Omada OC200 - Controller TP-LINK - Free user manual and instructions

Find the device manual for free Omada OC200 TP-LINK in PDF.

TP-LINK Omada OC200 - Controller
📄 401 pages English EN Download 💬 AI Question 10 questions ⚙️ Specs
Notice TP-LINK Omada OC200 - page 8
Pick your language and provide your email: we'll send you a specifically translated version.
Product Type Hardware Controller for Omada SDN
Dimensions (W x D x H) 158 x 101 x 25 mm (6.2 x 4.0 x 1.0 in)
Weight 0.2 kg (0.44 lb)
Power Supply 9V DC 0.6A or PoE (802.3af/at)
Power Consumption ≤ 5 W
Ethernet Ports 1x 10/100/1000 Mbps RJ45
USB Port 1x USB 2.0 (for backup/restore)
Maximum Managed Devices Up to 100 (APs, switches, gateways)
Management Features Centralized cloud and local management, VLAN, QoS, Captive Portal, Mesh
Mounting Desktop or wall-mountable (kit included)
Operating Temperature 0°C to 40°C (32°F to 104°F)
Storage Temperature -40°C to 70°C (-40°F to 158°F)
Operating Humidity 10% to 90% RH (non-condensing)
Certifications CE, FCC, RoHS
Package Contents OC200 Controller, Power Adapter, RJ45 Cable, Mounting Kit, Quick Installation Guide
Maintenance Clean with dry cloth, avoid liquids, ensure ventilation
Safety Use only supplied power adapter, avoid water, unplug during storms
Spare Parts & Repairability Power adapter available separately; no user-serviceable parts inside
Warranty 3 years limited (check local terms)

Frequently Asked Questions - Omada OC200 TP-LINK

How do I set up the Omada OC200 for the first time?
Connect the OC200 to your network via Ethernet, power it on (using the provided adapter or PoE), then access the Omada Controller interface via web browser at https://. Follow the Quick Setup Wizard to configure network topology and adopt devices.
How many devices can the OC200 manage?
The OC200 can manage up to 100 devices, including Omada access points, switches, and gateways. For larger deployments, consider the OC300 or software controller.
Does the OC200 support PoE power?
Yes, the OC200 supports PoE (802.3af/at) on its Ethernet port. Alternatively, it can be powered via the included 9V DC adapter.
Can I access the controller remotely?
Yes, with the Omada Cloud service, you can remotely monitor and manage your network from anywhere. Cloud access requires an Omada account and internet connectivity.
What is the default IP address of the OC200?
The default IP is 192.168.0.1 if connected to a network with DHCP; otherwise, you can use the Omada Discovery Utility to find the device on the network.
How do I reset the OC200 to factory defaults?
Press and hold the Reset button (located on the back) for about 5 seconds using a paperclip until the LED starts flashing. Release to reset to factory settings.
Is the OC200 compatible with third-party devices?
No, the OC200 is designed to manage only Omada-compatible devices (APs, switches, gateways) from TP-Link. It does not support third-party equipment.
Can I use multiple OC200 controllers in one network?
It is possible by configuring separate controller clusters, but for most environments a single controller is sufficient. Multiple controllers require careful configuration to avoid conflicts.
How do I update the firmware on the OC200?
Log into the Omada Controller interface, go to Maintenance > Firmware Upgrade, and check for updates. If available, follow the on-screen prompts. Alternatively, download the firmware from TP-Link's website and upload it manually.
What should I do if I forget the login password?
Perform a factory reset by pressing the Reset button for 5 seconds. After reset, use default credentials (admin/admin) to log in and reconfigure the controller.

User questions about Omada OC200 TP-LINK

0 question about this device. Answer the ones you know or ask your own.

Ask a new question about this device

Your email remains private: it is only used to notify you if someone answers your question.

No questions yet. Be the first to ask one.

Download the instructions for your Controller in PDF format for free! Find your manual Omada OC200 - TP-LINK and take your electronic device back in hand. On this page are published all the documents necessary for the use of your device. Omada OC200 by TP-LINK.

USER MANUAL Omada OC200 TP-LINK

This User Guide provides information for centrally managing TP-Link devices via Omada SDN Controller. Please read this guide carefully before operation.

Intended Readers

This User Guide is intended for network managers familiar with IT concepts and network terminologies.

Conventions

When using this guide, notice that:

■ Features available in Omada SDN Controller may vary due to your region, controller version, and device model. All images, steps, and descriptions in this guide are only examples and may not reflect your actual experience. ■ The information in this document is subject to change without notice. Every effort has been made in the preparation of this document to ensure accuracy of the contents, but all statements, information, and recommendations in this document do not constitute the warranty of any kind, express or implied. Users must take full responsibility for their application of any products. This guide uses the specific formats to highlight special messages. The following table lists the notice icons that are used throughout this guide.

TP-LINK Omada OC200 - Conventions - 1

Note

Remind to take notice. The note contains the helpful information for a better use of the controller.

TP-LINK Omada OC200 - Conventions - 2

Configuration Guidelines

Provide tips for you to learn about the feature and its configurations.

More Information

■ For technical support, the latest version of the User Guide and other information, please visit https://www.tp-link.com/support. ■ To ask questions, find answers, and communicate with TP-Link users or engineers, please visit https://community.tp-link.com to join TP-Link Community.

CONTENTS

About this Guide

Omada SDN Controller Solution Overview

Overview of Omada SDN Controller Solution....2

Core Components....3

Get Started with Omada SDN Controller

Set Up Your Software Controller 8

Determine the Network Topology....8

Install Omada Software Controller 9

Start and Log In to the Omada Software Controller 11

Set Up Your Hardware Controller 17

Determine the Network Topology....17

Deploy Omada Hardware Controller....17

Start and Log in to the Controller 18

Set Up Your Cloud-Based Controller (Coming Soon) 23

Manage Omada Managed Devices and Sites

Create Sites 25

Adopt Devices....29

For Omada Software Controller / Omada Hardware Controller 29

For Omada Cloud-Based Controller (Coming Soon)....41

Configure the Network with Omada SDN Controller

Navigate the UI....45

Modify the Current Site Configuration....48

Site Configuration 48

Services 49

Advanced Features 51

Device Account 54

Configure Wired Networks....55

Set Up an Internet Connection 55

Configure LAN Networks....75

Configure Wireless Networks 87

Set Up Basic Wireless Networks 87

Advanced Settings 93

WLAN Schedule 95

802.11 Rate Control....95

MAC Filter 96

Network Security 98

ACL 98

URL Filtering....106

Attack Defense 109

Firewall 113

Transmission....116

Routing 116

NAT 119

Session Limit....123

Bandwidth Control 124

Configure VPN 127

VPN 127

VPN User 151

Create Profiles....154

Time Range 154

Groups 156

Rate Limit 159

Authentication....161

Portal 161

802.1X....195

MAC-Based Authentication....198

RADIUS Profile....200

Services....203

Dynamic DNS....203

SNMP 205

UPnP 206

SSH....207

Reboot Schedule 207

PoE Schedule 208

Export Data 209

Configure the Omada SDN Controller

Manage the Controller 212

General Settings....212

Mail Server 214

History Data Retention 215

Customer Experience Improvement Program....216

HTTPS Certificate 216

Access Config....217

Manage Your Controller Remotely via Cloud Access....219

Maintenance 221

Configure and Monitor Omada Managed Devices

Introduction to the Devices Page....239

Configure and Monitor the Gateway....243

Configure the Gateway....243

Monitor the Gateway 247

Configure and Monitor Switches....251

Configure Switches....251

Monitor Switches 274

Configure and Monitor EAPs 279

Configure EAPs....279

Monitor EAPs 289

Monitor and Manage the Clients

Manage Wired and Wireless Clients in Clients Page....302

Introduction to Clients Page 302

Using the Clients Table to Monitor and Manage the Clients 302

Using the Properties Window to Monitor and Manage the Clients 304

Manage Client Authentication in Hotspot Manager 309

Authorized Clients 309

Vouchers....309

Local Users 313

Operators 317

Monitor the Network

View the Status of Network with Dashboard....320

Page Layout of Dashboard 320

Explanation of Widgets....322

View the Statistics of the Network....335

Performance....335

Switch Statistics 338

Speed Test Statistics....340

Monitor the Network with Map....342

Topology 342

Map 344

View the Statistics During Specified Period with Insight....347

Known Clients 347

Past Connections....348

Past Portal Authorizations 349

Switch Status 350

Port Forwarding Status 354

VPN Status 355

Routing Table 357

Dynamic DNS....359

Rogue APs 359

View and Manage Logs....362

Alerts 363

Events 364

Notifications....365

Manage Administrator Accounts of Omada SDN Controller

Introduction to User Accounts 372

Manage and Create Local User Accounts ....373

Edit the Master Administrator Account 373

Create and Manage Administrator and Viewer 375

Manage and Create Cloud User Accounts 378

Set Up the Cloud Master Administrator....378

Create and Manage Cloud Administrator and Cloud Viewer 378

Appendix 1: Omada APP

Install Omada App on the Mobile Device....382

Manage Your Network in Standalone Mode 382

Manage Your Network in Controller Mode 385

Locally Manage Your Devices Using the Omada App 385

Remotely Manage Your Devices Using the Omada App 388

1

Omada SDN Controller Solution Overview

Omada SDN Controller Solution offers centralized and efficient management for configuring enterprise networks comprised of security gateways, switches, and wireless access points.

With a reliable network management platform powered by TP-Link Omada SDN Controller, you can develop comprehensive, software-defined networking across demanding, high-traffic environments with robust wired and wireless solutions.

The chapter includes the following sections:

• 1.1 Overview of Omada SDN Controller Solution • 1.2 Core Components

1.1 Overview of Omada SDN Controller Solution

Omada SDN Controller Solution is designed to provide business-class networking solutions for demanding, high-traffic environments such as campuses, hotels, malls, and offices. Omada SDN Controller Solution simplifies deploying and managing large-scale enterprise networks and offers easy maintenance, ongoing monitoring, and flexible scalability.

