................................83
8.1.4 Walled Garden AD......................................................................................................................................84
8.2 After Login ............................................................................................................................................85
8.2.1 Start Page URL after Successful Login ....................................................................................................85
8.2.2 Idle Timer....................................................................................................................................................86
8.2.3 Multiple Login ............................................................................................................................................87
9 Networking Features of a Gateway ...................................................................................88
9.1 Dynamic Domain Name Service (DDNS)............................................................................................88
9.2 Port and IP Forwarding.........................................................................................................................89
10 System Management and Utilities......................................................................................90
10.1 System Time ..........................................................................................................................................90
10.2 Management IP Address List .............................................................................................................91
10.3 IP Address for Accessing User Log ....................................................................................................92
10.4 SNMP .....................................................................................................................................................93
10.5 Administration......................................................................................................................................94

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
iv
10.6 Change Admin Passwords...................................................................................................................97
10.7 Backup / Restore and Reset to the Factory Default.........................................................................98
10.8 Firmware Upgrade .............................................................................................................................99
10.9 Restart..................................................................................................................................................100
10.10 Network Utility....................................................................................................................................101
10.10.1 Wake-on-LAN........................................................................................................................................102
10.10.2 Ping.........................................................................................................................................................102
10.10.3 Trace Route ...........................................................................................................................................102
10.10.4 Show ARP Table ...................................................................................................................................102
10.11 Monitor IP Link.................................................................................................................................103
10.12 Console Interface..............................................................................................................................104
11 System Status and Reports.................................................................................................107
11.1 Viewing the Status ...............................................................................................................................107
11.1.1 System Status............................................................................................................................................107
11.1.2 Interface Status........................................................................................................................................109
11.1.3 Routing Table...........................................................................................................................................112
11.1.4 Current Users...........................................................................................................................................113
11.1.5 Session List...............................................................................................................................................114
11.1.6 User Log....................................................................................................................................................114
11.1.7 Local User Monthly Network Usage Report.........................................................................................117
11.1.8 System Related Logs ...............................................................................................................................118
11.1.9 DHCP Lease..............................................................................................................................................118
11.2 Notification ..........................................................................................................................................120
11.2.1 E-Mail........................................................................................................................................................121
11.2.2 SYSLOG ....................................................................................................................................................122
11.2.3 FTP............................................................................................................................................................123
12 Advanced Applications.........................................................................................................125
12.1 Upload/Download Local User Accounts..........................................................................................125
12.2 RADIUS Advanced Settings..............................................................................................................127
12.3 Roaming Out .......................................................................................................................................128
12.4 Customizable Pages............................................................................................................................129
Appendix A. Policy Priority ....................................................................................................131
Appendix B. WDS Management ............................................................................................132
Appendix C. RADIUS Accounting .........................................................................................134
Appendix D. On-demand Account types & Billing Plan ..............................................143
Appendix E. External Payment Gateways........................................................................152
Appendix F. Portal Page Customization ...........................................................................163
Appendix G. Terminal Server Setup ....................................................................................177

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
1
1Before You Start
1.1 Preface
This manual is for WLAN service providers or network administrators to set up a network environment using the
HSG Hotspot Gateway Series. It contains step-by-step procedures and graphic examples to guide MIS staff or
individuals with slight network system knowledge to complete the installation.
Corresponding Software Versions for each Model
HSG260
Up to software version 2.40
HSG320
Up to software version 1.20
HSG327
Up to software version 1.20
1.2 Document Conventions
Caution:
Represents essential steps, actions, or messages that should not be ignored.
Note:
Contains related information that corresponds to a topic.
Indicates that clicking this button will apply all of your settings.
Indicates that clicking this button will clear what you have set before the settings are applied.
Indicates that clicking this button will save the changes you made, but you must reboot the
system upon the completion of all configuration settings for the changes to take effect.
The red asterisk indicates that information in this field is compulsory.

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
2
1.3 Package Checklist
The standard package of Hotspot Gateway Series HSG includes:
HSG260 / HSG320 / HSG327 x 1
CD-ROM (with User’s Manual and QIG) x 1
Quick Installation Guide (QIG) x 1
Ethernet Cable x 1
Console Cable x 1 (Not included for HSG327)
Power Adapter (DC 5V) x 1 (HSG260)
Power Adapter (DC 12V) x1 (HSG320)
Detachable antenna (x 2 for HSG260 and x 4 for HSG320)
Caution:
It is highly recommended to use all the supplies in the package instead of substituting any components with other
suppliers to guarantee best performance.

