O3-User Guide
O3-User Guide
User Guide
Outdoor CPE
Copyright statement
© 2021-2024 Shenzhen Tenda Technology Co., Ltd. All rights reserved.
is a registered trademark legally held by Shenzhen Tenda Technology Co., Ltd. Other brand
and product names mentioned herein are trademarks or registered trademarks of their respective
holders. Copyright of the whole product as integration, including its accessories and software,
belongs to Shenzhen Tenda Technology Co., Ltd. No part of this publication can be reproduced,
transmitted, transcribed, stored in a retrieval system, or translated into any language in any form or
by any means without the prior written permission of Shenzhen Tenda Technology Co., Ltd.
Disclaimer
Pictures, images and product specifications herein are for references only. To improve internal
design, operational function, and/or reliability, Tenda reserves the right to make changes to the
products without obligation to notify any person or organization of such revisions or changes. Tenda
does not assume any liability that may occur due to the use or application of the product described
herein. Every effort has been made in the preparation of this document to ensure accuracy of the
contents, but all statements, information and recommendations in this document do not constitute
a warranty of any kind, express or implied.
i
Preface
Thank you for choosing Tenda! Please read this user guide before you start managing the CPE.
This user guide applies to Tenda CPEs. O4V1.0 working in AP mode is used for illustration here
unless otherwise specified.
This user guide is for configuration reference only and does not indicate that the product supports
all functions described here. Functions available may vary with the product model. Please refer to
the actual product.
The UI screenshots, IP addresses and other data are for illustrative purposes only and do not affect
your configuration. Functions or parameters grayed out on the UI indicate that they are unavailable
or cannot be modified on the product.
Conventions
The typographical elements that may be found in this document are defined as follows.
The symbols that may be found in this document are defined as follows.
Symbol Meaning
This format is used to highlight a procedure that will save time or resources.
ii
For more documents
If you want to get more documents about the device, visit www.tendacn.com and search for the
corresponding product model.
Technical support
Contact us if you need more help. We will be glad to assist you as soon as possible.
Website: www.tendacn.com
Revision history
Tenda is constantly searching for ways to improve its products and documentation. The following
table indicates any changes that might have been made since this guide was first published.
iii
Contents
1 Typical application scenario .................... 1 4.3.1 Overview.................................... 30
iv
6 Network ............................................... 72 7.3.2 Example of configuring access
control .............................................. 124
6.1 LAN setup ........................................... 72
7.4 Management RF ............................... 126
6.1.1 Overview ................................... 72
7.4.1 Overview.................................. 126
6.1.2 Modify LAN IP address .............. 75
7.4.2 Delay duration of management
6.2 Packet filter ........................................ 77
RF's wireless network ....................... 127
6.3 MAC clone .......................................... 79
8 Advanced............................................ 129
6.3.1 Overview ................................... 79
8.1 LAN rate............................................ 129
6.3.2 Clone a MAC address ................ 79
8.2 Diagnose........................................... 131
6.4 DHCP server ....................................... 81
8.2.1 Site survey ............................... 131
6.4.1 Overview ................................... 81
8.2.2 Ping .......................................... 132
6.4.2 Configure the DHCP server ....... 81
8.2.3 Traceroute................................ 133
6.5 DHCP client ........................................ 83
8.2.4 Speed test ................................ 134
6.6 VLAN settings ..................................... 84
8.2.5 Spectrum analysis .................... 137
6.6.1 Overview ................................... 84
8.3 Bandwidth control............................ 141
6.6.2 Configure VLAN (Example:
8.3.1 Overview.................................. 141
OS3V1.0)............................................. 84
8.3.2 Example of configuring bandwidth
6.6.3 Example of configuring VLAN on
control .............................................. 142
O4V1.0 ................................................ 85
8.4 Port forwarding ................................ 144
7 Wireless settings .................................. 88
8.4.1 Overview.................................. 144
7.1 Basic configuration............................. 88
8.4.2 Example of configuring port
7.1.1 Overview ................................... 88
forwarding ........................................ 145
7.1.2 Basic wireless settings ............... 90
8.5 MAC filter ......................................... 148
7.1.3 Set up a non-encrypted wireless
8.5.1 Overview.................................. 148
network .............................................. 98
8.5.2 Example of configuring MAC filter
7.1.4 Set up a wireless network
.......................................................... 149
encrypted using WPA2-PSK .............. 100
8.6 Network service ............................... 151
7.1.5 Set up a wireless network
encrypted using WPA or WPA2 ........ 102 8.6.1 DDNS........................................ 151
7.2 Advanced settings ............................ 119 8.6.2 Remote web management ...... 155
7.3 Access control .................................. 123 8.6.3 Reboot schedule ...................... 157
7.3.1 Overview ................................. 123 8.6.4 Login timeout interval ............. 157
v
8.6.5 SNMP agent ............................. 158
vi
Document Version: V2.2
1 Typical application
scenario
− At least two CPEs are required for bridging. Different application scenarios require different CPE
models. For more information, visit www.tendacn.com.
− A CPE can be used with multiple cameras. The specific number of cameras can be calculated by
the formula (Number of Cameras = CPE Sending/Receiving Rate * 70% ÷ Camera Stream).
1.1.1 Solution
− Method 1: Use the CPE kit to set up a monitoring network, such as the CPE kit O1-
5GV1.0. You only need to install the CPEs to easily manage the CCTV surveillance for
the community.
− Method 2: Use two CPEs to set up a monitoring network, such as the CPE O4V1.0. You
only need to Set up the CPEs > Install the CPEs to easily manage the CCTV surveillance
for the community.
To facilitate you to quickly set up a monitoring network, it is recommended to set up the CPEs first and
then install the CPEs.
1
Document Version: V2.2
− Automatic bridging is only applicable when the CPEs are in factory settings.
− When performing peer-to-peer bridging, ensure that only two CPEs are powered on and near
each other. Otherwise, the bridging may fail.
− After the bridging succeeds, the DHCP service of the CPE is automatically disabled. The IP address
of the CPE working in AP mode remains unchanged (192.168.2.1), and the IP address of the CPE
working in Client mode is changed to 192.168.2.2.
CPE1 CPE2
2
Document Version: V2.2
− If the CPE supports DC power supply, you can use the correct power adapter to power on the
CPE. The power parameters can be checked on the label of the CPE. If the power adapter (5.5×2.1
mm) is not included in the product package, you can purchase it by yourself.
− Some CPEs can use PoE power supply device with IEEE 802.3af standard. For details, visit
www.tendacn.com to search for the specific product model, and check the relevant information
on the details page.
− The maximum PoE power supply distance supported by each CPE varies. For details, visit
www.tendacn.com to search for the specific product model, enter the Download page, and
download the datasheet to check the maximum PoE power supply distance of the product.
----End
After the two CPEs are powered on, they start bridging each other with their LED1, LED2 and LED3
indicators blinking fast. When the LED1, LED2 and LED3 indicators of one CPE are lit solid and the
same indicators of the other CPE blink slowly, the peer-to-peer bridging succeeds.
CPE1 CPE2
AP mode Client mode
3
Document Version: V2.2
If the peer-to-peer bridging fails, reset the two CPEs to factory settings, and try again.
CPE1 CPE2
− If the CPE supports DC power supply, you can use the correct power adapter to power on the
CPE. The power parameters can be checked on the label of the CPE. If the power adapter (5.5×2.1
mm) is not included in the product package, you can purchase it by yourself.
− Some CPEs can use PoE power supply device with IEEE 802.3af standard. For details, visit
www.tendacn.com to search for the specific product model, and check the relevant information
on the details page.
− The maximum PoE power supply distance supported by each CPE varies. For details, visit
www.tendacn.com to search for the specific product model, enter the Download page, and
download the datasheet to check the maximum PoE power supply distance of the product.
4
Document Version: V2.2
Power socket
PoE injector
PoE
CPE1
2. Connect the computer to the LAN port of the PoE power supply using an Ethernet cable.
Power socket
PoE injector
PoE LAN
CPE1
Computer
3. Start a web browser on your computer, visit the IP address of the CPE (192.168.2.1 by
default) in the address bar, and press the Enter (or Return) key on your keyboard.
5
Document Version: V2.2
If the above page does not appear, try the following methods:
− Ensure that the CPE is powered on properly.
− Ensure that the computer is connected to the LAN port of the CPE properly.
− Ensure that the IP address of the computer belongs to the same subnet the CPE. For example, if
the IP address of the CPE is 192.168.2.1, you can set the IP address of the computer to
192.168.2.X (X ranges from 3 to 254 and is not occupied).
− If more than one CPE is connected, modify the IP address of each one to avoid the login failure
due to IP address conflict.
− Reset the CPE to factory settings. Reset method: After CPE completes startup, hold down the reset
button (such as RST, RESET or Reset) for about 8 seconds, and then release it when all indicators
light up.
6
Document Version: V2.2
3. Click Save, and wait until the CPE reboots to make the settings take effect.
Step 4 Log in to the web UI of CPE2 and set to the Client mode.
1. Refer to Step 2 to log in to the web UI of CPE2.
2. Navigate to Quick Setup. Select Client mode, and click Next.
3. Select the wireless network to bridge from the list, which is Tenda_123456 in this example,
and click Next.
7
Document Version: V2.2
If you cannot find any wireless network from the list, navigate to Wireless > Basic and enable the
wireless function. Then try again.
4. Enter the Wi-Fi password of the upstream wireless network in the Key, and click Next.
5. Set the IP address of CPE2 to an unused IP address belonging to the same subnet as CPE1.
Set the Subnet Mask to the one same as CPE1, and click Next.
In this example, IP Address is set to 192.168.2.100 and Subnet Mask is set to
255.255.255.0.
6. Click Save, and wait until CPE2 reboots to make the settings take effect.
8
Document Version: V2.2
----End
When the two CPEs start bridging each other, all the LED1, LED2 and LED3 indicators blink fast.
When the LED1, LED2 and LED3 indicators of one CPE are lit solid and the same indicators of the
other CPE blink slowly, the bridging succeeds. To check the SSID and key of the CPE, you can log in
to the web UI of the CPE and navigate to Wireless > Basic.
9
Document Version: V2.2
10
Document Version: V2.2
Check the LED1, LED2 and LED3 indicators of the CPEs to confirm whether the positions are proper.
The more LED indicators light up, the better the connection quality is.
The LED indicator descriptions of the CPEs below are for reference.
Computer Each LED indicator is set with a received signal strength value,
which is the threshold for the corresponding LED indicator to
LED1, LED2, LED3 Solid on/Blinking light up. You can judge the connection quality through the
status of these indicators.
(Received signal strength
LED indicators)
11
Document Version: V2.2
1.2.1 Solution
O4V1.0 is used for illustration. Procedures for other CPE models are similar.
To quickly set up a monitoring network, it is recommended to configure the CPEs before installation.
Power cord
PoE injector
PoE
12
Document Version: V2.2
Power cord
PoE injector
PoE LAN
Computer
4. Select the wireless network of your ISP hotspot, which is Tenda_123456 in this example,
and click Next.
13
Document Version: V2.2
5. Enter the Wi-Fi password of your ISP hotspot in the Key field, and click Next.
6. Select the Internet Connection Type of your ISP hotspot, which is PPPoE in this example.
Enter the PPPoE user name and password provided by your ISP, and click Next.
14
Document Version: V2.2
8. Set an IP address that belongs to a subnet different from your ISP hotspot. For example, if
the IP address of your ISP hotspot is 192.168.2.1, you can set this CPE’s IP address to
192.168.X.1 (X ranges from 0 to 254 excluding 2). Then click Next.
9. Click Save, and wait until the CPE reboots to make the settings take effect.
----End
When LED1, LED2, and LED3 indicators of the CPE are blinking, the CPE is connected to your ISP
hotspot successfully.
15
Document Version: V2.2
This user guide is for configuration reference only and does not indicate that the product supports all
functions described here. Functions available may vary with the product model. Please refer to the
actual product.
2.1 Login
2.1.1 Login with computer
Step 1 Connect the computer to the CPE or the switch connected to the CPE.