This figure shows a sample architecture of an Omada SDN enterprise network:

graph TD A["Omada SDN Controller"] --> B["Site A"] A --> C["Site B"] A --> D["Site C"] A --> E["Site D"] A --> F["Site E"] B --> G["AP"] B --> H["AP"] C --> I["Router"] C --> J["Switch"] D --> K["AP"] D --> L["AP"] E --> M["Router"] E --> N["Switch"] F --> O["AP"] F --> P["AP"] F --> Q["AP"] style A…

The interconnected elements that work together to deliver a unified enterprise network include: Omada SDN Controller, gateways, switches, access points, and client devices. Beginning with a base of client devices, each element adds functionality and complexity as the network is developing, interconnecting with the elements above and below it to create a comprehensive, secure wired and wireless solution.

Omada SDN Controller is a command center and management platform at the heart of the Omada network. With a single platform, the network administrators configure and manage enterprise networks comprised of routers, switches, and wireless access points in batches. This unleashes new levels of management to avoid complex and costly overprovisioning.

1.2 Core Components

An Omada SDN network consists of the following core components:

  • Omada SDN Controller—a command center and management platform at the heart of Omada network solution for the enterprise. With a single platform, the network administrators configure and manage all Omada products which have all your needs covered in terms of routing, switching and Wi-Fi. ■ Gateways—boast excellent data processing capabilities and an array of powerful functions, including IPsec/OpenVPN/PPTP/L2TP VPN, Load Balance, and Bandwidth Control, which are ideal for the business network where a large number of users require a stable, secure connection. ■ Switches—offer flexible and cost-effective network solution with powerful Layer 2 features and PoE options. Advanced features such as Access Control, QoS, LAG and Spanning Tree will satisfy advanced business networks. ■ Access Points (Omada EAPs)—satisfy the mainstream Wi-Fi Standard and address your high-density access needs with TP-Link's innovation to help you build the versatile and reliable wireless network for all business applications.

Omada SDN Controller

Tailored to different needs and budgets, Omada SDN Controller offers diverse deployment solutions. Omada Software Controller, Omada Hardware Controller, and Omada Cloud-Based Controller, each have their own set of advantages and applications.

■ Omada Software Controller

Omada Software Controller is totally free, as well as all upgrades. The controller can be hosted on any computers with Windows or Linux systems on your network.

graph TD A["Internet"] --> B["SafeStream Gateway"] B --> C["JetStream Switch"] C --> D["Omada Software Controller"] D --> E["Omada Access Points"] C --> F["Network Link"]

■ Omada Hardware Controller

Omada Hardware Controller is the management device which is pre-installed with Omada Software Controller. You just need to pay for the device, then the built-in Omada Controller software is free to use, no license fee or extra cost required. About the size of a mobile phone, the device is easy to deploy and install on your network.

graph TD A["Omada Hardware Controller"] --> B["JetStream Switch"] C["Internet"] --> D["SafeStream Gateway"] D --> B B --> E["Omada Access Points"]

■ Omada Cloud-Based Controller

Omada Cloud controller is deployed on the Omada Cloud server, providing paid license service with tiered pricing. With paid licenses bound to the devices on the controller, you can configure and manage the devices via Omada Cloud Service. And you need not purchase an additional hardware device or install the software on the host.

graph TD A["Omada Cloud Server"] --> B["Internet"] C["Omada Cloud Controller"] --> B D["SafeStream Gateway"] --> E["SafeStream Gateway"] F["JetStream Switch"] --> G["JetStream Gateway"] H["Omada Access Points"] --> I["Omada Cloud Controller"] J["Omada Cloud Controller"] --> K["Omada Cloud Server"]

The controllers differ in forms, but they have almost the same browser-based management interface and serve the same functions of network management. In this guide, Omada Software Controller, Omada Hardware Controller, and Omada Cloud-Based Controller are referred to as the controller, unless we mention otherwise.

Omada Managed Gateways

TP-Link's Omada Router supports Gigabit Ethernet connections on both WAN and LAN ports which keep the data moving at top speed. Including all the routing and network segmentation functions that a business router must have, SafeStream VPN Router will be the backbone of the Omada SDN network. Moreover, the router provides a both secure and easy approach to deploy site-to-site VPN tunnels and access for remote clients.

Managing the gateway centrally through Omada SDN Controller is available on certain models only. Please check the Omada Cloud SDN Platform Compatibility List for more information.

Omada Managed Switches

TP-Link's JetStream Switch provides high-performance and enterprise-level security strategies and a number of advanced features, which is ideal access-edge for the Omada SDN network.

Managing the switch centrally through Omada SDN Controller is available on certain models only. Please check the Omada Cloud SDN Platform Compatibility List for more information.

Omada Access Points

TP-Link's Omada Access Point provides business-class Wi-Fi with superior performance and range, guaranteeing reliable wireless connectivity for the Omada SDN network.

Managing the access points centrally through Omada SDN Controller is available on certain models only. Please check the Omada Cloud SDN Platform Compatibility List for more information.

2

Get Started with Omada SDN Controller

This chapter guides you on how to get started with Omada SDN Controller to configure the network. Omada Software Controller, Omada Hardware Controller, and Omada Cloud-Based Controller differ in form, but they have almost the same browser-based management interface for network management. Therefore, they have almost the same initial setup steps, including building your network topology, deploying your controller, and logging in to the controller. The chapter includes the following sections:

• 2.1 Set Up Your Software Controller • 2.2 Set Up Your Hardware Controller • 2.3 Set Up Your Cloud-Based Controller (Coming Soon)

2.1 Set Up Your Software Controller

Omada SDN Controller Solution is designed for scalable networks. Deployments and configurations vary according to actual situations. Understanding your network requirements is the first step when planning to provision any project. After you have identified these requirements, follow the steps below to initially set up Omada Software Controller:

1) Determine the network topology. 2) Install Omada Software Controller. 3) Start and log in to the controller.

2.1.1 Determine the Network Topology

The network topology that you create for Omada SDN Controller varies depending on your business requirements. The following figure shows a typical topology for a high-availability use case.

graph TD A["Internet"] --> B["SafeStream Gateway"] B --> C["JetStream Switch"] C --> D["Client 1: Cloud Server"] C --> E["Client 2: Wireless"] C --> F["Client 3: Wireless"] C --> G["Client 4: Wireless"] C --> H["Client 5: Wireless"] C --> I["Client 6: Wireless"]

Omada Access Points Omada Software Controller

① Note:

When using Omada SDN Controller, we recommend that you deploy the full Omada topology with supported TP-Link devices. If you use third-party devices, Omada SDN Controller cannot discover and manage them.

2.1.2 Install Omada Software Controller

Omada Software Controller is provided for both Windows and Linux operating systems. Determine your operating system and follow the introductions below to install Omada Software Controller.

Installation on Windows Host

Omada Software Controller can be hosted on any computers with Windows systems on your network. Make sure your PC's hardware and system meet the following requirements, then properly install the Omada Software Controller.

■ Hardware Requirements

Omada Software Controller can manage up to 1500 EAPs if the Controller Host has enough hardware resources. To guarantee operational stability for managing 1500 EAPs, we recommend that you use the hardware which meets or exceeds the following specifications:

CPU: Intel Core i3-8100, i5-6500, or i7-4700 with 2 or more cores and 4 or more threads.

Memory: 6 GB RAM or more.

■ System Requirements

Operating System: Microsoft Windows 7/8/10/Server. (We recommend that you deploy the controller on a 64-bit operating system to guarantee the software stability.)

Web Browser: Mozilla Firefox 32 (or above), Google Chrome 37 (or above), Opera 24 (or above), or Microsoft Internet Explorer 11 (or above).

■ Install Omada Software Controller

Download the installation file of Omada Software Controller from the website. Then follow the instructions to properly install the Omada Software Controller. After a successful installation, a shortcut icon of the Omada Software Controller will be created on your desktop.

Installation on Linux Host

Two versions of installation package are provided: .tar.gz file and .deb file. Both of them can be used in multiple versions of Linux operating system, including Ubuntu, CentOS, Fedora, and Debian.

Make sure your PC's hardware and system meet the following requirements, then choose the proper installation files to install the Omada Software Controller.

■ Hardware Requirements

Omada Software Controller can manage up to 1500 EAPs if the Controller Host has enough hardware resources. To guarantee operational stability for managing 1500 EAPs, we recommend that you use the hardware which meets or exceeds the following specifications:

CPU: Intel Core i3-8100, i5-6500, or i7-4700 with 2 or more cores and 4 or more threads.

Memory: 6 GB RAM or more.

■ System Requirements

Operating System: 64-bit Linux operating system, including Ubuntu 14.04/16.04/17.04/18.04, CentOS 6.x/7.x, Fedora 20 (or above), and Debian 9.8.

Web Browser: Mozilla Firefox 32 (or above), Google Chrome 37 (or above), Opera 24 (or above), or Microsoft Internet Explorer 11 (or above).

■ Install Omada Software Controller

Download the installation file of Omada Software Controller from the website. Check the prerequisites and follow the steps based on your file version to install the controller. Here takes Omada SDN Controller 4.2.8 as the example.

- Prerequisites for installing

To successfully install Omada Software Controller, ensure that you have performed the following tasks before your installation:

  1. Ensure that the Java Runtime Environment (JRE) have been installed in your system. The controller requires that the system have Java 8 installed. Download the file according to your operating system from the website and follow the instructions to install the JRE. For Ubuntu16.04 or above, you can use the command: apt-get install openjdk-8-jre-headless to get the Java 8 installed.
  2. Ensure that MongoDB has been installed in your system. The controller works when the system runs MongoDB 3.0.15–3.6.18. Download the file according to your operating system from the website and follow the instructions to install the MongoDB.
  3. Ensure that you have jsvc and curl installed in your system before installation, which is vital to the smooth running of the system. If your system does not have jsvc or curl installed, you can install it manually with the command: apt-get install or yum install. For example, you can use the command: apt-get install jsvc or yum install jsvc to get jsvc installed. And if dependencies are missing, you can use the command: apt-get -f install to fix the problem.