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
3
2System Overview and Getting Started
2.1 Introduction of the Hotspot Gateway HSG Series
The HSG gateway series is the most economical and feature-rich Wireless Hotspot Gateway, targeting mini-size
stores that want to provide small, single-point wireless Internet access service. The HSG gateway is a perfect
choice for beginners to run hotspot businesses. It does not cost much compared to buying a pile of equipment, nor
does it take the skills of an expert to glue multiple applications out of multiple freeware. Feature-packed for hotspot
operation, the HSG gateway comes with built-in 802.11 n/b/g (a/b/g/n for dual RF models) MIMO access point,
web server and web pages for clients to login, easy logo-loading for branding a hotspot store, simple
user/visitor account management tool, payment plans, multiple credit card gateways, traffic logs, IP
sharing and etc. The HSG gateway also brings in an extra advantage - the wall-mountable IP50 dust-proof
(HSG260 / HSG320) or ceiling mountable (HSG327) housing.
2.2 System Concept
The HSG gateway is capable of managing user authentication, authorization and accounting. The user account
information is stored in the local database or a specified external RADIUS database server. Featured with user
authentication and integrated with external payment gateway, the HSG gateway allows users to easily pay the fee
and enjoy the Internet service using credit cards through a variety of payment gateways includingAuthorize.Net,
PayPal, SecurePay, and WorldPay. Furthermore, the HSG gateway introduces the concept of Service Zones –
Private Zone and Public Zone, each with its own definable access control profiles. Private Zone means clients are
not required to be authenticated before using the network service. However, clients in Public Zone are required to
get authentication before using the network service. This is very useful for hotspot owners seeking to deploy
wireless network service for clients and manage the network as well. The following diagram is an example of a
HSG gateway set to manage the Internet and network access services at a hotspot venue.
【Example: A typical Hotspot network】

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
4
2.3 The HSG Series Hardware Overview
HSG260
Rear Panel
1
Antenna connector
Reverse SMA connectors for attaching antenna as shown in above figure.
2
WAN
For attaching an Ethernet cable to an uplink service.
3
LAN 1- 4 ports
Attach Ethernet cables here for connecting to the wired local network.
4
USB 2.0 port
Reserved for future use.
5
Console port
Attach the serial cable here to access console interface.
6
5V 2 A
Attach the power adapter here.
7
Reset button
Press once to restart the system; Press and hold for more than 5 seconds to
reset to factory default.

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
5
Front Panel
1
Quick button
Press this button to quick-print an account generated from billing plan 1.
2
WES button
Press and hold over 5 seconds to initiate Master Mode for the WES process.
Press and release to initiate Slave Mode for the WES process.
3
Power LED
On indicates power on.
4
Status LED
On indicates the system ready.
5
Wireless LED
On indicates wireless network interface is ready for service.
6
WAN LED
On indicates that WAN uplink connected.
7
LAN1 - 4 LED
Indicates the connection status of each LAN.
8
USB LED
Indicates the status of USB connection. USB port reserved for future use.
9
WES LED
For indicating WDS connection status.
Master
Slave
WES Start
LED (Green) OFF and
then BLINKING SLOWLY
LED (Red) OFF and then
BLINKING SLOWLY
WES Negotiate
BLINKING NORMALLY
(Green)
BLINKING NORMALLY
(Red)
WES Timeout
LED (Green) ON
LED (Red) ON
WES Success
LED (Red) ON
LED (Green) ON
WES Fail
LED (Green) ON
LED (Red) ON

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
6
HSG320
1 2 3 4 5 6 7
4
Rear Panel
1
12V 2A
Power Jack Socket for the power adaptor.
2
Restart / Reset
Press once to restart the system; Press and hold for more than 5 seconds to
reset to factory default.
3
WES Button (A / B)
WDS Easy Setup. Press the button to build up a WDS link with another peer. 2
WDS links can be set up per RF card.
4
LED Indicators
6 indicators that displays the states of 6 various functions or progresses. The
numbers are explained on the leftmost side of the rear panel.
5
WAN
For attaching an Ethernet cable to an uplink service. PoE (Power over Ethernet)
is supported for the WAN port.
6
LAN Ports 1 - 2
The ports for connections with LAN side devices.
7
Console Port
To access HSG320 via the console interface.

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
7
HSG327
1 2 3 4 56
Rear Panel
1
12V 2A
Power Jack Socket for the power adaptor.
2
Restart / Reset
Press once to restart the system; Press and hold for more than 5 seconds to
reset to factory default.
3
WES Button
WDS Easy Setup. Press the button to build up a WDS link with another peer.
4
LED Indicators
4 LED lights are available. What the numbers stand for is listed at the bottom of
the panel.
5
WAN
For attaching an Ethernet cable to an uplink service. PoE (Power over Ethernet)
is support for the WAN port.
6
LAN Ports 1 –2
Attach Ethernet cables here to connect to the wired local network.