Step 2 Set the IP address of the computer to an unused one within the same subnet as the CPE. (If
the DHCP of the CPE is enabled, skip this step)
For example, if the IP address of the CPE is 192.168.2.1, you can set the IP address of the
computer to 192.168.2.X (X ranges from 3 to 254 and is not occupied), and subnet mask to
255.255.255.0. The following figure is for reference only.
16
Document Version: V2.2
Step 3 Start a web browser on your computer, enter the default IP address of the CPE
(192.168.2.1 in AP mode or 192.168.2.2 in Client mode), and press the Enter (or Return)
key on your keyboard.
Step 4 Enter your user name and password, and click Login. The following figure is for reference
only.
− If the above page does not appear, try the following methods:
Ensure that the CPE is powered on properly.
Ensure that the computer is connected to the LAN port of the CPE properly.
Ensure that the IP address of the computer belongs to the same subnet as the CPE. For example,
if the IP address of the CPE is 192.168.2.1, you can set the IP address of the computer to
192.168.2.X (X ranges from 3 to 254 and is not occupied).
If more than one CPE is connected, modify the IP address of each one to avoid login failure due
to IP address conflict.
Reset the CPE to factory settings. Reset method: After CPE completes startup, hold down the
reset button (such as RST, RESET or Reset) for about 8 seconds, and then release it when all
indicators light up.
− The default login user name and password of the CPE are admin. For the network security, refer
to the Account to change the login user name and password.
----End
17
Document Version: V2.2
Step 2 Set the IP address of the smartphone to an unused one within the same subnet as the CPE.
(If the DHCP of the CPE is enabled, skip this step.)
18
Document Version: V2.2
For example, if the IP address of the CPE is 192.168.2.1, you can set the IP address of the
computer to 192.168.2.X (X ranges from 3 to 254 and is not occupied), and subnet mask to
255.255.255.0.
Step 4 Start a browser on your smartphone, and enter the default IP address of the CPE
(192.168.2.1 in AP mode or 192.168.2.2 in Client mode).
19
Document Version: V2.2
Step 5 Enter your user name and password, and click Login. The following figure is for reference
only.
----End
20
Document Version: V2.2
2.2 Logout
After you log in to the web UI of the router, the system will automatically log you out if there is no
operation within the login timeout interval (default: 5 minutes). Alternatively, you can directly click
Logout on the upper right corner to exit the web UI.
21
Document Version: V2.2
3 Web UI
3.1 Web UI layout
The web UI of the CPE is composed of 4 parts, including the level-1 navigation tree, level-2
navigation tree, tab, and configuration area. See the following figure.
3
1
Functions or parameters in grey fields indicate that are not available or cannot be modified under the
current configurations.
Used to display menu items of the CPE in the form of a navigation tree
❷ Level-2 navigation tree
that allows you to quickly access functions.
❸ Tab
22
Document Version: V2.2
Button Description
Used to save the configuration on the current page and enable the configuration to
take effect.
Used to go back to the original configuration without saving the configuration on the
current page.
Used to view help information corresponding to the settings on the current page.
23
Document Version: V2.2
4 Quick setup
− This user guide is for configuration reference only and does not indicate that the product supports
all functions described here. Functions available may vary with the product model. Please refer to
the actual product.
− If it is a CPE kit, the two CPEs are pre-configured and can be installed directly.
This module enables you to quickly change the working mode of the CPE and deploy your wireless
network.
Different working modes are described below. Select one to fit your needs:
− AP: In this mode, the CPE converts a wired network into a wireless one.
− Client: In this mode, the CPE works as a wireless adapter that can connect to other
wireless networks. The CPE does not provide wireless connections, so client devices
need to be connected with an Ethernet cable.
− Universal Repeater: In this mode, the CPE extends an existing wireless network for
broader network coverage. The wireless information (such as SSID and password) of
the new network is the same as the upstream wireless network.
− WISP: In this mode, the CPE connects to a hotspot provided by ISP in a wireless
manner, and provides the wireless network. The CPE can also be connected to the LAN
port of an upstream wireless router to obtain the IP address by DHCP (Dynamic IP),
static IP address or PPPoE for internet access.
− Repeater: In this mode, the CPE connects multiple wired networks through wireless
bridging, and provides wireless access point.
− P2MP: In this mode, the CPE connects multiple wired networks through wireless
bridging, but does not provide wireless access point.
− Router: In this mode, the CPE connects to a modem in a wired manner to obtain the IP
address by DHCP (Dynamic IP), static IP address or PPPoE for internet access.
24
Document Version: V2.2
4.1 AP mode
4.1.1 Overview
In AP mode, the CPE converts a wired network into a wireless one by connecting to the internet
through an Ethernet cable.
The CPE in AP mode usually works with another CPE in Client mode or Universal Repeater mode to
establish a video surveillance network. The following figure shows how the CPE in AP mode works
with the one in Client mode.
25
Document Version: V2.2
*
*
*
Parameters description
Name Description
Specifies the operating channel of this CPE. Select a less used channel in the ambient
environment to reduce interference.
Channel
Auto indicates that the CPE automatically adjusts its operating channel based on the
ambient environment.
Specifies the security mode of the wireless network, including None, WPA-PSK, WPA2-
Security Mode
PSK, and Mixed WPA/WPA2-PSK.
Step 4 Click Save, and wait until the CPE reboots to make the settings take effect.
----End
26
Document Version: V2.2
The CPE in Client mode usually works with the CPE in AP mode to create a video surveillance
network, and use the CPE in Client mode to connect to IP cameras. The network topology is shown
as below.
27
Document Version: V2.2
Step 3 Select the wireless network to bridge from the list, which is Tenda_123456 in this example,
and click Next.
If you cannot find any wireless network from the list, navigate to Wireless > Basic and enable the
wireless function. Then try again.
Step 4 Enter the Wi-Fi password for the selected wireless network Tenda_123456 in the Key field,
and click Next.
Parameters description
Name Description
Upstream AP Specifies the Wi-Fi name (SSID) of the wireless network to be bridged.
28
Document Version: V2.2
Step 6 Click Save, and wait until the CPE reboots to make the settings take effect.
----End
29
Document Version: V2.2
The CPE in Universal Repeater mode usually works with the CPE in AP mode to establish a video
surveillance network. The network topology is shown as below.
IP camera
NVR
Computer
4.3.2 Set Universal Repeater mode
Step 1 Log in to the web UI of the CPE, and navigate to Quick Setup.
Step 2 Select Universal Repeater, and click Next.
30
Document Version: V2.2
Step 3 Select the wireless network to bridge from the list, which is Tenda_123456 in this example,
and click Next.
If you cannot find any wireless network from the list, navigate to Wireless > Basic and enable the
wireless function. Then try again.
Step 4 Enter the Wi-Fi password of the upstream wireless network in the Key field, and click Next.
Parameters description
Name Description
Upstream AP Specifies the Wi-Fi name (SSID) of the wireless network to be bridged.
Specifies the security mode of the wireless network to be bridged. It will be automatically
Security Mode populated when you select an SSID to bridge. If the wireless network to be bridged has a
Wi-Fi password, you need to enter the password manually.
31
Document Version: V2.2
Step 6 Click Save, and wait until the CPE reboots to make the settings take effect.
----End
After the CPE is bridged, it uses the same key for the peer CPE.
32
Document Version: V2.2
The CPE is used to extend the ISP hotspot. The network topology is shown as below.
33
Document Version: V2.2
Step 3 Select the wireless network to bridge from the list, which is Tenda_123456 in this example,
and click Next.
If you cannot find any wireless network from the list, navigate to Wireless > Basic and enable the
wireless function. Then try again.
Step 4 Enter the Wi-Fi password of the upstream wireless network in the Key field, and click Next.
Parameters description
Name Description
Upstream AP Specifies the Wi-Fi name (SSID) of the wireless network to be bridged.
34
Document Version: V2.2
Step 5 Select the Internet Connection Type of your ISP hotspot, which is PPPoE in this example.
Enter the PPPoE user name and password provided by your ISP, and click Next.
Parameter description
Name Description
35
Document Version: V2.2
Step 7 Set an IP address belonging to a subnet different from your ISP hotspot. For example, if the
IP address of your ISP hotspot is 192.168.2.1, you can set the CPE’s IP address to
192.168.X.1 (X ranges from 0 to 254 excluding 2) which is also the login IP address of this
CPE. Then click Next.
Step 8 Click Save, and wait until the CPE reboots to make the settings take effect.
----End
After the CPE is rebooted, log in to the web UI of the CPE and navigate to Status.
− Ensure that the WAN IP address, default gateway and DNS server information obtained
by the WAN port are displayed on the System Status module.
− On the Wireless Status module, with the Working Mode is the WISP mode, if the SSID
is the Wi-Fi name you set in Step 6 and the AP’s MAC Address is the WLAN MAC
address of the peer device, the configuration is successful.
36
Document Version: V2.2
After the successful configuration, devices connected to the CPE can access to the internet in a
wired or wireless manner. In practical environments, it is recommended to connect a wireless
router to the CPE for omnidirectional wireless network coverage.
Wi-Fi name and Wi-Fi password are SSID and Key set in Step 6 above.
WAN LAN
Smartphone, Tablet
Computer
For detailed configuration of the router, refer to the corresponding user guide.
37
Document Version: V2.2
Repeater mode can be used to achieve communication between multiple office sites of an
enterprise in a city.
The CPE in Repeater mode can work with the CPE in Repeater or P2MP mode.
When configuring the Repeater mode, ensure that the Channel and Channel Bandwidth of all CPEs are
the same.
Internet
Router
WAN LAN
Switch Switch
Configuration procedure
To check the SSID and key of the CPE, you can log in to the web UI of the CPE and navigate to Wireless >
Basic.
38
Document Version: V2.2
39
Document Version: V2.2
4. Select the wireless network to bridge from the list, which is Tenda_123456 in this example,
and click Next.
− If wireless networks cannot be scanned, navigate to Wireless > Basic and enable the wireless
function. Then try again.
− Only the wireless networks whose security modes are set to None or WEP can be displayed on
the list.
5. Set Authentication Type and Default Key, enter the Key 1, and click Next.
40
Document Version: V2.2
Parameters description
Name Description
Peer AP1 Specifies the Wi-Fi name (SSID) of the wireless network to be bridged.
The Repeater mode only supports WEP and None security modes.
6. Set the IP address to an unused IP address within the same subnet as the peer CPE, which
is 192.168.2.100 in this example. Then set the Subnet Mask to the one same as the peer
CPE, and click Next.
7. Click Save, and wait until the CPE reboots to make the settings take effect.
Step 2 Refer to Step 1 to set the CPE2 to bridge CPE1 in Repeater mode.
----End
41
Document Version: V2.2
----End
42
Document Version: V2.2
Assuming that all CPEs uses the Repeater mode. The network topology is shown as below.
Office network
Switch
Switch
Office network
Switch
Office network
43
Document Version: V2.2
Assume that the SSIDs and MAC addresses of CPE1, CPE2, CPE3, and CPE4 are as follows:
Configuration procedure
Step 1 Set the CPE1 to the Repeater mode.
1. Log in to the web UI of CPE1, and navigate to Wireless > Basic.
2. Modify the Channel and Channel Bandwidth as required, and click Save.
44
Document Version: V2.2
4. Select the wireless network to bridge from the list, which is Tenda_1 in this example, and
click Next.
− If wireless networks cannot be scanned, navigate to Wireless > Basic and enable the wireless
function. Then try again.
− Only the wireless networks whose security modes set to None or WEP can be displayed on the
list.
5. Click Next.
45
Document Version: V2.2
6. Set the IP address to an unused IP address within the same subnet as the peer CPE, which
is 192.168.2.100 in this example. Then set the Subnet Mask to the one same as the peer
CPE, and click Next.
7. Click Save, and wait until the CPE reboots to make the settings take effect.
Step 2 Refer to Step 1 to set CPE2, CPE3 and CPE4 to bridge the primary CPE in Repeater mode.