- Install the .tar.gz file

  1. Make sure your PC is running in the root mode. You can use this command to enter root mode: sudo
  2. Extract the tar.gz file using the command: tar zxvf Omada_Controller_v4.2.8_linux_x64_targz.tar.gz
  3. Install Omada Controller using the command: sudo bash ./install.sh

- Install the .deb file

  1. Make sure your PC is running in the root mode. You can use this command to enter root mode: sudo
  2. Install the .deb file using the command: dpkg -i Omada_Controller_v4.2.8_linux_x64.deb

If dependencies are missing during the installation, you can use the command: apt-fix-broken install to fix the problem.

After installing the controller, use the following commands to check and change the status of the controller.

  1. tpeap start — start the controller, use the command.
  2. tpeap stop —stop running the Omada Controller.
  3. tpeap status — show the status of Controller.

For more detailed information about the installation on Linux hosts, refer to the installation instructions.

Note:

  • For installing the .tar.gz, if you want Omada Controller to run as a user (it runs as root by default) you should modify OMADA_USER value in bin/control.sh.
  • To uninstall Omada Controller, go to the installation path: /opt/tplink/EAPController, and run the command: sudo bash ./uninstall.sh.
  • During uninstallation, you can choose whether to back up the database. The backup folder is /opt/tplink/eap_db_backup.
  • During installation, you will be asked whether to restore the database if there is any backup database in the folder /opt/tplink/eap_db_backup.

2.1.3 Start and Log In to the Omada Software Controller

Launch Omada Software Controller and follow the instructions to complete the basic configurations, and then you can log in to the management interface.

Launch Omada Software Controller

Double-click the icon and the following window will pop up. You can click Hide to hide this window but do not close it. After a while, your web browser will automatically open.

Omada Controller v4.2.4 - TP-Link tp-link Omada Controller v4.2.4 Started. Details [2020-10-23 11:26:55] Starting... [2020-10-23 11:26:57] Mongo DB server started [2020-10-23 11:27:26] Web server started [2020-10-23 11:27:27] Omada Controller started [2020-10-23 11:27:28] discovery server started [2…

TP-LINK Omada OC200 - Launch Omada Software Controller - 2

Note:

  • If your browser does not open automatically, click Launch a Browser to Manage the Network. You can also launch a web browser and enter http://127.0.0.1:8088 in the address bar.
  • If your web browser opens but prompts a problem with the website's security certificate, click Continue.

Do the Basic Configurations

In the web browser, you can see the configuration page. Follow the setup wizard to complete the basic settings for Omada Controller.

  1. Click Let's Get Started.

omada Welcome to use Omada Controller Please follow the wizard to set up your controller. Let's Get Started

  1. Specify a name for Omada Controller, and set your region and timezone. Then select the application scenario depending on your needs. Click Next.

Omada Setup Wizard Configure Devices Configure Wi-Fi Controller Access Summary Omada Setup Wizard Set Your Controller Name: Omada Controller_TPLINK Set your country or region: China Mainland Select Your Timezone: (UTC+08:00) Beijing, Chongqing, Hong Kong, Urumqi Application Scenario Select the appli…

  1. The setup page displays all the discovered devices in the network. Select one or more devices to be managed and click Next.

Omada Setup Wizard — 2 Configure Devices — 3 Configure Wi-Fi — 4 Controller Access — 5 Summary Configure Devices Please select the devices you would like to configure. DEVICE NAME MODEL IP ADDRESS UP TIME No entry in the table. Back Skip Next

  1. Set a wireless network name (SSID) and password for the EAPs to be managed. Omada Controller will create two wireless networks, a 2.4GHz one and a 5GHz one, both encrypted in WPA-Personal

mode. You can set Guest Wi-Fi to provide open Wi-Fi access for guests without disclosing your main network if needed. Click Next.

Omada Setup Wizard Configure Devices 3 Configure Wi-Fi 4 Controller Access 5 Summary Configure Wi-Fi You may skip this step if you are not setting up any Omada access points. Network Name (SSID): SSID-1 Password: ******** You can create an open wireless network for your guests if needed. Guest Wi-Fi…

  1. Set a username and password for the login account. Specify the email address for resetting your password in case you forget it. After logging into Omada Controller, set a mail server so that you can receive emails and reset your password. For instructions on setting a mail server, refer to section 8.5.3 Notifications.

Omada Setup Wizard Configure Devices Configure Wi-Fi Controller Access Summary Controller Access Create an administrator name and password for local login to Omada Controller. Administrator Name: admin Enter the username with letters (case-sensitive), numbers, underscores, or hyphens. Email: admin@e…

  1. If you want to access the controller to manage networks remotely, enable the Cloud Access button, bind your TP-Link ID to your Omada Controller, and then click Next. If not, click Next directly.

For more details about Omada Cloud, please refer to section 5.2 Manage Your Controller Remotely via Cloud Access.

To enjoy Omada Cloud Service, you can log in and bind your TP-Link ID to your controller. Cloud Access: TP-Link ID: clouduser@example.com Password: ............ Log In and bind No TP-Link ID? Register now Back Next

7. Review your settings and click Finish.

Omada Setup Wizard Configure Devices Configure Wi-Fi Controller Access Summary Please confirm the settings below. Once finished you will be directed to the management interface. Controller Name: Omada Controller_TPLINK Country/Region: China Timezone: (UTC+08.00) Beijing, Chongqing, Hong Kong, Urumqi…

Log In to the Management Interface

Once the basic configurations are finished, the browser will be redirected to the following page. Log in to the management interface using the username and password you set in the basic configurations.

TP-LINK Omada OC200 - Log In to the Management Interface - 1

tp-link

TP-LINK Omada OC200 - Log In to the Management Interface - 2

Omada SDN Controller

admin ****** Remember Me Log in

Forgot password?

TP-LINK Omada OC200 - Omada SDN Controller - 2

Note:

In addition to the Controller Host, other hosts in the same LAN can also manage EAPs via remote access to the Controller Host. For example, if the IP address of the Controller Host is 192.168.0.100 and Omada Controller is running normally on this host, you can enter https://192.168.0.100:8043 or http://192.168.0.100:8088 in the web browser of other hosts in the same LAN to log in to the Omada Controller and manage EAPs. Alternatively, you can log in to Omada Controller using other management devices through the Omada Cloud service.

2.2 Set Up Your Hardware Controller

The Omada SDN Controller Solution is designed for scalable networks. Deployments and configurations vary according to actual situations. Understanding your network requirements is the first step when planning to provision any project. After you have identified these requirements, follow the steps below to initially set up the Omada Hardware Controller:

1) Determine the network topology. 2) Deploy the Omada Hardware Controller. 3) Start and log in to the controller.

2.2.1 Determine the Network Topology

The network topology that you create for Omada SDN Controller varies depending on your business requirements. The following figure shows a typical topology for a high-availability use case.

graph TD A["Internet"] --> B["SafeStream Gateway"] B --> C["JetStream Switch"] C --> D["Omada Access Points"] C --> E["Omada Hardware Controller"] C --> F["Omada Gateway"] C --> G["Omada Link"] C --> H["Omada Port"] C --> I["Omada Link"]

Note:

When using Omada SDN Controller, we recommend that you deploy the full Omada topology with supported TP-Link devices. If you use third-party devices, Omada SDN Controller cannot discover and manage them.

2.2.2 Deploy Omada Hardware Controller

Omada Hardware Controller comes with the pre-installed controller software, so installation is not necessary. After deploying Omada Hardware Controller on your network infrastructure, proceed to configure the controller.

2.2.3 Start and Log in to the Controller

Log In to the Management Interface

Follow the steps below to enter the management interface of Omada Hardware Controller:

  1. Make sure that your management device has the route to access the controller.
  2. Check the DHCP server (typically a router) for the IP Address of the controller. If the controller fails to get a dynamic IP address from the DHCP server, the default fallback IP address 192.168.0.253, is used.
  3. Launch a web browser and type the IP address of the controller in the address bar, then press Enter (Windows) or Return (Mac).

Do the Basic Configurations

In the web browser, you can see the configuration page. Follow the setup wizard to complete the basic settings for Omada Controller.

  1. Click Let's Get Started.

omada Welcome to use Omada Controller Please follow the wizard to set up your controller. Let's Get Started

  1. Specify a name for Omada Controller, and set your region and timezone. Then select the application scenario depending on your needs. Click Next.

Omada Setup Wizard Configure Devices Configure Wi-Fi Controller Access Summary Omada Setup Wizard Set Your Controller Name: Omada Controller_TPLINK Set your country or region: China Mainland Select Your Timezone: (UTC+08:00) Beijing, Chongqing, Hong Kong, Urumqi Application Scenario Select the appli…

  1. The setup page displays all the discovered devices in the network. Select one or more devices to be managed and click Next.

Omada Setup Wizard — 2 Configure Devices — 3 Configure Wi-Fi — 4 Controller Access — 5 Summary Configure Devices Please select the devices you would like to configure. DEVICE NAME MODEL IP ADDRESS UP TIME No entry in the table. Back Skip Next

  1. Set a wireless network name (SSID) and password for the EAPs to be managed. Omada Controller will create two wireless networks, a 2.4GHz one and a 5GHz one, both encrypted in WPA-Personal

mode. You can set Guest Wi-Fi to provide open Wi-Fi access for guests without disclosing your main network if needed. Click Next.

Omada Setup Wizard Configure Devices 3 Configure Wi-Fi 4 Controller Access 5 Summary Configure Wi-Fi You may skip this step if you are not setting up any Omada access points. Network Name (SSID): SSID-1 Password: ............. You can create an open wireless network for your guests if needed. Guest…

  1. Set a username and password for the login account. Specify the email address for resetting your password in case that you forget the password. After logging in Omada Controller, set a mail server so that you can receive emails and reset your password. For how to set a mail server, refer to 8.5.3 Notifications.