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
8
2.4 System Requirement
Gigabit Ethernet network cables with RJ-45 connectors.
All PCs need to install the TCP/IP network protocol.
2.5 Installation Steps
Please follow the steps mentioned below to install the hardware of the HSG gateway:
1. Place the HSG gateway at the best location.
The best location is usually at the center of your wireless network.
2. To supply power to the HSG gateway.
Connect the power adapter to the HSG gateway’s power jack socket on the rear panel.
3. Connect HSG gateway to your outbound network device.
Connect one end of the Ethernet cable to the WAN port of HSG the gateway on the rear panel. Depending on
the type of internet service provided by your ISP, connect the other end of the cable to the ATU-Router of an
ADSL, a cable modem, a switch or a hub. The WAN LED indicator should be ON to indicate a proper
connection.
4. Connect the HSG gateway to your PC.
Connect one end of the Ethernet cable to the LAN1 port of the HSG gateway on the rear panel. Connect the
other end of the cable to a PC for configuring the system. The LAN1 LED indicator should be ON to indicate a
proper connection.
Note:
The HSG gateway has two virtual Private and Public zones that are mapped to LAN1, LAN2
(192.168.1.254) and LAN3, LAN4 (192.168.11.254) respectively on the HSG260.
The HSG gateway has two virtual Private and Public zones that are mapped to LAN1 (192.168.1.254)
and LAN2 (192.168.11.254) respectively on the HSG320/HSG327.
Now, the hardware installation is complete.
Caution:
Please use only the power adapter supplied with the HSG package. Using a different power adapter may cause
damage to this system.
Caution:
To verify the wired connection between the HSG gateway and your switch/router/hub. Please check the LED status
indication of these network devices.

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
9
2.6 Access Web Management Interface
The HSG gateway supports Web Management Interface (WMI) configuration. Upon the completion of hardware
installation, the HSG gateway can be configured via web browsers with JavaScript enabled such as Internet
Explorer version 6.0 and above or Firefox.
Default LAN interface IP address:
Private Zone with IP 192.168.1.254, no authentication is required for users.
Public Zone with IP 192.168.11.254, by default authentication is required for users.
Note: The instructions below are illustrated with the administrator PC connected to LAN1.
To access the web management interface, connect a PC to LAN1 Port, and then launch a browser. Make sure
you have set DHCP in TCP/IP of your PC to ”Obtain an IP address automatically”. The default gateway IP
address is the default gateway IP address of Private Zone: “192.168.1.254”.
Next, enter the gateway IP address of the HSG gateway at the address field. The default gateway IP address of
LAN1 Port is“https://192.168.1.254” (“https” is used for a secured connection).
The administrator login page will appear. Enter “admin”, the default username, and “admin”, the default
password, in the User Name and Password fields. Click LOGIN to log in.

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
10
After a successful login, a “Home” page with four main buttons will appear on the screen.
Caution:
If you can’t get to the login screen, the reasons may be: (1) The PC is set incorrectly so that the PC can’t obtain
the IP address automatically from the LAN port; (2) The IP address and the default gateway are not under the
same network segment. Please set your PC with a static IP address such as 192.168.1.xx in your network and
then try it again.

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
11
3Incorporate HSG gateway to the Network
3.1 Network Requirement
In the general network environment, the main role of the HSG gateway is to manage all the network access from
internal network to Internet. Thus, the first step is to prepare an Internet connection from your ISP (Internet Service
Provider) and connect it to the WAN port of the HSG gateway.
3.2 Configure WAN Port
There are 3 connection types for the WAN Port: Static, Dynamic and PPPoE. These connection types are enough
to support most ISPs.
Now, let us discuss how to configure the WAN port. Go to: System >> WAN.
The parameters related to each connection method are described in the following page.

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
12
3.2.1 Static IP
Static: Manually specifying the IP address of the WAN Port. The fields with red asterisks are mandatory.
IP Address: The IP address of the WAN port.
Subnet Mask: The subnet mask of the WAN port.
Default Gateway: The gateway of the WAN port.
Preferred DNS Server: The primary DNS Server of the system.
Alternate DNS Server: The substitute DNS Server of the system. This is an optional field.
3.2.2 Dynamic
Dynamic: It is only applicable for the network environment where the DHCP server is available upstream of the
system. Click the Renew button to get an IP address automatically.

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
13
3.2.3 PPPoE
PPPoE: When selecting PPPoE to connect to the network, please set the “Username”, “Password”, “MTU” and
“Clamp MSS”. There is a Dial on demand function under PPPoE. If this function is enabled, a Maximum Idle
Time slot will be available for inputting a value. When the idle time is reached, the system will automatically
disconnect itself.

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
14
3.2.3 PPTP
PPTP: Although not a popular method, PPTP protocol for dialup connections is adapted by some ISPs (in
European Countries). Your PPTP ISP will issue you an account with a password as well as the PPTP server
address.

User’s Manual
HSG Wireless Hotspot Gateway ENGLISH
15
3.3 Internet Connection Detection
To configure Internet Connection Detection, go to: System >> WAN Traffic.
Internet Connection Detection: When this function is enabled, system will try to access these IP/Domain
addresses, if system can reach these IP/Domain addresses, it means that the outbound Internet connection is
in normal state. On the other hand, there is a textbox available for the administrator to enter a message
reminder. This reminder will appear on clients’ screens when Internet connection is down.
This manual suits for next models
2
Table of contents
Other 4IPNET Wireless Router manuals