Step 3 Set the primary CPE to Repeater mode and bridge to CPE1, CPE2, CPE3 and CPE4.
1. Log in to the web UI of the primary CPE, and navigate to Quick Setup.
2. Select Repeater mode, and click Next.
3. Select SSIDs of CPE1, CPE2, CPE3 and CPE4, and click Next.
− If wireless networks cannot be scanned, navigate to Wireless > Basic and enable the wireless
function. Then try again.
− Only the wireless networks whose security modes set to None or WEP can be displayed on the
list.
46
Document Version: V2.2
4. Click Next.
5. Click Next.
47
Document Version: V2.2
6. Click Save, and wait until the CPE reboots to make the settings take effect.
----End
You can ping these four CPEs' IP addresses on the primary CPE to check connectivity. Below takes
CPE1 as an example.
----End
To check the SSID and key of the CPE, you can log in to the web UI of the CPE and navigate to Wireless >
Basic.
48
Document Version: V2.2
The CPE in P2MP mode can work with the CPE in Repeater mode.
Switch
Router
Switch
WAN LAN
Office network
Office network
Office network
49
Document Version: V2.2
When configuring the P2MP mode, ensure that the Channel and Channel Bandwidth of all CPEs are the
same.
Assume that the SSIDs and MAC addresses of CPE1, CPE2, CPE3, and CPE4 are as follows:
Configuration procedure
When setting the CPE to P2MP and Repeater mode, ensure that all CPEs operate in the same channel.
Step 1 Set CPE1 to Repeater mode and bridge to the primary CPE.
1. Log in to the web UI of CPE1, and navigate to Wireless > Basic.
2. Modify the Channel and Channel Bandwidth as required, and click Save.
50
Document Version: V2.2
51
Document Version: V2.2
4. Select the wireless network to bridge from the list, which is Tenda_1 in this example, and
click Next.
− If wireless networks cannot be scanned, navigate to Wireless > Basic and enable the wireless
function. Then try again.
− Only the wireless networks whose security modes are set to None or WEP can be displayed on
the list.
5. Click Next.
52
Document Version: V2.2
6. Set the IP address to an unused IP address within the same subnet as the peer CPE, which
is 192.168.2.100 in this example. Then set the Subnet Mask to the one same as the peer
CPE, and click Next.
7. Click Save, and wait until the CPE reboots to make the settings take effect.
Step 2 Refer to Step 1 to set the CPE2, CPE3 and CPE4 to bridge to the primary CPE in Repeater
mode.
Step 3 Set the primary CPE to P2MP mode and bridge to CPE1, CPE2, CPE3 and CPE4.
1. Log in to the web UI of the primary CPE, and navigate to Quick Setup.
2. Select P2MP mode, and click Next.
3. Select the SSIDs of CPE1, CPE2, CPE3 and CPE4, which are Tenda_2, Tenda_3, Tenda_4 and
Tenda_5 in this example, and click Next.
4. Click Next.
53
Document Version: V2.2
Parameters description
Name Description
Peer AP1 Specifies the Wi-Fi name (SSID) of the wireless network to be bridged.
The P2MP mode only supports WEP and None security modes.
5. Click Next.
54
Document Version: V2.2
6. Click Save, and wait until the CPE reboots to make the settings take effect.
----End
You can ping these four CPEs' IP addresses on the primary CPE to check connectivity. Below takes
CPE1 as an example.
----End
55
Document Version: V2.2
The CPE is used to provide a wireless network and assign IP addresses to your Wi-Fi-enabled
devices. The network topology is shown as below.
Internet
Router mode
Modem
LAN
Smartphone, Tablet
If there is only one Ethernet port on the CPE, you can connect a wireless device (such as a laptop) to the
wireless network of the CPE and log in to the web UI of the CPE to perform following configurations.
Step 1 Log in to the web UI of the CPE, and navigate to Quick Setup.
Step 2 Select Router mode, and click Next.
Step 3 Select your internet connection type of your ISP hotspot, and set the related parameters.
Take PPPoE as an example here.
56
Document Version: V2.2
1. Select PPPoE.
2. Enter the PPPoE User Name and Password provided by your ISP.
3. Click Next.
Parameters description
Name Description
57
Document Version: V2.2
Parameters description
Name Description
Security Mode Specifies the security mode of the wireless network of the CPE, including None, WPA-
PSK, WPA2-PSK, and Mixed WPA/WPA2-PSK.
Step 5 Click Save, and wait until the CPE reboots to make the settings take effect.
----End
After the CPE is rebooted, verify the settings as follows.
Log in to the web UI of the CPE and navigate to Status. Ensure that the WAN IP address, default
gateway and DNS server information obtained by the WAN port are displayed on the System Status
module.
After the successful configuration, devices connected to the CPE can access to the internet in a
wired or wireless manner.
58
Document Version: V2.2
− If there is only one LAN port on the CPE, you can connect your Wi-Fi-enabled devices to the
wireless network of the CPE to access the internet.
− The name and password of the wireless network are SSID and Key set in Step 4.
If the CPE has more than one LAN port, you can connect a wireless router to the CPE for
omnidirectional wireless network coverage. The network topology is shown as below.
Router mode
Internet
Wireless router
Modem
PoE/LAN LAN
Computer
For detailed configuration of the router, refer to the corresponding user guide.
‒ Wired devices: Connect the wired devices, such as a computer, to the LAN ports of the wireless
router which is connected to the CPE. Ensure that the IP address of the computer is
automatically obtained.
59
Document Version: V2.2
5 Status
This user guide is for configuration reference only and does not indicate that the product supports all
functions described here. Functions available may vary with the product model. Please refer to the
actual product.
This module allows you to view the information of system and wireless network, including system
status, wireless status, and statistics.
You can view the system status here. O8V1.0 is used for illustration.
If the CPE is set to AP mode, Client mode, Universal Repeater mode, Repeater mode or P2MP mode,
the system status is shown as follows. If the CPE has multiple Ethernet ports, this page displays the
current connection rate of each LAN port.
If the CPE is set to WISP or Router mode, the system status is shown as follows:
When the CPE works in Router mode, the PoE port serves as a WAN port.
60
Document Version: V2.2
Parameters description
Name Description
Specifies the name of this CPE. Different device names help you identify CPEs in
LAN easily.
Device Name You can change the name of this CPE on the LAN Setup page when the device
works in AP, Client, Universal Repeater, Repeater, and P2MP modes. When the
device works in WISP or Router mode, it displays the model of the device, and
cannot be changed.
Uptime Specifies the time that has elapsed since the CPE was started last time.
Firmware Version Specifies the system firmware version number of this CPE.
CPU Specifies the Central Processing Unit (CPU) usage of this CPE.
LAN MAC Address Specifies the MAC address of LAN port of this CPE.
WLAN MAC Address Specifies the MAC address of the wireless interface of this CPE.
61
Document Version: V2.2
Name Description
LAN Speed Specifies the Ethernet port negotiation speed and duplex mode of this CPE.
Specifies the IP address of this CPE, which is also the management IP address of
this CPE.
LAN IP Address
A LAN user can access the web UI of this CPE using this IP address. You can
modify this IP address on the LAN Setup page.
Specifies the internet connection type of this CPE in WISP or Router mode.
− DHCP (Dynamic IP): The CPE obtains IP address from the upstream
DHCP server for internet access.
Connection Type
− Static IP Address: The CPE uses a fixed IP address, subnet mask, default
gateway, and DNS server info for internet access.
− PPPoE: The CPE uses a user name and password for internet access.
Connection Status Specifies the connection status of WAN port of this CPE in WISP or Router mode.
WAN IP Address Specifies the IP address of WAN port of this CPE in WISP or Router mode.
Default Gateway Specifies the default gateway address of this CPE in WISP or Router mode.
Specifies the IP address of primary DNS server of this CPE in WISP or Router
Primary DNS Server
mode.
Specifies the IP address of secondary DNS server of this CPE in WISP or Router
Secondary DNS Server
mode.
62
Document Version: V2.2
You can view wireless status here, including working mode, SSID, security mode and so on. O6V3.0
is used for illustration here.
Parameters description
Name Description
Working Mode Specifies the working mode in which the CPE operates.
Security Mode Specifies the security mode of the wireless network of the CPE’s operating RF.
Channel/Radio Band Specifies the channel and radio band used by this CPE to transmit radio signals.
Channel Bandwidth Specifies the channel bandwidth of the CPE’s operating RF.
Specifies the number of wireless clients connected to the wireless network of the
Wireless Client
CPE’s operating RF.
63
Document Version: V2.2
Name Description
Specifies the strength of radio interference signals in the ambient environment that
Background Noise interferes with the wireless signal of this CPE in the same channel. Larger absolute
value indicates less interference.
Specifies the number of spatial streams of wireless data the CPE is transmitting or
TX/RX Link
receiving. The more links indicate the more traffic.
TD-MAX Specifies the status of the TD-MAX function. For details, refer to TD-MAX.
Specifies the distance between the two CPEs after the bridging succeeds.
Distance If there are more than two CPEs, it specifies the bridging distance between this CPE
and the farthest CPE.
64
Document Version: V2.2
Parameters description
Name Description
SSID Specifies the Wi-Fi name sent by the CPE’s management RF.
Channel/Frequency
Specifies the channel and frequency band of the CPE’s management RF.
Band
Specifies the status of the CPE’s management RF auto-start function. With this
Enabled upon Power on function enabled, the management RF will be automatically enabled after the CPE is
powered off and then powered on again.
Specifies the duration of the CPE’s management RF enabled. If you do not delay
Duration duration of management RF's wireless network, the management RF will be
automatically disabled after the auto-start duration is exceeded.
65
Document Version: V2.2
5.3 Statistics
To access the configuration page, log in to the web UI of the CPE and navigate to Status.
You can learn statistics information about throughput, wireless client, interface, ARP table and
routing table here.
5.3.1 Throughput
On the Statistics module, click Throughput to access the page. The line charts visually show the
real-time transmitting and receiving traffic of WLAN and LAN port of the CPE.
66
Document Version: V2.2
In AP, Router, P2MP or Repeater mode, it displays information of connected wireless clients.
Parameters description
Name Description
Transmit/Receive Specifies the transmitting and receiving rate of the wireless client.
Specifies the connection quality of the wireless client. A higher percentage indicates
CCQ
better connection quality.
Specifies the time that has elapsed since the wireless client is connected to the
Connection Duration
wireless network of the CPE.
67
Document Version: V2.2
5.3.3 Upstream AP
On the Statistics module, click Upstream AP to access the page.
In Client, Universal Repeater or WISP mode, it displays information of the upstream AP.
Parameters description
Name Description
Transmit/Receive Specifies the transmitting and receiving rate of the upstream device.
Specifies the connection quality between this CPE and the upstream device. A higher
CCQ
percentage indicates better connection quality.
Connection Duration Specifies the time that has elapsed since this CPE bridges the upstream device.
68
Document Version: V2.2
5.3.4 Interface
On the Statistics module, click Interface to access the page.
It displays the IP address, MAC address and traffic information of the interfaces of the CPE.
Parameters description
Name Description
Interface Specifies the wired interface, bridge interface, and WLAN interface of the CPE.
Specifies the IP addresses of the wired interface, bridge interface, and WLAN
IP Address
interface.
Specifies the MAC addresses of the wired interface, bridge interface, and WLAN
MAC Address
interface.
Received Packets
Specify the number of received or transmitted packets of the interface.
Transmitted Packets
Receive Error
Specify the number of received or transmitted error packets of the interface.
Transmit Error
69
Document Version: V2.2
Address Resolution Protocol (ARP) is a network layer protocol used to convert the IP address of the
destination device into a physical address. The ARP table displays the IP address and its MAC
address the device visits.
Parameters description
Name Description
MAC Address Specifies the MAC address corresponding to the IP address of the host.
70
Document Version: V2.2
Parameters description
Name Description
Specifies the IP address of the entrance of the next hop route when the packets
Next Hop
egress from the interface of the CPE.