Omada Setup Wizard Configure Devices Configure Wi-Fi Controller Access Summary Controller Access Create an administrator name and password for local login to Omada Controller. Administrator Name: admin Enter the username with letters (case-sensitive), numbers, underscores, or hyphens. Email: admin@e…

  1. If you want to access the controller to manage networks remotely, enable the Cloud Access button, and bind your TP-Link ID to your Omada Controller, and then click Next. If not, click Next directly.

For more details about Omada Cloud, please refer to 5.2 Manage Your Controller Remotely via Cloud Access.

To enjoy Omada Cloud Service, you can log in and bind your TP-Link ID to your controller. Cloud Access: TP-Link ID: clouduser@example.com Password: ............ Log In and bind No TP-Link ID? Register now Back Next

7. Review your settings and click Finish.

Omada Setup Wizard Configure Devices Configure Wi-Fi Controller Access Summary Please confirm the settings below. Once finished you will be directed to the management interface. Controller Name: Omada Controller_TPLINK Country/Region: China Timezone: (UTC+08.00) Beijing, Chongqing, Hong Kong, Urumqi…

Log In to the Management Interface

Once the basic configurations are finished, the browser will be redirected to the following page. Log in to the management interface using the username and password you have set in the basic configurations.

TP-LINK Omada OC200 - Log In to the Management Interface - 1

tp-link

TP-LINK Omada OC200 - Log In to the Management Interface - 2

Omada SDN Controller

admin ****** Remember Me Log in

Forgot password?

TP-LINK Omada OC200 - Omada SDN Controller - 2

Note:

In addition to the Controller Host, other hosts in the same LAN can also manage EAPs via remote access to the Controller Host. For example, if the IP address of the Controller Host is 192.168.0.100 and Omada Controller is running normally on this host, you can enter https://192.168.0.100:8043, or http://192.168.0.100:8088 in the web browser of other hosts in the same LAN to log in to the Omada Controller and manage EAPs. Or you can log in to Omada Controller using other management devices through Omada Cloud service.

2.3 Set Up Your Cloud-Based Controller (Coming Soon)

The Omada SDN Controller Solution is designed for scalable networks. Deployments and configurations vary according to actual situations. Understanding your network requirements is the first step when planning to provision any project. After you have identified these requirements, follow the steps below to initially set up the Omada Cloud-Based Controller:

1) Launch a web browser and enter https://omada.tplinkcloud.com in the address bar. Enter your TP-Link ID and password to log in. If you do not have a TP-Link ID, create one first. 2) Click Add Controller and register for an Omada Cloud-Based Controller. Follow the instructions to complete the setup process. 3) Add devices with the serial number, making sure the devices are online and in factory default state. 4) Assign appropriate licenses in order to manage and configure the devices on the cloud-based controller. Then wait until your controller is deployed.

For detailed information about device-based licensing, refer to "Know more about licensing."

Note:

Only when you have available licenses can you register for the Cloud-Based Controller and manage the devices. To successfully register for a Cloud-Based Controller, purchase appropriate licenses.

3

Manage Omada Managed Devices and Sites

Start managing your network by creating sites and adopting devices so that you can configure and monitor your devices centrally while keeping things organized. This chapter includes the following sections:

• 3.1 Create Sites • 3.2 Adopt Devices

TP-LINK Omada OC200 - Manage Omada Managed Devices and Sites - 1

3.1 Create Sites

Overview

Different sites are logically separated network locations, like different subsidiary companies or departments. It's best practice to create one site for each LAN (Local Area Network) and add all the devices within the network to the site, including the router, switches, and APs.

graph TD A["Omada SDN Controller"] --> B["Site A"] A --> C["Site B"] A --> D["Site C"] A --> E["Site D"] A --> F["Site E"] B --> G["AP"] B --> H["AP"] C --> I["LAN 3"] C --> J["Switch"] D --> K["AP"] D --> L["AP"] E --> M["AP"] E --> N["AP"] F --> O["LAN 2"] F --> P["Switch"] G --> Q["AP"] G --> R["…

Devices at one site need unified configurations, whereas those at different sites are not related. To make the best of a site, configure features simultaneously for multiple devices at the site, such as VLAN and PoE Schedule for switches, and SSID and WLAN Schedule for APs, rather than setting them up one by one.

Configuration

To create and manage a site, follow these steps:

1) Create a site. 2) View and edit the site. 3) Go into the site.

Create a Site View and Edit the Site Go Into the Site

To create a site, choose one from the following methods according to your needs.

■ Create a site from scratch

  1. Click + Add New Site in the drop-down list of Sites. Alternatively, click ⚫ Site Manager in the drop-down list of Sites and click ⊕ in the Site Management page.
  2. Enter a Site Name to identify the site, and configure other parameters according to where the site is located. Then click Apply. The new site is added to the drop-down list of Sites, and the table in the Site Management page as well.

Add New Site Site Name: Country/Region: United States Time Zone: (UTC+08:00) Beijing, Chongqing, Hong Kong, Urumqi Application Scenario: Hotel Apply

■ Copy an existing site

You can quickly create a site based on an existing one by copying its site configuration, wired configuration, and wireless configuration among others. After that, you can flexibly modify the new site configuration to make it different from the old.

  1. Click Site Manager in the drop-down list of Sites. In the Site Management page, click in the ACTION column of the site which you want to copy.
  2. Enter a Site Name to identify the new site. Click Apply. The new site is added to the drop-down list of Sites, and the table in the Site Management page as well.

Site Copy Site Name: Note: With Site Copy, you can create a new site with the same configuration as the existing site. Apply Cancel

■ Import a site from another controller

If you want to migrate seamlessly from an old controller to a new one, import the site configuration file of the old controller into the new. Before that, you need to export the site configuration file from the old controller, which is covered in 5.4.1 Site Migration.

  1. Click ↑ Import Site in the drop-down list of Sites. Alternatively, click in the drop-down list of Sites and click ↑ in the Site Management page.
  2. Enter a Site Name to identify the site. Browse your file explorer and choose a site configuration file. Click Import. The new site is added to the drop-down list of Sites, and the table in the Site Management page as well.

Import Site Site Name: Choose File: Please select a file. Browse Import Cancel

Create a Site View and Edit the Site Go Into the Site

After you create the site, you can click Site Manager in the drop-down list of Sites, and view the site status in the Site Management page. You can click in the ACTION column to edit the site configuration. You can click in the ACTION column to delete the site.

Site Name NAME COUNTRY/REGION ALERTS WAN LAN CONNECTED DISCONNECTED WLAN CONNECTED DISCONNECTED ISOLATED USERS GUESTS ACTION Ip Ink United States 2 1 1 1 3 7 0 5 8

Create a Site View and Edit the Site Go Into the Site

To monitor and configure a site, you need first go into the site.

  1. Select the site from the drop-down list of Sites to go into the site.

graph LR A["Internet Capacity"] --> B["Gateway"] B --> C["Switches"] C --> D["EAFs"] D --> E["Clients"] E --> F["Google"] style A fill:#f9f,stroke:#333 style B fill:#ccf,stroke:#333 style C fill:#cfc,stroke:#333 style D fill:#fcc,stroke:#333 style E fill:#cff,stroke:#333 style F fill:#ffc,stroke:#33…

  1. The Site field indicates the site which you are currently in. Some configuration items in the menu are applied to the site which you are currently in, whereas others are applied to the whole controller.

TP-Link Omada Sites: 2 links IP Load: Unknown N/A Internet Capacity N/A Gateway 0 Switches 0 EAPs 0 Clients 0 Guests Overall Network Clients 2 sites in 1 counties 4 Devices 2 Admins See Admin > Connected Cloud Access Manage Cloud Access + 32 Association Failures 0 Type Client ● Association Thread 0…

TP-LINK Omada OC200 - Create a Site View and Edit the Site Go Into the Site - 3

3.2 Adopt Devices

Overview

After you create a site, add your devices to the site by making the controller adopt them. Make sure that your devices in each LAN are added to the corresponding site so that they can be managed centrally.

graph TD A["Omada SDN Controller"] --> B["Site A Site B Site C Site D Site E"] A --> C["Site D"] A --> D["Site E"] B --> E["AP"] B --> F["AP"] C --> G["LAN 3"] C --> H["LAN 2"] C --> I["LAN 1"] D --> J["AP"] D --> K["AP"] D --> L["AP"] D --> M["LAN 4"] D --> N["LAN 5"] D --> O["AP"] B --> P["Router"…

Configuration

Choose a procedure according to the type of your controller:

■ 3.3.1 For Omada Software Controller / Omada Hardware Controller

■ 3.3.2 For Omada Cloud-Based Controller (Coming Soon)

3.3.1 For Omada Software Controller / Omada Hardware Controller

To adopt the devices on the controller, follow these steps:

1) Prepare for communication between the controller and devices. 2) Prepare for device discovery. 3) Adopt the devices.

Prepare for Communication Prepare for Device Discovery Adopt the Devices

TP-LINK Omada OC200 - For Omada Software Controller / Omada Hardware Controller - 1

Note:

If the controller and devices are in the same LAN, subnet, and VLAN, skip this step.

Make sure that the controller can communicate with the devices. Otherwise, the controller cannot discover or adopt the devices by any means. If the controller and devices are in different LANs, subnets, or VLANs, use the following techniques to build up the connection according to your scenario.

1. Set up the Network

■ Scenario 1: Across VLANs or Subnets

As shown in the following figures, the controller and devices are in different VLANs or subnets. You need to set up a layer 3 interface for each VLAN or subnet, and make sure the interfaces can communicate with each other.

graph TD A["Internet"] --> B["Gateway"] B --> C["Interface 1 Interface 2"] B --> D["Omada SDN Controller Site"] C --> E["Switch"] E --> F["AP AP"] E --> G["VLAN 1 VLAN 2"] D --> H["Unified Management from One Interface"] D --> I["Gateway Switch APs"] J["Internet"] --> K["Gateway"] K --> L["Interface…

■ Scenario 2: Across LANs

As shown in the following figure, the controller and devices are in different LANs. You need to establish communication across the internet and the gateways.