71
Document Version: V2.2
6 Network
This user guide is for configuration reference only and does not indicate that the product supports all
functions described here. Functions available may vary with the product model. Please refer to the actual
product.
To access the configuration page, log in to the web UI of the CPE and navigate to Network > LAN
Setup.
In AP, Client, Universal Repeater, Repeater and P2MP modes, the page is displayed as below.
72
Document Version: V2.2
Parameters description
Name Description
If the IP Address Type is set to DHCP (Dynamic IP Address), you need to check the
CPE’s IP address on the clients list of the upstream DHCP server, and use this IP
address to log in to the web UI of the CPE.
Specifies the IP address of the CPE. A LAN user can use this IP address to log in to the
web UI of the CPE.
IP Address
To connect the CPE to the internet, change this IP address to the same subnet of the
LAN IP address of the egress router.
Subnet Mask Specifies the subnet mask of the CPE. The default is 255.255.255.0.
Specifies the name of the CPE. The default name is the product model and version.
Device Name You are recommended to change the name to indicate the location of the CPE, so
that you can easily identify the target CPE in the network.
73
Document Version: V2.2
When the CPE works in WISP or Router mode, the page is displayed as below.
Parameters description
Name Description
If the IP Address Type is set to DHCP (Dynamic IP Address), you need to check the
CPE’s IP address on the clients list of the upstream DHCP server, and use this IP
address to log in to the web UI of the CPE.
Specifies the LAN IP address of the CPE. A LAN user can visit this address to log in to
IP Address
the web UI of the CPE.
Specifies the subnet mask corresponding to the LAN IP address of the CPE. The
Subnet Mask default is 255.255.255.0.
74
Document Version: V2.2
Configuration procedure
----End
75
Document Version: V2.2
After changing the LAN IP address of the CPE, if the new and original IP addresses belong to the
same subnet, you can log in to the web UI of the CPE by accessing the new IP address.
Otherwise, assign your computer an IP address that belongs to the same subnet as the new IP
address of the CPE before login with the new IP address. Refer to How to assign a fixed IP address to
your computer in Appendix for details.
Configuration procedure
----End
After completing the configuration, if you want to re-log in to the web UI of the CPE, check the new
IP address on the web UI of the upstream device which assigns the IP address to this CPE. Ensure
that the IP address of the management computer and the IP address of the CPE belong to the same
subnet, and access the IP address of the CPE.
Refer to steps in the How to assign a fixed IP address to your computer part to assign an IP address
to the computer manually.
76
Document Version: V2.2
On this page, you can set parameters related to the packet filtering function of the wired Ethernet
port. The CPE kit O1V1.1 is used for illustration.
Parameters description
Name Description
Filter Rule Indicates the Specifies whether to allow packets without filtering rules configured to pass
packet filtering mode through.
77
Document Version: V2.2
Name Description
Rule details Specifies the parameter settings required for filtering rules to filter the packets.
Regular switch state Specifies the status of the filtering rule. Values: Enable and Disable.
Filter mode Specifies whether to filter the packets. Values: Permit and Prohibit.
Source MAC Specifies the data frames from this MAC address will be filtered.
Specifies the data frames with this MAC address as the destination address will
Destination MAC
be filtered.
Specifies the packets with this IP address as the destination address will be
Destination IP
filtered.
Specifies the type of transport layer protocol used by the data segments that
IP protocol type
need to be filtered. All means filtering both TCP and UDP protocols.
Source port Specifies the packets corresponding to the source port number will be filtered.
Used to customize the protocol type field of the packets that need to be filtered
Custom
(2 bytes, hexadecimal, such as 0x8010).
78
Document Version: V2.2
6.3.1 Overview
If the CPE cannot access the internet after you configure the internet settings, your ISP may have
associated your internet service account with a device's MAC address.
Before you clone the MAC address of the computer or the router's WAN port, ensure that the device you
used previously can access the internet.
Method 1
Step 1 Connect the computer to the CPE.
Step 2 Log in to the web UI of the CPE, and navigate to Network > MAC Clone.
Step 3 Click Clone Local MAC Address.
Step 4 Click Save.
----End
79
Document Version: V2.2
Method 2
Step 1 Log in to the web UI of the router, and record the MAC address.
Step 2 Log in to the web UI of the CPE, and navigate to Network > MAC Clone.
Step 3 Enter the MAC address of the computer in the MAC Address field.
Step 4 Click Save.
----End
If you want to restore the MAC address to factory settings, navigate to Network > MAC Clone, click
Restore to Default MAC Address, and click Save.
80
Document Version: V2.2
If you change the LAN IP address of the CPE and the new and original IP addresses belong to different
subnets, the system automatically changes the IP address pool of the DHCP server to be in the same
subnet as the new IP address of the LAN port.
*
*
----End
If another DHCP server is available in your LAN, ensure that the IP address pool of the CPE does not
overlap with the IP address pool of that DHCP server. Otherwise, IP address conflicts may occur.
81
Document Version: V2.2
Parameters description
Name Description
DHCP Server Specifies whether to enable the DHCP server function of the CPE.
Specifies the start IP address of the IP address pool of the DHCP server. The default
Start IP Address
value is 192.168.2.100.
Specifies the end IP address of the IP address pool of the DHCP server. The default
value is 192.168.2.200.
End IP Address
The start and end IP addresses must belong to the same subnet as the LAN port of
the CPE.
Specifies the subnet mask assigned by the DHCP server to clients. The default value is
Subnet Mask
255.255.255.0.
Specifies the IP address of default gateway assigned by the DHCP server to clients.
Generally, it is the IP address of the LAN port of the router in LAN. The default value
is 192.168.2.254.
Gateway Address
A client can access a server or host not in the local network segment only through a
gateway.
Specifies the primary DNS server IP address assigned by the DHCP server to clients.
The default value is 8.8.8.8.
To enable clients to access the internet, set this parameter to a correct DNS server IP
address or DNS proxy IP address.
Specifies the secondary DNS server IP address assigned by the DHCP server to clients.
Secondary DNS Server
This parameter is optional.
Specifies the validity period that a client holds an IP address assigned by the DHCP
server.
When the IP address expires:
− If the client is still connected to the CPE, the client will automatically renew
Lease Time and continue to occupy the IP address.
− If the client is not connected (due to shut-down or wireless disconnection),
the CPE will release the IP address. If other clients send a request for an IP
address, the CPE can assign this IP address to other clients.
You are recommended to keep the default value.
82
Document Version: V2.2
To access the configuration page, log in to the web UI of the CPE and navigate to Network > DHCP
Client.
Parameters description
Name Description
MAC Address Specifies the MAC address assigned by the DHCP server to clients.
Specifies the validity period that a client holds an IP address assigned by the DHCP
Lease Time
server.
83
Document Version: V2.2
Once the 802.1Q VLAN settings take effect, tagged packets will be forwarded to the ports with VLANs
assigned based on the packet's VLAN ID, and untagged packets will be forwarded to the ports with
VLAN assigned based on the port's PVID.
The following form shows how different link type ports process received packets:
Received Packets
Port Type Transmitted Packets
Tagged Packets Untagged Packets
84
Document Version: V2.2
Parameters description
Name Description
VLAN Settings Specifies whether to enable 802.1Q VLAN on this CPE. By default, it is disabled.
PVID Specifies the default native VLAN ID of the trunk port. The default is 1.
Specifies the wired LAN port as this CPE's trunk port. A trunk port allows all VLANs to
pass through.
Trunk Port
After 802.1Q VLAN is enabled on the CPE that does not support custom trunk ports,
the LAN port that can be used for PoE power supply (such as: PoE/LAN) works as the
CPE's trunk port.
Used to set a VLAN ID for the wireless network of this CPE. By default, it is set to 1000.
WLAN VLAN ID After the VLAN function is enabled, the WLAN interface functions is equivalent to an
access port, whose PVID is the same as VLAN ID.
LAN2
Used to set a VLAN ID of the Ethernet port of this CPE. By default, it is set to 1.
LAN3 After the VLAN function is enabled, the Ethernet port is equivalent to an access port,
whose PVID is the same as VLAN ID.
LAN4
Two communities want to create a separate network with two CPEs and connect to the internet
through the same router.
Solution
− Configure two separate DHCP servers for VLAN10 and VLAN20 on the router that
supports IEEE 802.1q VLAN.
85
Document Version: V2.2
Network topology
CPE2: VLAN20
Power socket
Computer
PoE injector
PoE LAN
Configuration procedure
86
Document Version: V2.2
Uplink port
Trunk 1, 10, 20 1
(Connected to the router)
Port 1
Trunk 1, 10 1
(Connected to CPE1)
Port 3
Trunk 1, 20 1
(Connected to CPE2)
Keep the default settings for other ports not mentioned here. For details, see the user guide
for the switch.
Step 4 Set up the router.
1. Enable two DHCP servers on the router, and assign them to VLAN10 and VLAN20
respectively.
2. Configure the QVLAN on the router as shown in the following table.
Verification
If the router enables two DHCP servers for VLAN10 and VLAN20 respectively, the client connected to
the CPE1 obtains an IP address and related parameters from the DHCP server belonging to VLAN10,
and the client connected to CPE2 obtains these parameters from the DHCP sever belonging to
VLAN20.
87
Document Version: V2.2
7 Wireless settings
This user guide is for configuration reference only and does not indicate that the product supports all
functions described here. Functions available may vary with the product model. Please refer to the
actual product.
Broadcast SSID
If broadcast SSID is enabled, nearby wireless clients can detect the SSID. If the function is disabled,
the CPE does not broadcast the SSID and nearby wireless clients cannot detect the SSID. In this case,
you need to enter the SSID manually on your wireless client if you want to connect to the wireless
network of the SSID. This to some extent enhances the security of the wireless network.
However, hackers may still find ways to obtain SSIDs and gain access to target networks.
Isolate client
Similar to a VLAN on a wired network, the isolate client function completely isolates all wireless
clients connected to the same SSID. Only the wired network connected by the CPE can be accessed.
It is suitable for the establishment of public hotspots such as hotels and airports, so that the
wireless clients connected can be kept isolated and the wireless network security can be improved.
Security mode
A wireless network uses radio, which is open to the public, as its data transmission medium. If a
wireless network is not protected by necessary measures, any client can connect to the network to
use the resources of the network or access unprotected data over the network.
88
Document Version: V2.2
To ensure communication security, transmission links of wireless networks must be encrypted for
protection.
There are various security modes for network encryption, including None, WEP, WPA-PSK, WPA2-
PSK, Mixed WPA/WPA2-PSK, WPA, and WPA2.
◼ None
In this mode, any wireless client can connect to the CPE's wireless network. This is not a secure
option.
◼ WEP
Wired Equivalent Privacy (WEP) uses a static key to encrypt all exchanged data, and ensures that a
wireless LAN has the same level of security as a wired LAN. Data encrypted based on WEP can be
easily cracked. In addition, WEP supports a maximum wireless network throughput of only 54
Mbps. Therefore, this security mode is not recommended.
◼ WPA-PSK, WPA2-PSK and Mixed WPA/WPA2-PSK
WPA-PSK, WPA2-PSK and Mixed WPA/WPA2-PSK (compatible with WPA-PSK and WPA2-PSK) use a
pre-shared key or personal key for authentication only. Data encryption keys are generated by the
CPE. This prevents the vulnerability caused by static WEP keys, and makes the three security modes
suitable for ensuring security of home wireless networks.
Nevertheless, because the initial pre-shared key for authentication is manually set and all clients
use the same key to connect to the same CPE, the key may be disclosed unexpectedly. This makes
the security modes not suitable for scenarios where high security is required.
◼ WPA and WPA2
To address the key management weakness of WPA-PSK and WPA2-PSK, the Wi-Fi Alliance puts
forward WPA and WPA2, which use 802.1x to authenticate clients and generate root keys to encrypt
data, instead of using pre-shared keys that set manually. The encryption process is same as WPA-
PSK and WPA2-PSK.
WPA and WPA2 use 802.1x to authenticate clients and the login information of a client is managed
by the client. This effectively reduces the probability of information leakage.