By default, devices in LAN 1 cannot communicate with the controller in LAN 2, because Gateway B is in front of the controller and blocks access to it. To make the controller accessible to the devices, you can use Port Forwarding or VPN.

- Use Port Forwarding

Configure Port Forwarding on Gateway B and open port 29810-29813 for the controller, which are essential for discovering and adopting devices. If you are using firewalls in the networks, make sure that the firewalls don't block those ports.

graph TD A["Internet"] --> B["Gateway A"] A --> C["Switch"] B --> D["AP AP"] B --> E["AP AP"] F["Port Forwarding Gateway B"] --> G["Omada SDN Controller Site"] G --> H["Unified Management from One Interface"] G --> I["Gateway Switch APs"] style A fill:#f9f,stroke:#333 style F fill:#bbf,stroke:#333

To configure Port Forwarding on Gateway B, you need first adopt Gateway B on the controller. For how to adopt Gateway B, refer to Adopt the Devices. Go to Settings > Transmission > NAT > Port Forwarding. Click + Create New Rule to load the following page. Specify a name to identify the Port Forwarding rule, check Enable for Status, select Any as Source IP, select the desired WAN port

as Interface, disable DMZ, specify 29810-29813 as Source Port and Destination Port, specify the controller's IP address as Destination IP, and select All as Protocol. Then click Create.

Create New Rule Name: open-port-for-controller Status: Enable Source IP: Any Limited IP Address Interface: WAN × DMZ: Enable Source Port: 29810-29813 (1-65535. e.g. 80 or 80-100) Destination IP: 192.168.0.26 Destination Port: 29810-29813 (1-65535. e.g. 80 or 80-100) Protocol: All TCP UDP Create Canc…

- Use VPN

Set up a VPN connection between Gateway A and Gateway B in Standalone Mode. For details about VPN configuration, refer to the User Guide of the gateways.

graph TD A["Internet"] -->|VPN Connection| B["Gateway A"] A -->|VPN Connection| C["Gateway B"] B --> D["Switch"] D --> E["AP AP"] D --> F["Switch"] C --> G["Omada SDN Controller Site"] G --> H["Unified Management from One Interface"] G --> I["Gateway Switch APs"]

2. (Optional) Test the network

If you are not sure whether the controller and devices can establish communication, it's recommended to do the ping test from the devices to the controller.

Let's take a switch for example. Log into the web page of the switch in Standalone Mode. Then go to MAINTENANCE > Network Diagnostics > Ping to load the following page, and specify Destination

IP as the IP address of the controller (if you have configured Port Forwarding on the controller side, use the public WAN IP address of the gateway instead). Then click Ping.

Ping Config Destination IP: 192.168.0.26 (Format: 192.168.0.1 or 2001::1) Ping Times: 4 (1-10) Data Size: 64 bytes (1-1500) Interval: 1000 milliseconds (100-1000) Ping Ping Result Pinging 192.168.0.26 with 64 bytes of data: Reply from 192.168.0.26: bytes=64 time=19ms TTL=64 Reply from 192.168.0.26:…

If the ping result shows the packets are received, it implies that the controller can communicate with the devices. Otherwise, the controller cannot communicate with the devices, then you need to check your network.

Prepare for Communication

Prepare for Device Discovery

Adopt the Devices

TP-LINK Omada OC200 - Adopt the Devices - 1

Note:

If the controller and devices are in the same LAN, subnet and VLAN, skip this step. In this scenario, the controller can discover the devices directly, and no additional settings are required.

Make sure that the controller can discover the devices.

When the controller and devices are in different LANs, subnets or VLANs, the controller cannot discover the devices directly. You need to choose Controller Inform URL, Discovery Utility, or DHCP Option 138 as the method to help the controller discover the devices.

■ Controller Inform URL

Controller Inform URL informs the devices of the controller's URL or IP address. Then the devices make contact with the controller so that the controller can discover the devices.

You can configure Controller Inform URL for devices in Standalone Mode. Let's take a switch for example. Log into the management page of the switch in Standalone Mode and go to SYSTEM > Controller Settings to load the following page. In Controller Inform URL, specify Inform URL/IP Address as the controller's URL or IP address (if you have configured Port Forwarding on the controller side, use the public WAN IP address of the gateway instead). Then click Apply.

Cloud-Based Controller Management Connection Status: Disabled Cloud-Based Controller Management: Enable Notes: To enjoy centralized management on Omada Cloud-Based Controller, enable Cloud-Based Controller Management and add the device to the controller via its serial number. You can disable this fe…

■ Discovery Utility

Discovery Utility can discover the devices in the same LAN, subnet and VLAN, and inform the devices of the controller's IP address. Then the devices make contact with the controller so that the controller can discover the devices.

  1. Download Discovery Utility from the website and then install it on your PC which should be located in the same LAN, subnet and VLAN as your devices.
  2. Open Discovery Utility and you can see a list of devices. Select the devices to be adopted and click Batch Setting.

Omada Discovery Utility Discovering EAPs... MAC, IP, Status Select MAC Address IP Address Model Version Status Action D8-0D-17-DA-46-89 192.168.0.3 EAP115-Wall 1.2.0 Build 2018060... Pending Manage EA-23-51-06-22-52 192.168.0.5 EAP225-Outdoor 1.5.0 Build 2018112... Pending Manage EA-33-51-A8-22-A0 1…

  1. Specify Controller Hostname/IP as the IP address of the controller (if you have configured Port Forwarding on the controller side, use the public WAN IP address of the gateway instead), and

enter the username and password of the devices. By default, the username and password are both admin. Then click Apply. Wait until the setting succeeds.

Omada Discovery Utility Discovering EAPs... MAC, IP, Status Select MAC Address ✓ D8-0D-17-DA-46-8 ✓ EA-23-51-06-22-52 ✓ EA-33-51-AB-22-A Batch Setting Controller Hostname/IP: 192.168.0.26 Username: admin Password: •••••• Apply Cancel Status Action Binding Manage Binding Manage Binding Manage Display…

■ DHCP Option 138

DHCP Option 138 informs a DHCP client, such as a switch or an EAP, of the controller's IP address when the DHCP client sends DHCP requests to the DHCP server, which is typically a gateway.

  1. To use DHCP Option 138, you need to adopt the gateway on the controller first, which may require other techniques like Controller Inform URL or Discovery Utility if necessary.
  2. After the gateway is adopted, go to Settings > Wired Networks > LAN > Networks, and click in the ACTION column of the LAN where the DHCP clients are located. Enable DHCP Server and configure common DHCP parameters. Then click Advanced DHCP Options and specify Option

138 as the controller's IP address (if you have configured Port Forwarding on the controller side, use the public WAN IP address of the gateway instead). Click Save.

Edit Network Name: LAN Purpose: Interface VLAN LAN Interfaces: WAN/LAN2 WAN/LAN3 LAN1 VLAN: 1 (1-4090) Gateway/Subnet: 192.168.1.1 / 24 i Update DHCP Range Gateway IP 192.168.1.1 Network Broadcast IP 192.168.1.255 Network IP Count 254 Network IP Range 192.168.1.1 - 192.168.1.254 Network Subnet Mask…

  1. To make DHCP Option 138 take effect, you need to renew DHCP parameters for the DHCP clients. One possible way is to disconnect the DHCP clients and then reconnect them.

Prepare for Communication Prepare for Device Discovery Adopt the Devices

  1. Decide which site you want to add the devices to. On the controller configuration page, select the site from the drop-down list of Sites.

graph LR A["N/A<br>Internet Capacity"] --> B["1<br>Gateway"] B --> C["1<br>Switches"] C --> D["2<br>EAFs"] D --> E["1<br>Clients"] E --> F["Qut"] F --> G["Site Manager"] G --> H["Add New Site"] H --> I["Import Site"] I --> J["Hotspot Manager"] J --> K["2 sites in 1 countries"] K --> L["4 Devices"] L…

  1. Go to Devices, and devices which have been discovered by the controller are displayed. Click √ in the ACTION column of the devices which you want to add to the site.

tp-link omada Search or selection log All <|vision_start|> Malware/Defaulted APIs DEVICE NAME IP ADDRESS STATUS MODEL VERSION UP TIME ACTION 00-0A-ED-16-F7-AI 10.0.0.196 PENDING TL-002210HP v1.0 1.0.0 2 days 10:36:25 00-0D-PF-FF-DE-0E 10.0.3.144 PENDING EAP560 HD(EU) v1.1 1.0.0 2 days 10:36:18 Showi…

  1. Wait until the STATUS turns into Connected. Then the devices are adopted by the controller and added to the current site. Once the devices are adopted, they are subject to central management in the site.

tp-link omda Search or selection: All Getaway/Setbitres Altfs DEVICE NAME IP ADDRESS STATUS MODEL VERSION UP TIME / ACTION 05-04-EB-16-F7-AI 10.0.0.198 CONNECTED TL-5G2210HP-v1.0 1.0.9 2 days 10:36:25 05-03-PF-IF-DE-80 10.0.3.144 CONNECTED EAXSED HD/EUy v1.0 1.0.9 2 days 10:15:16 Showing 1-2 of 2 re…

3.3.2 For Omada Cloud-Based Controller (Coming Soon)

To adopt the devices on the controller, follow these steps:

1) Connect to the internet. 2) Prepare for controller management.

3) Adopt the devices.