In addition, each time a client connects to an AP that adopts the WPA or WPA2 security mode, the
RADIUS server generates a data encryption key and assigns it to the client. This makes it difficult for
attackers to obtain the key.
These features of WPA and WPA2 help significantly increase network security, making WPA and
WPA2 the preferred security modes of wireless networks that require high security.
89
Document Version: V2.2
90
Document Version: V2.2
Parameters description
Name Description
Transparent WDS and Transparent Bridge cannot be enabled at the same time.
Specifies the bandwidth of the operating channel of the CPE's wireless network.
Channel Bandwidth The channel bandwidth varies with different network modes. Select it based on your
actual operating environment. Auto indicates that the CPE can switch its channel
bandwidth based on the ambient environment.
91
Document Version: V2.2
Name Description
When the Channel Shift function is enabled, other CPEs that bridge with it should
also enable this function, and the offset value must be consistent. Otherwise, the
bridging will fail.
Specifies the offset value of the channel center frequency. This parameter is
Offset Value
available only when the Channel Shift function is enabled.
The maximum negotiation rate varies with different channel bandwidths and
Transmit Rate network modes. Refer to the web UI of the CPE for details. When Auto is selected,
the CPE will be adjusted to the maximum transmit rate under the corresponding
network mode.
There are various security modes for network encryption, including None, WEP,
Security Mode
WPA-PSK, WPA2-PSK, Mixed WPA/WPA2-PSK, WPA, and WPA2.
Enable: Clients connected to this wireless network cannot communicate with each
other, which improves the wireless network security.
Isolate Client
Disable: Clients connected to this wireless network can communicate with each
other. It is Disable by default.
Specifies the maximum number of clients that can connect to the wireless network
corresponding to an SSID.
Max. Number of Clients
If the number is reached, the wireless network rejects new connection requests from
clients.
92
Document Version: V2.2
◼ None
In this mode, the wireless network is not protected by password. This is not a secure option.
◼ WEP
Parameters description
Name Description
Specifies the encryption type for the WEP security mode. Values:
− Open: A wireless client can connect to the wireless network of the selected
SSID without being authenticated, and data exchanged between the client
Encryption Type and the network is encrypted using WEP.
− Shared: A shared key is used for authentication and data is encrypted using
WEP. In this case, a wireless client must use a preset WEP key to connect
to the wireless network of the selected SSID. The wireless client can be
connected to the wireless network only if they use the same WEP key.
Specifies the WEP key for the Open or Shared encryption type.
Default Key For example, if Default Key is set to Key 2, a wireless client can connect to the
wireless network of the selected SSID only with the password specified by Key 2.
Specifies the WEP key. You can enter four keys, but only the one specified as Default
Key takes effect.
Key 1/2/3/4 Supported formats:
− ASCII: Enter 5 or 13 ASCII characters for the key.
− Hex: Enter 10 or 26 hexadecimal characters (0-9, a-f, and A-F) for the key.
93
Document Version: V2.2
Parameters description
Name Description
Specifies the security mechanism that protects the wireless network. Values:
− WPA-PSK: The wireless network of the selected SSID is encrypted using
WPA-PSK.
Security Mode − WPA2-PSK: The wireless network of the selected SSID is encrypted using
WPA2-PSK.
− Mixed WPA/WPA2-PSK: Wireless clients can connect to the wireless
network of the selected SSID using either WPA-PSK or WPA2-PSK.
If Security Mode is set to WPA-PSK, this parameter can be set to AES or TKIP. If it is
set to WPA2-PSK or Mixed WPA/WPA2-PSK, this parameter can be set to AES, TKIP,
or TKIP&AES.
Specifies a pre-shared WPA key. A WPA key can contain 8 to 63 ASCII characters or 8
Key
to 64 hexadecimal characters.
Specifies the automatic update interval of a WPA key for data encryption. A shorter
Key Update Interval interval results in higher data security.
The value 0 indicates that a WAP key is not updated.
94
Document Version: V2.2
◼ WPA, WPA2
Parameters description
Name Description
Specifies the security mechanism that protects the wireless network. Values:
− WPA: The wireless network of the selected SSID is encrypted using WPA-
Security Mode PSK.
− WPA2: The wireless network of the selected SSID is encrypted using WPA2-
PSK.
RADIUS Server Specifies the IP address of the RADIUS server for client authentication.
RADIUS Port Specifies the port number of the RADIUS server for client authentication.
RADIUS Password Specifies the shared key of the RADIUS server for client authentication.
95
Document Version: V2.2
When the CPE works in Client or Universal Repeater mode, the basic wireless settings page is
displayed as below. O8V1.0 in Client mode is used for illustration.
Parameters on the Basic page vary with different modes. The actual web UI shall prevail.
The following table describes parameters for the CPE in Client mode. For other parameters, see
Parameter description of AP mode.
96
Document Version: V2.2
Name Description
Specifies the SSID of the primary upstream wireless network that the CPE connects to.
Primary Upstream
SSID After bridging succeeds, the SSID of the primary upstream wireless network will
automatically populate.
Lock With this function enabled, the CPE can only connect to the wireless network with the
current MAC address, and cannot connect to other upstream APs with the same Wi-Fi
name.
Specifies the SSID of the secondary upstream wireless network that the CPE connects
Secondary Upstream to.
SSID With this function enabled, if the CPE fails to connect to the primary upstream SSID, it
will automatically connect to the secondary upstream SSID.
Secondary Upstream
Specifies the wireless MAC address of the secondary upstream wireless network.
BSSID
Specifies the interval at which the CPE tries to reconnect to the primary upstream SSID
Reconnection Interval
when it is connected to the secondary upstream SSID.
Site Survey Used to refresh the available wireless networks and select the one for connection.
97
Document Version: V2.2
A community uses the CPE to deploy its network for CCTV surveillance. It requires that the SSID is
FREE and there is no Wi-Fi password.
Network topology
SSID: FREE
Internet
Router
LAN
Switch
WAN
Computer
Configuration procedure
Step 1 Log in to the web UI of the CPE.
Step 2 Navigate to Wireless > Basic.
Step 3 Set SSID to FREE.
Step 4 Set Security Mode to None.
Step 5 Click Save.
98
Document Version: V2.2
----End
Verification
Wi-Fi-enabled devices can connect to the wireless network whose SSID is FREE without a password.
99
Document Version: V2.2
A factory uses CPEs to set up a wireless network. It requires that the wireless network has a certain
level of security. In this case, WPA2-PSK mode is recommended.
Network topology
SSID: Factory
Key: UmXmL9UK
Internet
Router
Router
Switch
WAN LAN
Compute
r
Computer
Configuration procedure
Step 1 Log in to the web UI of the CPE.
Step 2 Navigate to Wireless > Basic.
Step 3 Set SSID to Factory.
Step 4 Set Security Mode to WPA2-PSK and Encryption Algorithm to AES.
Step 5 Set Key to UmXmL9UK.
Step 6 Click Save.
100
Document Version: V2.2
*
*
----End
Verification
Wi-Fi-enabled devices can connect to the Wi-Fi named Factory with the password UmXmL9UK.
101
Document Version: V2.2
A highly secure wireless network is required and a RADIUS server is available. In this case, WPA or
WPA2 mode is recommended.
Network topology
RADIUS Server
IP: 192.168.2.200 Switch Router Internet
Configuration procedure
I. Configure the CPE
Assume that:
− IP address of the RADIUS server: 192.168.2.200
− RADIUS Password: UmXmL9UK
− Authentication port: 1812
− SSID of the CPE: hot_spot
− Security mode: WPA2
− Encryption algorithm: AES
Step 1 Log in to the web UI of the CPE, and navigate to Wireless > Basic.
Step 2 Set SSID to hot_spot.
Step 3 Set Security Mode to WPA2.
Step 4 Set RADIUS Server, RADIUS Port, and RADIUS Password to 192.168.0.200, 1812, and
UmXmL9UK respectively.
Step 5 Set Encryption Algorithm to AES.
Step 6 Click Save.
102
Document Version: V2.2
*
*
*
*
*
----End
II. Configure the RADIUS server
Windows 2016 is used as an example to describe how to configure the RADIUS server.
Step 1 Install Active Directory Certificate Services and Network Policy and Access Services, and
deploy the certificate.
1. On the Start > Server Manager > Dashboard page, navigate to Add roles and features >
Server Selection > Server Roles, and tick the Active Directory Certificate Services.
2. According to the operation wizard, install the Certification Authority of Active Directory
Certificate Services and Network Policy and Access Services.
103
Document Version: V2.2
3. After the service installation is completed, click in the upper right corner and follow
the prompts to deploy the certificate.
Step 2 Configure 802.1X.
1. Navigate to Start > Server Manager > Dashboard, click Tools in the upper right corner, and
click Network Policy Server.
2. Select RADIUS server for 802.1X Wireless or Wired Connection from Standard
Configuration and click Configure 802.1X.
104
Document Version: V2.2
3. Select Secure Wireless Connections for Type of 802.1X connections. Modify the name as
required, which is Secure Wireless Connections in this example, and click Next.
105
Document Version: V2.2
6. Select Microsoft: Protected EAP (PEAP) from Type, and click Configure. Select the
certificate deployed in the certificate authority in the previous step, click OK, and click
Next after the configuration is completed.
106
Document Version: V2.2
8. On the Configure Traffic Controls page, configure the parameters as required, click Next,
and click Finish.
107
Document Version: V2.2
108
Document Version: V2.2
109
Document Version: V2.2
3. Click Network Policies and double-click Secure Wireless Connections. On the Secure
Wireless Connections Properties window, click Conditions, and click Add.
Add the Windows Groups, enter the created user group, click Check Names, click OK, then
click OK, and click Apply.
110
Document Version: V2.2
----End
111
Document Version: V2.2
Step 1 Navigate to Start > Control Panel > Network and Internet > Network and Sharing Center,
then click Manage wireless networks.
112
Document Version: V2.2
Step 3 Enter wireless network information, select Connect even if the network is not
broadcasting, and click Next.
113
Document Version: V2.2
Step 4 Click Change connection settings. Click the Security tab, select Microsoft: Protected EAP
(PEAP), and click Settings.
114
Document Version: V2.2
Step 5 Deselect Validate server certificate and click Configure. Deselect Automatically use my
Windows logon name and password (and domain if any) and click OK.
115
Document Version: V2.2
Step 6 Click Advanced settings. Select User or computer authentication and click OK.
116
Document Version: V2.2
117
Document Version: V2.2
Step 8 Click the network icon in the lower-right corner of the desktop and choose the wireless
network of the CPE such as hot_spot in this example. Click Connect.
Step 9 In the Windows Security dialog box that appears, enter the user name and password set
on the RADIUS server and click OK.
----End
Verification
Wi-Fi-enabled devices can connect to the wireless network hot_spot.
118
Document Version: V2.2
To access the configuration page, log in to the web UI of the CPE and navigate to Wireless >
Advanced.
Parameters description
Name Description
119
Document Version: V2.2
Name Description
Automatic Power Save Delivery (APSD) is a WMM power saving protocol created by
Wi-Fi Alliance.
APSD
Enabling APSD helps reduce power consumption. By default, this mode is disabled.
The Transparent Bridge function enables the WLAN interface of this CPE to forward
all packets. It is used to solve the problem that some NVRs cannot detect IP
cameras, or cannot change the IP addresses of cameras in different networks.
Transparent Bridge
‒ This function is applicable only when the CPE works in AP, Client or Universal
Repeater mode.
‒ Transparent WDS and Transparent Bridge cannot be enabled at the same time.
If TD-MAX is enabled, the device operates in TD-MAX mode and only accepts
connections from TD-MAX devices. And you cannot connect standard Wi-Fi devices,
such as laptops, tablets, or smartphones, to the CPE.
120
Document Version: V2.2
Name Description
The Transmit Power Control (TPC) function decreases the TX power of this CPE
automatically to improve the negotiation rate when the two devices are too close.
TPC
By default, when the received signal strength is greater than -25 dBm, the CPE
decreases its TX power.
Used to adjust the signal reception level of this CPE. A higher level leads to better
Signal Reception Level signal reception capability and more wireless networks can be searched, but lower
throughput. Adjust the level based on your actual situation.
Specifies the wireless transmission distance of this CPE. You can set it based on the
actual installation distance.
Transmission Distance
Modifying this distance will affect wireless transmission performance, and it is
recommended to keep the default setting. If you want to set it manually, you should
enter a value that is greater than the actual distance between the two CPEs.
121
Document Version: V2.2
Name Description
Specifies the frame length threshold for triggering the RTS/CTS mechanism. If a
frame exceeds this threshold, the RTS/CTS mechanism is triggered to reduce
conflicts. The unit is byte.
Set the RTS threshold based on the actual situation. An excessively small value
increases the RTS frame transmission frequency and bandwidth requirement. A
RTS Threshold higher RTS frame transmission frequency enables a wireless network to recover
from conflicts quicker. For a wireless network with high user density, you can
reduce this threshold for reducing conflicts.
The RTS mechanism requires some network bandwidth. Therefore, it is triggered
only when frames exceed this threshold.
Specifies the countdown before this device transmits broadcast and multicast
frames in its cache. The unit is Beacon interval.
DTIM Interval
For example, if Delivery Traffic Indication Map (DTIM) Interval is set to 1, this CPE
transmits all cached frames at one Beacon interval.
122
Document Version: V2.2
To access the configuration page, log in to the web UI of the CPE and navigate to Wireless > Access
Control. This function is disabled by default. After it is enabled, the page is shown as follows.
Parameters description
Name Description
Specifies the SSID of this device. With the rule enabled, clients connected to the
SSID
network with this SSID will be controlled by the rule.
Access Control Specifies whether to enable or disable the Access Control function.
123
Document Version: V2.2
A community uses the CPE for wireless networking. Now, only specific members in this community
are allowed to connect to the wireless network.
Solution
The Access Control function of the CPE is recommended. Assume that the users have three Wi-Fi-
enabled devices whose MAC addresses are C8:3A:35:00:00:01, C8:3A:35:00:00:02, and
C8:3A:35:00:00:03.
Configuration procedure
If the Wi-Fi-enabled devices to be controlled are connected to the CPE, click Add online devices to add
them to the access control list quickly.
124
Document Version: V2.2
*
*
----End
Verification
Only Wi-Fi-enabled devices mentioned above can connect to the wireless network of the CPE.
125
Document Version: V2.2
7.4 Management RF
7.4.1 Overview
Management RF (2.4 GHz) is mainly used to facilitate users to connect to the wireless network of
the CPE to manage the CPE under special circumstances. For example, when the CPE is working in
Client mode, you can log in to the web UI of the CPE by connecting to the wireless network of the
CPE's Management RF.
To access the configuration page, log in to the web UI of the CPE and navigate to Wireless >
Management RF.
On this page, you can set the basic information of the CPE's management RF wireless network. It is
recommended to only set the SSID and Encryption, and keep the other default settings.
Parameters description
Name Description
Management RF When you manually enable Management RF's wireless network, it will not disable
automatically. Since the Management RF's Wi-Fi is not protected by password by
default, it is recommended to disable the function when not in use so as to ensure
network security.
Enabled upon Power Specifies whether to enable or disable the Enabled upon Power on function.
on
126
Document Version: V2.2
Name Description
With this function enabled, Management RF's wireless network will be automatically
enabled when the CPE is powered off and on again.
You can use a wireless client to connect the wireless network of the Management RF.
Log in to the web UI of the CPE, you can delay the available time for the wireless
network of the Management RF as required.
Specifies the name of the CPE Management RF's wireless network. You can modify it
SSID
as required.
Specifies the network mode of the CPE Management RF's wireless network. Only
Network Mode
wireless clients supporting the listed network mode can connect to the CPE.
Specifies the operating channel of the CPE management RF's wireless network. When
Channel Auto is selected, the CPE will automatically adjust its operating channel based on the
surrounding environment.
Specifies the security mode of the wireless network of the CPE Management RF. Refer
Encryption
to the Security Mode for details.
Configuration procedure
Step 1 Connect the wireless client to the wireless network of Management RF.
Step 2 Start a browser on your wireless client, visit the CPE's management IP address (By default,
AP mode: 192.168.2.1, Client mode: 192.168.2.2), and log in to the web UI of the CPE.
Step 3 Click Delay in the upper right corner of the page. The following figure is for reference only.
127
Document Version: V2.2
----End
− To delay the available time of the Management RF's wireless network, you must enable the
Management RF function. As long as you delay the available time of wireless network before the
wireless network of the Management RF is automatically disabled, that is, you can normally use
the wireless network of the Management RF.
− Each time you click Delay, the maximum delay time is 5 minutes.
− The total delay time cannot exceed the Duration. For example, if the Duration is 10 minutes, it
means you can only delay to a maximum of 10 minutes.
128
Document Version: V2.2
8 Advanced
This user guide is for configuration reference only and does not indicate that the product supports all
functions described here. Functions available may vary with the product model. Please refer to the
actual product.
When you change the settings, ensure that the LAN speed and duplex mode of the port of the CPE
is the same as that of peer CPE. By default, the LAN speed settings of the LAN port is Auto
Negotiation. OS3V1.0 is used for illustration.
After the LAN speed and duplex mode settings are changed, you can check on the System Status
page.
Parameters description
Name Description
Specifies the speed and duplex mode of the port are determined by the negotiation
Auto Negotiation
between the CPE and peer CPE.
Specifies the port working at 1000 Mbps, and can transmit and receive packets at the
1000Mbps Full Duplex
same time.
129
Document Version: V2.2
Name Description
Specifies the port working at 100 Mbps, and can transmit or receive packets at the
100Mbps Full Duplex
same time.
100Mbps Half Duplex Specifies the port working at 100 Mbps, and can only transmit or receive packets.
Specifies the port working at 10 Mbps, and can transmit and receive packets at the
10Mbps Full Duplex
same time.
10Mbps Half Duplex Specifies the port working at 10 Mbps, and can only transmit or receive packets.
− If you set the speed and duplex mode of the port manually, ensure that the speed and duplex
mode of the peer port are set to Auto Negotiation or the same as this port.
− Lower speed mode can improve the transmission distance of the port. If you want to extend the
PoE power supply distance, you can change the speed to a low speed mode, such as 10 Mbps full-
duplex. And ensure that the speed mode for the peer port is also 10 Mbps Full Duplex or Auto
Negotiation.
130
Document Version: V2.2
8.2 Diagnose
To access the configuration page, log in to the web UI of the CPE and navigate to Advanced >
Diagnose.
You can use the diagnosis tools for troubleshooting.
− Site Survey: Used to check nearby wireless signals.
− Ping: Used to check the network connectivity and connection quality.
− Traceroute: Used to check the network routes.
− Speed Test: Used to check the connection speed between two devices in a same
network.
− Spectrum Analysis: Used to check the nearby wireless noise of each channel, then you
can select a frequency band with less wireless noise for the CPE.
Configuration procedure
The diagnosis result will be displayed in a few seconds in the list below. See the following figure.
131
Document Version: V2.2
8.2.2 Ping
You can use ping to detect the connectivity and quality of network connection.
Assume that you want to know whether the CPE can access Bing.
Configuration procedure
----End
The diagnosis result will be displayed in a few seconds in the list below. See the following figure.
132
Document Version: V2.2
8.2.3 Traceroute
You can use the Traceroute tool to detect the routes that the packets pass by from the CPE to
destination host.
Assume that you want to detect the routes that the packets pass by from the CPE to cn.bing.com.
Configuration procedure
----End
The diagnosis result will be displayed in a few seconds in the list below. See the following figure.
133
Document Version: V2.2
Log in to the web UI of the CPE, navigate to Advanced > Diagnose, and select Speed Test from the
Diagnose drop-down list.
Parameters description
Name Description
134
Document Version: V2.2
Name Description
Client
This version is not supported yet.
Server
Specifies the LAN IP address of the peer CPE. You can enter it manually or select the
IP Address of Peer AP IP address of the peer AP from the drop-down list if there are peer CPEs connected
to the CPE.
If the IP Address of Peer AP is set to Manual, you need to enter the LAN IP address
IP Address
of peer CPE here.
Specifies the HTTP service port number of peer CPE, which is used to establish speed
HTTP Port test connections based on TCP/IP. The default value is 80. You are recommended to
keep the default value.
User Name
Specify the login user name and password of the peer CPE.
Password
Time Specifies the duration of the speed test, which is 30s by default.
Assume that CPE1 working in AP mode and CPE2 working in Client mode have bridged successfully.
Below shows basic information about two CPEs:
Configuration procedure
135
Document Version: V2.2
*
*
*
*
----End
The test result will be displayed in a few seconds in the list below. See the following figure.
136
Document Version: V2.2
----End
The diagnosis result will be displayed in a few seconds in the list below. See the following figure.
Based on the diagnosis result, the CPE can be set to channel 48 for optimal transmission.
137
Document Version: V2.2
138
Document Version: V2.2
----End
The diagnosis result will be displayed in a few seconds in the list below. See the following figure.
Based on the diagnosis result, the CPE can be set to channel 44 for optimal transmission.
139
Document Version: V2.2
----End
The diagnosis result will be displayed in a few seconds in the list below. See the following figure.
Based on the diagnosis result, the CPE can be set to channel 40, 44 or 48 for optimal transmission.
140
Document Version: V2.2
If multiple clients access the internet through the CPE, bandwidth control is recommended, so that
high-speed file downloaded by a client does not reduce the internet access speed of the other
clients.
To access the configuration page, log in to the web UI of the CPE and navigate to Advanced >
Bandwidth Control.
Parameters description
Name Description
Specifies the IP address or IP address range of clients that this rule applies to.
If you want to control only one client, enter the same IP address in the two boxes.
IP Address Range
If you want to control multiple clients, enter an IP address range including start IP
address and end IP address. The end IP address should be greater than the start IP
address.
Status Specifies the current status of the rule. You can enable or disable it as required.
141
Document Version: V2.2
Assume that: The maximum upload rate of each device connected to the wireless network of the
device is 5 Mbps, and download rate is 10 Mbps. And the IP address range of the devices connected
to the wireless network is 192.168.2.100 to 192.168.2.200.
Configuration procedure
Step 1 Log in to the web UI of the CPE.
Step 2 Navigate to Advanced > Bandwidth Control.
Step 3 (Optional) Enter a remark, which is Devices of Office1 in this example.
Step 4 Set IP Address Range, which is 192.168.2.100 ~ 192.168.2.200 in this example.
Step 5 Set the maximum upload and download rates, which are 5 and 10 in this example.
Step 6 Click Add.
----End
142
Document Version: V2.2
Verification
For a client whose IP address is within the range of 192.168.2.100 to 192.168.2.200, its maximum
upload rate is 5 Mbps and its maximum download rate is 10 Mbps.
143
Document Version: V2.2
8.4.1 Overview
If computers are connected to the CPE to form a LAN and access the internet through the CPE,
internet users cannot access the hosts on the LAN. Therefore, the servers, such as web servers,
email servers, and FTP servers, on the LAN are inaccessible to internet users.
To enable internet users to access a LAN server, enable the port forwarding function of the CPE, and
map one service port to the IP address of the LAN server. This enables the CPE to forward the
requests arriving at the port from the internet to the LAN server, and avoid the attacks from the
WAN.
To access the configuration page, log in to the web UI of the CPE and navigate to Advanced > Port
Forwarding.
Parameters description
Name Description
Internal IP Address Specifies the IP address of the host that establishes a server in LAN.
144
Document Version: V2.2
Name Description
Specifies the ports which are enabled for WAN users to visit the corresponding
servers in LAN.
External Port
After you select an Application, this option will be auto populated. You can also
customize it.
Specifies the protocol type of the selected applications. Select TCP&UDP when you
Protocol
are not sure.
Specifies the application services established in LAN. After you select an application,
Application
the internal and external ports will be populated.