Connect to the Internet Practice for Controller Management Adopt the Devices

1. Set up the network.

Make sure that your devices are connected to the internet.

graph TD A["Omada SDN Controller Site"] --> B["Internet"] B --> C["Gateway A"] B --> D["Switch"] C --> E["AP AP"] D --> F["LAN 1"] style A fill:#f9f,stroke:#333 style B fill:#bbf,stroke:#333 style C fill:#dfd,stroke:#333 style D fill:#dfd,stroke:#333

If you are using firewalls in your network, make sure that the firewall doesn't block traffic from the controller. To configure your firewall policy, you may want to know the URL of the controller. After you open the web page of the controller, you can get the URL from the address bar of the browser.

2. (Optional) Test the network.

If you are not sure whether the devices are connected to the internet, it's recommended to do the ping test from the devices to a public IP address, such as 8.8.8.8.

Let's take a switch for example. Log into the web page of the switch in Standalone Mode. Go to MAINTENANCE > Network Diagnostics > Ping to load the following page. Specify Destination IP as a public IP address, such as 8.8.8.8. Then click Ping.

Ping Config Destination IP: 8.8.8.8 (Format: 192.168.0.1 or 2001::1) Ping Times: 4 (1-10) Data Size: 64 bytes (1-1500) Interval: 1000 milliseconds (100-1000) Ping Ping Result Pinging 8.8.8.8 with 64 bytes of data: Reply from 8.8.8.8 : bytes=64 time=3ms TTL=64 Reply from 8.8.8.8 : bytes=64 time=3ms T…

If the ping result shows the packets are received, it implies that the devices are connected to the internet. Otherwise, the devices are not connected to the internet, then you need to check your network.

Connect to the Internet

Prepare for Controller Management

Adopt the Devices

Note:

If your devices are on the factory default setting, skip this step.

The Cloud-Based Controller Management feature allows the devices to be adopted by Omada Cloud-Based Controller. Make sure Cloud-Based Controller Management is enabled on the devices. For details, refer to the User Guide of your devices, which can be downloaded from the TP-Link download center.

Let's take a switch for example. Log into the web page of the switch in Standalone Mode. Go to SYSTEM > Controller Settings to load the following page. In Cloud-Based Controller Management, enable Cloud-Based Controller Management and click Apply.

Cloud-Based Controller Management

Connection Status: Off-line

Cloud-Based Controller Management: ☑ Enable

Notes:

To enjoy centralized management on Omada Cloud-Based Controller, enable Cloud-Based Controller Management and add the device to the controller via its serial number.

You can disable this feature if you do not need to manage the device with the Omada Cloud-Based Controller.

Controller Inform URL

Inform URL/IP Address:

Notes:

Enter the inform URL or IP address of your controller to tell the device where to discover the controller. This feature is commonly used for the device to be managed by the controller in Layer 3 deployments.

Apply

Connect to the Internet Prepare for Controller Management Adopt the Devices

On the controller configuration page, go into the site where you want to add the devices. Go to Devices and click Add Devices. Then add your devices to the controller. Once the devices are adopted, they are subject to central management in the site.

4

Configure the Network with Omada SDN Controller

This chapter guides you on how to configure the network with Omada SDN Controller. As the command center and management platform at the heart of the Omada network, Omada SDN Controller provides a unified approach to configuring enterprise networks comprised of routers, switches, and wireless access points. The chapter includes the following sections:

• 4.1 Navigate the UI • 4.2 Modify the Current Site Configuration • 4.3 Configure Wired Networks • 4.4 Configure Wireless Networks • 4.5 Network Security • 4.6 Transmission • 4.7 Configure VPN • 4.8 Create Profiles • 4.9 Authentication • 4.10 Services

4.1 Navigate the UI

As you start using the management interface of the controller (Controller UI) to configure and monitor your network, it is helpful to familiarize yourself with the most commonly-used elements of the Controller UI that are frequently referenced in this guide.

The Controller UI is grouped into task-oriented menus, which are located in the top right-hand corner and the left-hand navigation bar of the page. Note that the settings and features that appear in the UI depend on your user account permissions. The following image depicts the main elements of the Controller UI.

tp-link | omeda ISP Load Good Normal Internet N/A Getway 12 Switch 30/50 EAP 300 Clients Site Management Global Search Feature My Account More Settings Monitoring System Presenting Statistical Information 2.4 GHz 6 GHz 56 GHz 11 36 40 44 48 52 58 60 64 44 48 52 59 56 20 2.4 GHz 56 GHz WiFi Traffic D…

The elements in the top right corner of the screen give quick access to:

Sites: Default

Site Management

Site, which means logically separated network location, is the largest unit for managing networks with Omada SDN Controller. You can simultaneously configure features for multiple devices at a site. The Site Management includes:

Site Manager — have a quick overview of sites, including the name, location, managed devices, and connected clients.

Add New Site — add a new site, which is the logically separated network location. The site is the largest unit for managing the network.

Import Site — import the site from another controller.

Global Search Feature

Click the search icon and enter the keywords to quickly look up the functions that you want to configure. And you can search for the devices by their MAC addresses and device names.

My Account

Click the account icon to display account information, Account Settings and Log Out. You can change your password on Account Settings.

More Settings

Click the More icon to display Preferences, About and Tutorial.

Preferences: Click to jump to Maintenance and customize the Controller UI depending on your needs. For details, refer to 5.3 Maintenance

About: Click to display the controller version.

Tutorial: Click to view the quick Getting Started guide which demonstrates the navigation and tools available for the controller.

The left-hand navigation bar provides access to:

Dashboard displays a summarized view of the network status through different visualizations. The widget-driven dashboard is customizable depending on your needs.
Statistics provides a visual representation of the clients and network managed by the controller. The run charts show changes in device performances over time, including the status of switches and speed test results.
Map generates the system topology automatically and you can look over the provisioning status of devices. By clicking on each node, you can view the detailed information of each device. You can also upload images of your location for a visual representation of your network.
Devices displays all TP-Link devices discovered on the site and their general information. This list view can change depending on your monitoring needs through customizing the columns. You can click any device on the list to reveal the Properties window for more detailed information of each device and provisioning individual configurations to the device.
Clients displays a list view of wired and wireless clients that are connected to the network. This list view can change depending on your monitoring need through customizing the columns. You can click any clients on the list to reveal the Properties window for more detailed information of each client and provisioning individual configurations to the client.
Insight displays a list of statistics of your network device, clients and services during a specified period. You can change the range of date in one-day increments.
Log displays logs that record varied activities of users, devices, and systems events, such as administrative actions and abnormal device behaviors. You can also configure notifications to receive alert emails of certain activities.
Admin allows you to configure multi-level administrative accounts with a hierarchy of permissions that can be configured to provide finely grained levels of access to the controller as required by your enterprise.
Settings is divided to two parts: Site Settings and Controller Settings. In Site Settings, you can provision and configure all your network devices on the same site in minutes. In Controller Settings, you can maintain the controller system for best performance.

4.2 Modify the Current Site Configuration

You can view and modify the configurations of the current site in Site, including the basic site information, centrally-managed device features, and the device account. The features and device account configured here are applied to all devices on the site, so you can easily manage the devices centrally.

4.2.1 Site Configuration

Overview

In Site Configuration, you can view and modify the site name, location, time zone, and application scenario of the current site.

Configuration

Select a site from the drop-down list of Sites in the top-right corner, go to Settings > Site, and configure the following information of the site in Site Configuration. Click Save.

Site Configuration

Site Name:

Default

Country/Region

China Mainland

Time Zone:

(UTC+08:00) Beijing, Chongqing, Hong Kong, Urumqi

TP-LINK Omada OC200 - Site Configuration - 1

Daylight Saving Time:

Enable

TP-LINK Omada OC200 - Site Configuration - 2

- DST is applicable only when the device supports the feature. To make DST work properly, it is recommended to upgrade your devices to the latest firmware version. - The DST configuration here only takes effect on the site. To configure the DST for the controller, go to the Controller Configuration. - With DST configured, the valid duration of Local User will be influenced accordingly.

Time Offset:

60

minutes (1-120)

Starts On:

Week:

Day

Month:

Time

1st

Sunday

January

00:00

TP-LINK Omada OC200 - Site Configuration - 3

Ends On:

Week:

Day.

Month:

Time

1st

Sunday

January

00:00

TP-LINK Omada OC200 - Site Configuration - 4

Application Scenario:

Hotel

Site Name: Specify the name of the current site. It should be no more than 64 characters.

Country/Region: Select the location of the site.

Time Zone: Select the time zone of the site.

Daylight Saving Time

Enable the feature if your country/region implements DST. When it is enabled, the icon DST will appear on the upper right, showing the DST settings and status.

Time Offset: Specify the time added in minutes when Daylight Saving Time starts.

Starts OnSpecify the time when the DST starts. The clock will be set forward by the time offset you specify.
Ends OnSpecify the time when the DST ends.The clock will be set back by the time offset you specify.
Application ScenarioSpecify the application scenario of the site. To customize your scenario, click Create New Scenario in the drop-down list.

4.2.2 Services

Overview

In Services, you can view and modify the features applied to devices on the current site. Most features are applied to all devices, such as LED, Automatic Upgrades, and Alert Emails, while some are applied to EAPs only, such as Channel Limit and Mesh.

Configuration

Select a site from the drop-down list of Sites in the top-right corner, go to Settings > Site, and configure the following features for the current site in Services. Click Save.