Status Specifies the status of the rule. You can enable or disable it according to your need.
Solution
You can use the port forwarding function to enable internet users to access the intranet web server.
Assume that:
− WAN IP Address of theCPE: 202.105.11.22
− IP Address of the web server: 192.168.2.100
− Service port: 9999
− Before configuration, ensure that the WAN port of the CPE obtains a public IP address. If the
WAN port obtains a private IP address or an intranet IP address assigned by the ISP, the function
may not take effect. Common IPv4 addresses can be class A, class B and class C. The private IP
addresses ranges: Class A: 10.0.0.0-10.255.255.255, Class B: 172.16.0.0-172.31.255.255, Class C:
192.168.0.0-192.168.255.255.
− ISPs may not support unreported web service accessed using the default port number 80. When
setting port mapping, you are recommended to set the external port as an uncommon port (1024
to 65535), such as 9999, to ensure normal access.
− Internal and external ports can be different.
145
Document Version: V2.2
Switch
ISP hotspot
Office network
Configuration procedure
----End
146
Document Version: V2.2
Verification
Internet users can successfully access the intranet server by using the Intranet service application
layer protocol name://WAN port IP address. If the intranet service port is not the default port
number, the access address is Intranet service application layer protocol name://WAN port IP
address:External port.
In this example, the access address is http://202.105.11.22:9999.
You can find the current WAN port IP address in System Status.
If DDNS is enabled on the WAN port, internet users can also access the intranet server by using
Intranet service application layer protocol name://WAN port domain name:External port.
If internet users cannot visit the server in LAN after the configuration, try the following solutions:
− Ensure that the WAN IP address of the CPE is a public IP address, and the internal port you
entered is correct.
− Security software, antivirus software, and the built-in OS firewall of the server may cause port
forwarding function failures. Disable them and try again.
− Manually set an IP address and related parameters for the server to avoid the service
disconnection caused by the dynamic IP address.
147
Document Version: V2.2
8.5.1 Overview
The MAC Filter function enables you to restrict access to devices by their MAC addresses at specific
times.
To access the configuration page, log in to the web UI of the CPE and navigate to Advanced > MAC
Filter.
The function is disabled by default. Set the mode to Allow, and the page is shown as below.
Parameters description
Name Description
MAC Address Specifies the MAC address of the client to which the rule applies.
148
Document Version: V2.2
Name Description
Specifies the status of the rule. You can enable or disable the rule according to your
Status
needs.
Requirements: Allow internet access to a purchasing employee from 8:00 to 18:00, Monday to
Friday.
Solution
You are recommended to use the MAC Filter function to solve the problem.
Assume that the MAC addresses of the purchasing employee's computer is CC:3A:61:71:1B:6E.
Configuration procedure
Step 1 Log in to the web UI of the CPE.
Step 2 Navigate to Advanced > MAC Filter.
Step 3 Select a mode, which is Allow in this example.
Step 4 (Optional) Set Remark, which is Purchasing in this example.
Step 5 Set the MAC Address of the device, which is CC:3A:61:71:1B:6E in this example.
Step 6 Specify a period, which is 8:00 to 18:00 in this example.
Step 7 Tick the dates, which are Mon. to Fri. in this example.
Step 8 Click Add.
149
Document Version: V2.2
----End
Verification
Only the computer with the MAC addresses CC:3A:61:71:1B:6E and CC:3A:61:75:1F:3E can access
the internet at 9:00 to 17:00 from Monday to Friday. Other computers are blocked during this
period.
150
Document Version: V2.2
DDNS, dynamic domain name server, enables the dynamic DNS client on the CPE to deliver the
current WAN IP address to the DNS server. Then the server maps the WAN IP address to a domain
name for dynamic domain name resolution.
On this page, you can map the dynamic WAN IP address of the CPE (public IP address) to a fixed
domain name. The DDNS function is generally used with such functions as port forwarding and DMZ
host to enable internet users to access the LAN server or the web UI of the CPE through a domain
name without caring about the change of the WAN IP address.
To access the configuration page, log in to the web UI of the CPE and navigate to Advanced >
Network Service.
Parameters description
Name Description
User Name Specify the user name or password used to log in to the dynamic DNS service, which
are the login user name and password you registered on the website of the service
Password provider.
Specifies the domain name information obtained from the dynamic DNS server. You
Domain Name
need to enter the domain name which you registered on the website manually.
151
Document Version: V2.2
Networking requirements
An enterprise uses the CPE to set up a network. The CPE is in WISP mode and has connected to the
internet.
Requirement: The intranet web server is open to internet users to enable staff to access the
intranet even when they are outside the enterprise.
Solution
− You can use the Port Forwarding function to enable internet users to access the
intranet web server.
− You can use the DDNS function to enable internet users to access the intranet web
server through a fixed domain name, avoiding access failures caused by WAN IP
address change.
Assume that:
− Password: JohnDoe
− Before configuration, ensure that the WAN port of the CPE obtains a public IP address. If the
WAN port obtains a private IP address or an intranet IP address assigned by the ISP, the function
may not take effect. Common IPv4 addresses can be class A, class B and class C. The private IP
addresses ranges: Class A: 10.0.0.0-10.255.255.255, Class B: 172.16.0.0-172.31.255.255, Class C:
192.168.0.0-192.168.255.255.
− ISPs may not support unreported web service accessed using the default port number 80.
Therefore, when setting port mapping, you are recommended to set the external port as an
uncommon port (1024 to 65535), such as 9999, to ensure normal access.
− Internal and external ports can be different.
152
Document Version: V2.2
Switch
ISP
ISPhotspot
Hotspot
Office network
Configuration procedure
153
Document Version: V2.2
3. Set Internal Port and External Port, which are 9999 in this example.
4. Set Protocol, which is TCP&UDP in this example
5. Set Application, which is HTTP in this example.
6. Click Add.
----End
Verification
Internet users can successfully access the intranet server by using the Intranet service application
layer protocol name://WAN port IP address. If the intranet service port is not the default port
number, the access address is Intranet service application layer protocol name://WAN port IP
address:External port.
If internet users cannot visit the server in LAN after the configuration, try the following solutions:
− Ensure that the WAN IP address of the CPE is a public IP address, and the internal port you
entered is correct.
− Security software, antivirus software, and the built-in OS firewall of the server may cause port
forwarding function failures. Disable them and try again.
− Manually set an IP address and related parameters for the server to avoid the service
disconnection caused by the dynamic IP address.
154
Document Version: V2.2
Generally, you can log in to the web UI of the CPE only when you connect to the LAN port or the
wireless network of the CPE. However, this function enables access to the web UI remotely through
the WAN port in special cases (like when you need remote technical support).
You can access the CPE remotely by visiting an address in the form of http://WAN port IP
address:Port number. If the DDNS function is enabled on the CPE, you can access the CPE by
visiting an address in the form of http://Domain name of WAN port:Port number.
To access the configuration page, log in to the web UI of the CPE and navigate to Advanced >
Network Service.
This function is disabled by default. After it is enabled, the page is shown as follows.
Parameters description
Name Description
Remote Web Specifies whether to enable or disable the remote web management function.
Management
Specifies the IP address of the computer which is allowed to access the web UI of the
CPE.
− All: Indicates that any computer in WAN can manage the CPE remotely. For
IP Address security, this option is not recommended.
− Manual: Indicates that only the specified computer can manage the CPE
remotely. If the CPE belongs to a LAN, the gateway address (a public IP
address) of the computer should be entered.
Specifies the port number used for remote management of CPE. Default: 8080. You
can modify it as required.
Port
Ports 1 to 1024 have been used by known services. To avoid port conflicts, you can
set the port number to one between 1025 and 65535.
155
Document Version: V2.2
An enterprise uses the CPE to set up a network. The CPE is in WISP mode and has connected to the
internet. The network administrator encountered a problem during network setup and needs the
Tenda technical support to remotely log in to the web UI of the CPE to perform analysis and
troubleshooting.
Solution
You can use the remote web management function to solve the problem.
Assume that:
− WAN IP address of the CPE: 202.105.106.55
− IP address of the computer allowed to access the CPE: 202.105.88.77
− Port number: 8080
Configuration procedure
----End
Verification
The host can log in to the web UI of the CPE by visiting http://202.105.106.55:8080 on the
computer (the IP address of the computer is 202.105.88.77). If the DDNS function is enabled on the
CPE, you can access the CPE by visiting an address in the form of http://Domain name of WAN
port:8080.
156
Document Version: V2.2
This function enables the CPE to automatically reboot as scheduled. You can use this function to
prevent wireless performance degradation or network instability due to long-time running.
Configuration procedure
Step 1 Log in to the web UI of the CPE.
Step 2 Navigate to Advanced > Network Service.
Step 3 Enable the Reboot Schedule function.
Step 4 Set Time at which the CPE reboots, which is 3:00 in this example.
Step 5 Set Date on which the CPE reboots, which is Every Day in this example.
Step 6 Click Save.
----End
After the CPE is successfully configured, it will automatically reboot at 3 a.m. every day.
To access the configuration page, log in to the web UI of the CPE and navigate to Advanced >
Network Service.
157
Document Version: V2.2
SNMP allows automatic management of devices from various vendors regardless of physical
differences among the devices.
SNMP management framework
The SNMP management framework consists of SNMP manager, SNMP agent, and Management
Information Base (MIB).
− SNMP manager: It is a system that controls and monitors network nodes using the SNMP
protocol. The SNMP manager most widely used in network environments is Network
Management System (NMS). An NMS can be a dedicated network management server, or
an application that implements management functions in a network device.
− SNMP agent: It is a software module in a managed device. The module is used to manage
data about the device and report the management data to an SNMP manager.
An SNMP manager manages SNMP agents in an SNMP network. The SNMP manager exchanges
management information with the SNMP agents using the SNMP protocol.
Basic SNMP operations
− Get: An SNMP manager performs this operation to query the SNMP agent of the device for
values of one or more objects.
− Set: An SNMP manager performs this operation to set values of one or more objects in the
MIB of the SNMP agent of the device.
SNMP protocol version
The CPE is compatible with SNMP V1 and SNMP V2C and adopts the community authentication
mechanism. Community name is used to define the relationship between an SNMP agent and an
SNMP manager. If the community name contained in an SNMP packet is rejected by a device, the
packet is discarded. A community name functions as a password to control SNMP agent access
attempts of SNMP managers.
158
Document Version: V2.2
SNMP V2C is compatible with SNMP V1 and provides more functions than SNMP V1. Compared
with SNMP V1, SNMP V2C supports more operations (GetBulk and InformRequest) and data types
(such as Counter64), and provides more error codes for better distinguishing errors.
MIB introduction
An MIB adopts a tree structure. The nodes of the tree indicate managed objects. A path consisting
of digits and starting from the root can be used to uniquely identify a node. This path is calling an
object identifier (OID). The following figure shows the structure of an MIB. In the figure, the OID of
A is 1.3.6.1.2.1.1, whereas the OID of B is 1.3.6.1.2.1.2.
To access the configuration page, log in to the web UI of the CPE and navigate to Advanced >
Network Service.
159
Document Version: V2.2
Parameter description
Name Description
Specifies whether to enable or disable the SNMP agent function of the CPE. By
default, it is disabled.
SNMP Agent An SNMP manager and the SNMP agent can communicate with each other only if
their SNMP versions are the same. Currently, the SNMP agent function of the CPE
supports SNMP V1 and SNMP V2C.
Specifies the device name of the CPE. The default device name is assigned based
on the model and version number of the CPE.
Device Name
It is recommended that you change the device name so that you can easily
identify the target CPE when managing it using SNMP.
Specifies the read password shared between SNMP managers and this SNMP
agent. The default password is public.
Read Community
The SNMP agent function allows an SNMP manager to use the Read Community
to read variables in the MIB of the CPE.
Specifies the read/write password shared between SNMP managers and this
SNMP agent. The default password is private.
Read/Write Community
The SNMP agent function allows an SNMP manager to use the Read/Write
Community to read/write variables in the MIB of the CPE.