Services LED: ✓ Enable Automatic Upgrades: ☐ Enable Channel Limit: ☐ Enable ⓘ Mesh: ✓ Enable ⓘ Auto Failover: ☐ Enable ⓘ Connectivity Detection: Auto (Recommended) ✓ Full-Sector DFS: ✓ Enable ⓘ Periodic Speed Test: ✓ Enable Speed Test History Speed Test Interval: 20 hours (10-999) Alert Emails: ✓ En…

LED Enable or disable LEDs of all devices in the site.
By default, the device follows the LED setting of the site it belongs to. To change the LED setting for certain devices, refer to Chapter 6. Configure and Monitor Omada Managed Devices.
Automatic UpgradesWhen enabled, the controller will automatically upgrade devices in this site to the latest version.
Channel Limit(For Outdoor APs) When enabled, outdoor EAPs do not use the channel with the frequency ranging from 5150 MHz to 5350 MHz to meet the local laws and regulations limit in EU countries.
Mesh When enabled, EAPs supporting Mesh can establish the mesh network at the site.
Auto Failover(For APs in the mesh network) Auto Failover is used to automatically maintain the mesh network. When enabled, the controller will automatically select a new wireless uplink for the AP if the original uplink fails.To enable this feature, enable Mesh first.
Connectivity Detection(For APs in the mesh network) Specify the method of Connection Detection when mesh is enabled.In a mesh network, the APs can send ARP request packets to a fixed IP address to test the connectivity. If the link fails, the status of these APs will change to Isolated.Auto (Recommended): Select this method and the mesh APs will send ARP request packets to the default gateway for the detection.Custom IP Address: Select this method and specify a desired IP address. The mesh APs will send ARP request packets to the custom IP address to test the connectivity. If the IP address of the AP is in different network segments from the custom IP address, the AP will use the default gateway IP address for the detection.
Full-Sector DFS(For APs in the mesh network) With this feature enabled, when radar signals are detected on current channel by one EAP, the other EAPs in the mesh network will be also informed. Then all EAPs in the mesh network will switch to an alternate channel.To enable this feature, enable Mesh first.
Periodic Speed TestWhen enabled, the controller tests and records the speed and latency of WAN ports periodically.Speed Test Interval: When enabled, specify the interval to decide how often to test the speed of devices.Speed Test History: Click it to view the history statistics of speed test in 8.2.3 Speed Test Statistics.
Alert EmailsEnable alert emails: When enabled, the controller can send emails to notify the administrators and viewers of the site's alert logs once generated.Send similar alerts within seconds in one email: When enabled, the similar alerts generated in each time period are collected and sent to administrators and viewers in one email.To configure alert-level logs and enable email notifications on the controller, refer to8.5.3 Notifications.
Remote LoggingWith this feature configured, the controller will send generated site logs to the log server.When enabled, the following items are required:Syslog Server IP/Hostname: Enter the IP address or hostname of the log server.Syslog Server Port: Enter the port of the server.Client Detail Logs: With this feature enabled, the logs of clients will be sent to the syslog server.
Advanced Features(For APs) When enabled, you can configure more features for APs in Advanced Features.When disabled, these features keep the default settings.For detailed configuration, refer to4.2.3 Advanced Features.

4.2.3 Advanced Features

Overview

Advanced features include Fast Roaming, Band Steering, and Beacon Control, which are applicable to APs only. With these advanced features configured properly, you can improve the network's stability, reliability, and communication efficiency.

Advanced features are recommended to be configured by network administrators with WLAN knowledge. If you are not sure about your network conditions and the potential impact of all settings, keep Advanced Features disabled in Services to use their default configurations.

Configuration

Select a site from the drop-down list of Sites in the top-right corner, go to Settings > Site, and enable Advanced Features in Services first. Then configure the following features in Advanced Features. Click Save.

Advanced Features

Fast Roaming:✓ Enable i
AI Roaming:☐ Enable i
Dual Band 11k Report:☐ Enable i
Force-Disassociation:☐ Enable i
Band Steering:✓ Enable i
Connection Threshold:30(2-40) i
Difference Threshold:4(1-8) i
Maximum Failures:5(0-100) i

Beacon ControlTP-LINK Omada OC200 - Configuration - 1

2.4GHz5GHz
Beacon Interval:100 ms(40-100)
DTIM Period:1(1-255)
RTS Threshold:2347(1-2347)
Fragmentation Threshold:2346(256-2346, works only on 802.11b/g mode.)
Airtime Fairness:Enable i

Fast Roaming: With this feature enabled, wireless clients that support 802.11k/v can improve fast roaming experience when moving among different APs.

By default, it is disabled. This feature is available for some certain devices.

AI Roaming: With Fast Roaming enabled, you can enable AI Roaming to facilitate Fast Roaming, which improves roaming experience of the wireless clients that support 802.11k/v. This feature is available for some certain devices.

Dual Band 11k ReportWhen disabled, the controller provides neighbor list that contains only neighbor APs in the same band with which the client is associated.When enabled, the controller provides neighbor list that contains neighbor APs in both 2.4 GHz and 5 GHz bands.This feature is available only when Fast Roaming is enabled. By default, it is disabled.
Force-DisassociationWith this feature disabled, the AP only issues an 802.11v roaming suggestion when a client's link quality drops below the predefined threshold and there is a better option of AP, but whether to roam or not is determined by the client.With this feature enabled, the AP will force disassociate the client if it does not re-associate to another AP.This feature is available only when Fast Roaming is enabled. By default, it is disabled.
Band SteeringBand Steering can adjust the number of clients on 2.4 GHz and 5 GHz bands to provide better wireless experience.When enabled, dual-band clients will be steered to the 5 GHz band according to the configured parameters. With appropriate settings, Band Steering can improve the network performance because the 5 GHz band supports a larger number of non-overlapping channels and is less noisy. By default, it is disabled.Connection Threshold: Specify the maximum number of clients connected to the 5 GHz band. By default, the threshold is 30.Difference Threshold: Specify the maximum difference between the number of clients on the 5 GHz band and 2.4 GHz band. By default, the threshold is 4.When the connection number and difference of client number both exceed their configured threshold, the EAP will refuse the connection request on 5 GHz band and no longer steers other clients to the 5 GHz band.Maximum Failures: Specify the maximum number of the failed attempts when a client repeatedly tries to associate with an EAP on 5 GHz. When the number of rejections reaches Maximum Failures, the EAP will accept the client's request for connection. By default, it is 4.

Beacon Control

Beacons are transmitted periodically by the EAP to announce the presence of a wireless network for the clients. Click +, select the band, and configure the following parameters of Beacon Control.

Beacon Interval: Specify how often the APs send a beacon to clients. By default, it is 100.

DTIM Period: Specify how often the clients check for buffered data that are still on the EAP awaiting pickup. By default, the clients check for them at every beacon.

DTIM (Delivery Traffic Indication Message) is contained in some Beacon frames indicating whether the EAP has buffered data for client devices. An excessive DTIM interval may reduce the performance of multicast applications, so we recommend that you keep the default interval, 1.

RTS Threshold: RTS (Request to Send) can ensure efficient data transmission by avoiding the conflict of packets. If a client wants to send a packet larger than the threshold, the RTS mechanism will be activated to delay packets of other clients in the same wireless network.

We recommend that you keep the default threshold, which is 2347. If you specify a low threshold value, the RTS mechanism may be activated more frequently to recover the network from possible interference or collisions. However, it also consumes more bandwidth and reduces the throughput of the packet.

Fragmentation Threshold: Fragmentation can limit the size of packets transmitted over the network. If a packet to be sent exceeds the Fragmentation threshold, the Fragmentation function will be activated, and the packet will be fragmented into several packets. By default, the threshold is 2346.

Fragmentation helps improve network performance if properly configured. However, too low fragmentation threshold may result in poor wireless performance because of the increased message traffic and the extra work of dividing up and reassembling frames.

Airtime Fairness: With this option enabled, each client connecting to the EAP can get the same amount of time to transmit data so that low-data-rate clients do not occupy too much network bandwidth and network performance improves as a whole. We recommend you enable this function under multi-rate wireless networks.

4.2.4 Device Account

You can specify a device account for all adopted devices on the site in batches. Once the devices are adopted by the controller, their username and password become the same as settings in Device Account to protect the communication between the controller and devices. By default, the username is admin and the password is generated randomly.

Go to Settings > Site and modify the username and password in Device Account. Click Save and the new username and password are applied to all devices on the site.

Device Account

Username:

Password:

●●●●●●●

TP-LINK Omada OC200 - Device Account - 1

4.3 Configure Wired Networks

Wired networks enable your wired devices and clients including the gateway, switches, EAPs and PCs to connect to each other and to the internet.

As shown in the following figure, Wired Networks consist of two parts: Internet and LAN.

Wired Networksgraph LR A["Internet"] --> B["WAN Port"] B --> C["Gateway"] C --> D["Switch C"] D --> E["Omada Controller"] D --> F["Switch A"] D --> G["Switch B"] D --> H["FTP Server"] style A fill:#99CCFF style B fill:#99CCFF style C fill:#99CCFF style D fill:#99CCFF style E fill:#99CCFF style F fill:#99CCFF styl…

For Internet, you determine the number of WAN ports on the gateway and how they connect to the internet. You can set up an IPv4 connection and IPv6 connection to your internet service provider (ISP) according to your needs. The parameters of the internet connection for the gateway depend on which connection types you use. For an IPv4 connection, the following internet connection types are available: Dynamic IP, Static IP, PPPoE, L2TP, and PPTP. For an IPv6 connection, the following internet connection types are available: Dynamic IP (SLAAC/ DHCPv6), Static IP, PPPoE, 6to4 Tunnel, and Pass-Through (Bridge). And, when more than one WAN port is configured, you can configure Load Balancing to optimize the resource utilization if needed.

For LAN, you configure the wired internal network and how your devices logically separate from or connect to each other by means of VLANs and interfaces. Advanced LAN features include IGMP Snooping, DHCP Server and DHCP Options, PoE, Voice Network, 802.1X Control, Port Isolation, Spanning Tree, LLDP-MED, and Bandwidth Control.

4.3.1 Set Up an Internet Connection

Configuration

To set up an internet connection, follow these steps:

1) Configure the number of WAN ports on the gateway based on needs. 2) Configure WAN Connections. You can set up the IPv4 connection, IPv6 connection, or both. 3) (Optional) Configure Load Balancing if more than one WAN port is configured.

Select WAN Mode Configure WAN Connections (Optional) Configure Load Balancing

Go to Settings > Wired Networks > Internet to load the following page. In WAN Mode, configure the number of WAN ports deployed by the gateway and other parameters. Then click Apply.