Specifies the location where the CPE is used. You can change the location as
Location required.
160
Document Version: V2.2
Networking requirements
− The CPE connects to an NMS over a LAN. The IP address of the CPE is 192.168.2.1/24 and
the IP address of the NMS is 192.168.2.212/24.
− The NMS uses SNMP V1 or SNMP V2C to monitor and manage the CPE.
− Assume that Read Community is Jack, and Read/Write Community is Jack123.
PoE injector
PoE
NMS: 192.168.2.212/24
CPE: 192.168.2.1/24
Configuration procedure
*
*
*
*
*
*
161
Document Version: V2.2
On an NMS that uses SNMP V1 or SNMP V2C, set the read community to Jack and
read/write community to Jack123. For details about how to configure the NMS, refer to the
user guide for the NMS.
----End
Verification
After the configuration is successful, the NMS can connect to the SNMP agent of the CPE and can
query and set some parameters on the SNMP agent through the MIB.
With this function enabled, the CPE periodically pings a target IP address to check the network
connectivity and identify whether the device malfunctions. If it malfunctions, the CPE will reboot
automatically to ensure the network performance.
Configuration procedure
----End
Parameters description
Name Description
Ping Watch Dog Specifies whether to enable or disable the Ping Watch Dog function.
162
Document Version: V2.2
Name Description
Specifies the interval at which the CPE transmits packets to ping the target IP
Ping Interval
address. The default value is 300s.
Specifies the delay time for the CPE to enable the Ping Watch Dog function after the
CPE startup completes. The default value is 300s.
Ping Startup Delay Setting a proper Ping startup delay time can stop the Ping Watch Dog function from
being triggered during the startup of the CPE. Such triggering leads to failure of
accessing the web UI to modify the settings, causing the CPE to start up
continuously.
Specifies the threshold of lost packet that triggers reboot. The value range is 1 to
Threshold of Lost 65535. The default value is 3.
Packets For example, if 5 is set, the CPE will reboot automatically when it does not receive
response after sending 5 Ping packets to the target IP address or domain name.
The DMZ function is available only when the CPE works in WISP or Router mode.
After a device in the LAN is set as the DMZ host, the device enjoys no limitations when
communicating with the internet. For example, if video meeting or online games are underway on a
computer, you can set that computer as the DMZ host to make the video meeting and online games
go smoother.
− After you set a LAN device as a DMZ host, the device will be completely exposed to the internet
and the firewall of the controller does not take effect on the CPE.
− Hackers may attack on the local network by using the DMZ host. Exercise caution to use the DMZ
function.
− The security guard, anti-virus software and system firewall on the DMZ host may affect the DMZ
function. Disable them when using this function. When you are not using the DMZ function, you
are recommended to disable the function and enable the firewall, security guard and anti-virus
software on the DMZ host.
To access the configuration page, log in to the web UI of the CPE and navigate to Advanced >
Network Service.
163
Document Version: V2.2
Parameters description
Name Description
Specifies whether to enable the DMZ host function of the CPE. By default, it is
DMZ Host
disabled.
DMZ Host IP Address Specifies the IP address of the LAN device to be set to DMZ host.
Networking requirements
An enterprise uses the CPE to set up a network. The CPE is in WISP mode and has connected to the
internet.
The intranet web server is open to internet users to enable staff to access the intranet even when
they are outside the enterprise.
Solution
Assume that:
− WAN IP address of the CPE: 202.105.106.55
− Before the configuration, ensure that the WAN port of the CPE obtains a public IP address. If the
WAN port obtains a private IP address or an intranet IP address assigned by the ISP, the function
may not take effect. Common IPv4 addresses can be class A, class B and class C. The private IP
addresses ranges: Class A: 10.0.0.0-10.255.255.255, Class B: 172.16.0.0-172.31.255.255, Class C:
192.168.0.0-192.168.255.255.
− ISPs may not support unreported web service accessed using the default port number 80.
Therefore, when setting the DMZ host, you are recommended to set the internal port as an
uncommon port (1024 to 65535), such as 9999, to ensure normal access.
164
Document Version: V2.2
Switch
ISP hotspot
Configuration procedure
----End
Verification
Internet users can successfully access the intranet server by using the Intranet service application
layer protocol name://WAN port IP address. If the intranet service port is not the default port
number, the access address is Intranet service application layer protocol name://WAN port IP
address:Intranet service port.
You can find the current WAN port IP address in System status.
If DDNS is enabled on the WAN port, internet users can also access the intranet server by using
Intranet service application layer protocol name://WAN port domain name: Intranet service port.
165
Document Version: V2.2
If internet users cannot visit the server in LAN after the configuration, try the following solutions:
− Ensure that the WAN IP address of the CPE is a public IP address.
− Security software, antivirus software, and the built-in OS firewall of the server may cause the
function failures. Disable them and try again.
− Manually set an IP address and related parameters for the server to avoid the service
disconnection caused by the dynamic IP address.
To access the configuration page, log in to the web UI of the CPE and navigate to Advanced >
Network Service.
8.6.9 UPnP
Universal Plug and Play (UPnP) is a set of networking protocols that makes automatic port
forwarding possible. It can identify devices and enable ports for certain applications, such as
BitComet. To use this function, it requires that the operating system support UPnP, or application
software supporting UPnP is installed.
To access the configuration page, log in to the web UI of the CPE and navigate to Advanced >
Network Service.
To access the configuration page, log in to the web UI of the CPE and navigate to Advanced >
Network Service.
166
Document Version: V2.2
8.6.11 STP
Spanning Tree Protocol (STP) is a network protocol standardized by IEEE 802.1d. It helps establish a
loop-free logical topology for Ethernet network, and allows a network design to include backup
links to provide fault tolerance if an active link fails. The STP-enabled device creates a spanning tree
within a network of connected layer-2 bridges, and disables those links that are not part of the
spanning tree, leaving a single active path between any two network nodes. So that it prevents
packets from continued proliferation and endless loop in a loop network to avoid reducing the
capability of processing packets caused by receiving duplicate packets.
To access the configuration page, log in to the web UI of the CPE and navigate to Advanced >
Network Service.
167
Document Version: V2.2
9 Tools
This user guide is for configuration reference only and does not indicate that the product supports all
functions described here. Functions available may vary with the product model. Please refer to the
actual product.
This module enables you to set the system time of the CPE. The system time of the CPE can be
synchronized with the internet or manually configured. By default, it is configured to synchronize
the system time with the internet.
− When you log in to the web UI of the CPE, the system time will be synchronized with the
management host automatically no matter which time setting method you choose.
− Ensure that the system time of the CPE is correct, so that logs can be recorded correctly and the
reboot schedule can be executed correctly.
After the configuration is successful, you can navigate to Status page to check whether the system
time of the CPE is correct. The following figure is for reference only.
168
Document Version: V2.2
Parameters description
Name Description
Time Settings Specifies the method to set the system time of the CPE.
Specifies the interval to synchronize the system time of the CPE with the time
Time Interval
server on the internet.
Time Zone Specifies the standard time zone where the CPE is located.
9.1.2 Manual
You can manually set the system time of the CPE. If you choose this option, you need to set the
system time each time after the CPE reboots.
After the configuration is successful, you can navigate to Status page to check whether the system
time of the CPE is correct. The following figure is for reference only.
Parameters description
Name Description
Time Settings Specifies the method to set the system time of the CPE.
You can either enter the accurate time in this field, or click Synchronize with PC
Date & Time
Time to synchronize the system time of the CPE with the management computer.
169
Document Version: V2.2
9.2 Maintenance
9.2.1 Reboot device
When the CPE reboots, the current connections will be disconnected. Perform this operation when the
CPE is idle.
Configuration procedure
----End
170
Document Version: V2.2
− When the factory settings are restored, all settings on the CPE are removed. Operate only when
necessary.
− To prevent damage to the CPE, do not power off the CPE during the factory reset.
----End
171
Document Version: V2.2
Configuration procedure
Step 1 Download the firmware file for the CPE from www.tendacn.com to your local computer,
and unzip it.
Step 2 Log in to the web UI of CPE, and navigate to Tools > Maintenance.
Step 3 Click Upgrade.
Step 4 Select the correct upgrade file (extension: bin) from your local computer and the system
will upgrade automatically.
----End
Wait for the progress bar to complete. Then log in to the web UI of the CPE. On the Status page,
check if the current Firmware Version is consistent with the firmware version you selected for
upgrade.
To better experience the stability and value-added functions of the higher firmware version, you are
recommended to restore the CPE to factory settings and configure it again after the upgrade.
172
Document Version: V2.2
9.2.4 Backup/restore
The Backup function can save the current configuration of the CPE to your computer. The Restore
function can restore the CPE configuration from the previous backup.
When you have made a lot of configurations to the CPE for better operation performance or to
better meet the environment requirements, it is recommended to back up the configuration. When
you have upgraded and factory reset the CPE, you can restore the previous configuration.
To apply the same configuration to multiple CPEs with minimal effort, configure one CPE, back up its
configuration, and import the backup file to the rest.
Backup
Step 1 Log in to the web UI of CPE.
Step 2 Navigate to Tools > Maintenance.
Step 3 Click Backup/Restore.
173
Document Version: V2.2
Restore
Step 1 Log in to the web UI of CPE.
Step 2 Navigate to Tools > Maintenance.
Step 3 Click Backup/Restore.
Step 5 Select and upload the file you back up before (extension: .cfg).
----End
Wait for the progress bar to complete. The CPE is restored to the previous settings successfully.
174
Document Version: V2.2
9.3 Account
To access the configuration page, log in to the web UI of the CPE and navigate to Tools > Account.
On this page, you can change the login account information of the CPE to prevent unauthorized
login. By default, the CPE has one administrator account and one guest account. With the
administrator account, you can modify and view the settings of the CPE while with the guest
account, you can only view the settings.
Click to change the account information.
9.3.1 Administrator
You can modify and view the settings with the administrator account. Both the default user name
and password of the administrator account are admin.
For network security, it is recommended to modify your login password regularly. A password of high
security is preferred, such as a combination of lower-case letters, capital letters and numbers.
175
Document Version: V2.2
Parameters description
Name Description
Old User Name Specifies the user name and password of the current login account.
By default, the CPE has one administrator account and one guest account.
9.3.2 Guest
Guest account only allows you to view the settings. By default, this account is disabled. Both the
default user name and password are user.
176
Document Version: V2.2
The logs of the CPE record various events that occur and the operations that users perform after the
CPE starts. In case of a system fault, you can refer to the logs during troubleshooting.
To view the latest logs of the CPE, click Refresh. To clear the existing logs, click Clear.
To ensure that the logs are recorded correctly, verify the system time of the CPE. You can correct the
system time of the CPE on the Date & Time page.
177
Document Version: V2.2
Appendix
A.1 Default parameters
The main default parameters are shown in the following table.
Single 192.168.2.1
Login IP
Address AP mode: 192.168.2.1
Kit
Client mode: 192.168.2.2
Login
User name admin
Administrator
Password admin
Guest Disable
Single AP mode
Quick Setup Working Mode
Kit AP mode or Client mode
Single 192.168.2.1
Single Enable
DHCP Server
Kit Disable
178
Document Version: V2.2
PVID 1
VLAN Settings
Management VLAN 1
WLAN 1000
Wireless
The management RF is not available for some CPEs.
TD-MAX Disable
TPC Enable
STP Disable
179
Document Version: V2.2
AP Access Point
IP Internet Protocol
180
Document Version: V2.2
P2MP Point-to-Multi-Point
RF Radio Frequency
RX Receive
TX Transmit
UI User Interface
181
Document Version: V2.2
182
Document Version: V2.2
183
Document Version: V2.2
Step 5 Select Use the following IP address, set the IP address to 192.168.2.X (X ranges from 2 to
253), the Subnet mask to 255.255.255.0, and click OK.
Step 6 Click OK on the Local Area Connection Properties window, and close the other windows.
----End
184
Document Version: V2.2
1
2
----End
185
Document Version: V2.2
Then you can check the default gateway address on the following page.
186