WAN Mode

WAN Ports:

TP-LINK Omada OC200 - WAN Mode - 1

WAN

TP-LINK Omada OC200 - WAN Mode - 2

WAN/LAN1

TP-LINK Omada OC200 - WAN Mode - 3

WAN/LAN2

TP-LINK Omada OC200 - WAN Mode - 4

WAN/LAN3

Online Detection Interval:

2 minutes

Apply

Cancel

WAN Ports

Click the check box to enable the port as a WAN port. To configure multiple WAN ports, enable the ports one by one. Note that modification of WAN ports will automatically delete the current configurations associated with the ports, and the gateway will reboot.

Online Detection Interval

Select how often the WAN ports detect WAN connection status. If you don't want to enable online detection, select Disable.

Note that Load Balancing and Link Backup will take effects based on the results of online detection. Configure a proper online detection interval to make sure that Load Balancing and Link Backup works.

Select WAN Mode

Configure WAN Connections

(Optional) Configure Load Balancing

TP-LINK Omada OC200 - Online Detection Interval - 1

Note:

The number of configurable WAN ports is decided by WAN Mode.

- Set Up IPv4 Connection

Go to Settings > Wired Networks > Internet. For WAN connections, choose a Connection Type according to the service provided by your ISP.

Connection Type

Dynamic IP: If your ISP automatically assigns the IP address and the corresponding parameters, choose Dynamic IP.

Static IP: If your ISP provides you with a fixed IP address and the corresponding parameters, choose Static IP.

PPPoE: If your ISP provides you with a PPPoE account, choose PPPoE.

L2TP: If your ISP provides you with an L2TP account, choose L2TP.

PPTP: If your ISP provides you with a PPTP account, choose PPTP.

■ Dynamic IP

  1. Choose Connection Type as Dynamic IP and configure the following parameters.

WAN IPv4 Connection Type: Dynamic IP + Advanced Settings MAC Address MAC Address: Use Default MAC Address Customize MAC Address

MAC Address

Use Default MAC Address: The WAN port uses the default MAC address to set up the internet connection. It's recommended to use the default MAC address unless required otherwise.

Customize MAC Address: The WAN port uses a customized MAC address to set up the internet connection and you need to specify the MAC address. Typically, this is required when your ISP bound the MAC address with your account or IP address. If you are not sure, contact the ISP.

  1. Click + Advanced Settings and configure the following parameters. Then click Apply.

WAN IPv4 Connection Type: Dynamic IP Advanced Settings Unicast DHCP: Enable i Primary DNS Server: . . . . (Optional) Secondary DNS Server: . . . . (Optional) Host Name: MTU: 1500 (576-1500, default:1500) VLAN: Enable (1-4086) QoS Tag: None i

Unicast DHCPWith this option enabled, the gateway will require the DHCP server to assign the IP address by sending unicast DHCP packets. Usually you need not to enable the option.
Primary DNS Server / Secondary DNS ServerEnter the IP address of the DNS server provided by your ISP if there is any.
Host Name Enter a name for the gateway.
MTU Specify the MTU (Maximum Transmission Unit) of the WAN port.MTU is the maximum data unit transmitted in the physical network. When the connection type is Dynamic IP, MTU can be set in the range of 576-1500 bytes. The default value is 1500.
VLAN Add the WAN port to a VLAN and you need to specify the VLAN. Generally, you don't need to manually configure it unless required by your ISP.
QoS TagThe QoS (Quality of Service) function helps to prioritize the internet traffic based on your needs. You can determine the priority level for the traffic by specifying the tag. The tag ranges from 1 to 7. None means the packet will be forwarded without any operation.QoS Tag is only available when VLAN is enabled.

■ Static IP

  1. Choose Connection Type as Static IP and configure the following parameters.

WAN IPv4 Connection Type: Static IP IP Address: . . . . Subnet Mask: . . . . Default Gateway: . . . (Optional) + Advanced Settings MAC Address MAC Address: Use Default MAC Address Customize MAC Address

IP Address: Enter the IP address provided by your ISP.

Subnet Mask: Enter the subnet mask provided by your ISP.

Default Gateway: Enter the default gateway provided by your ISP.

MAC Address

Use Default MAC Address: The WAN port uses the default MAC address to set up the internet connection. It's recommended to use the default MAC address unless required otherwise.

Customize MAC Address: The WAN port uses a customized MAC address to set up the internet connection and you need to specify the MAC address. Typically, this is required when your ISP bound the MAC address with your account or IP address. If you are not sure, contact the ISP.

  1. Click + Advanced Settings and configure the following parameters. Then click Apply.

WAN IPv4 Connection Type: Static IP IP Address: . . . . Subnet Mask: . . . . Default Gateway: . . . (Optional) Advanced Settings Primary DNS Server: . . . . (Optional) Secondary DNS Server: . . . . (Optional) MTU: 1500 (576-1500, default:1500) VLAN: Enable (1-4086) QoS Tag: None i

Primary DNS Server / Secondary DNS ServerEnter the IP address of the DNS server provided by your ISP if there is any.
MTU Specify the MTU (Maximum Transmission Unit) of the WAN port.MTU is the maximum data unit transmitted in the physical network. When the connection type is Static IP, MTU can be set in the range of 576-1500 bytes. The default value is 1500.
VLAN Add the WAN port to a VLAN and you need to specify the VLAN. Generally, you don't need to manually configure it unless required by your ISP.
QoS TagThe QoS (Quality of Service) function helps to prioritize the internet traffic based on your needs. You can determine the priority level for the traffic by specifying the tag. The tag ranges from 1 to 7. None means the packet will be forwarded without any operation.QoS Tag is only available when VLAN is enabled.

■ PPPoE

  1. Choose Connection Type as PPPoE and configure the following parameters.

WAN IPv4 Connection Type: PPPoE Username: Password: + Advanced Settings MAC Address MAC Address: Use Default MAC Address Customize MAC Address

Username: Enter the PPPoE username provided by your ISP.

Password: Enter the PPPoE password provided by your ISP.

MAC Address

Use Default MAC Address: The WAN port uses the default MAC address to set up the internet connection. It's recommended to use the default MAC address unless required otherwise.

Customize MAC Address: The WAN port uses a customized MAC address to set up the internet connection and you need to specify the MAC address. Typically, this is required when your ISP bound the MAC address with your account or IP address. If you are not sure, contact the ISP.

  1. Click + Advanced Settings and configure the following parameters. Then click Apply.

WAN IPv4 Connection Type: PPPoE Username: Password: Advanced Settings Get IP address from ISP: Enable IP Address: . . . . Primary DNS Server: . . . (Optional) Secondary DNS Server: . . . (Optional) Connection Mode: Connect Automatically Connect Manually Time-based Redial Interval: 10 Seconds (1-9999…

Get IP address from ISPWith this option enabled, the gateway gets IP address from ISP when setting up the WAN connection.With this option disabled, you need to specify theIP Addressprovided by your ISP.
Primary DNS Server / Secondary DNS ServerEnter the IP address of the DNS server provided by your ISP if there is any.
Connection ModeConnect Automatically: The gateway activates the connection automatically when the connection is down. You need to specify theRedial Interval, which decides how often the gateway tries to redial after the connection is down.Connect Manually: You can manually activate or terminate the connection.Time-Based: During the specified period, the gateway will automatically activate the connection. You need to specify theTime Rangewhen the connection is up.
Service Name Keep it blank unless your ISP requires you to configure it.
MTU Specify the MTU (Maximum Transmission Unit) of the WAN port.MTU is the maximum data unit transmitted in the physical network. When the connection type is PPPoE, MTU can be set in the range of 576-1492 bytes. The default value is 1492.
VLAN Add the WAN port to a VLAN and you need to specify the VLAN. Generally, you don't need to manually configure it unless required by your ISP.
QoS TagThe QoS (Quality of Service) function helps to prioritize the internet traffic based on your needs. You can determine the priority level for the traffic by specifying the tag. The tag ranges from 1 to 7. None means the packet will be forwarded without any operation.QoS Tag is only available when VLAN is enabled.
Secondary ConnectionSecondary connection is required by some ISPs. Select the connection type required by your ISP.None: Select this if the secondary connection is not required by your ISP.Static IP: Select this if your ISP provides you with a fixed IP address and subnet mask for the secondary connection. You need to specify theIP Addressand Subnet Maskprovided by your ISP.Dynamic IP: Select this if your ISP automatically assigns the IP address and subnet mask for the secondary connection.

L2TP

Choose Connection Type as L2TP and configure the following parameters. Then click Apply.

WAN IPv4 Connection Type: L2TP Username: Password: VPN Server/Domain Name: Get IP address from ISP: Enable Primary DNS Server: . . . (Optional) Secondary DNS Server: . . . (Optional) Connection Mode: Connect Automatically Connect Manually Time-based Redial Interval: 10 Seconds (1-99999) MTU: 1460 (5…

Username: Enter the L2TP username provided by your ISP.

Password: Enter the L2TP password provided by your ISP.

VPN Server / Domain Name Enter the VPN Server/Domain Name provided by your ISP.
Get IP address from ISPWith this option enabled, the gateway gets IP address from ISP when setting up the WAN connection.With this option disabled, you need to specify theIP addressprovided by your ISP.
Primary DNS Server / Secondary DNS ServerEnter the IP address of the DNS server provided by your ISP if there is any.
Connection Mode Connect Automatically: The gateway activates the connection automatically when the connection is down. You need to specify theRedial Interval, which decides how often the gateway tries to redial after the connection is down.Connect Manually: You can manually activate or terminate the connection.Time-Based: During the specified period, the gateway will automatically activate the connection. You need to specify theTime Rangewhen the connection is up.
MTU Specify the MTU (Maximum Transmission Unit) of the WAN port.MTU is the maximum data unit transmitted in the physical network. When the connection type is L2TP, MTU can be set in the range of 576-1460 bytes. The default value is 1460.
VLAN Add the WAN port to a VLAN and you need to specify the VLAN. Generally, you don't need to manually configure it unless required by your ISP.
QoS TagThe QoS (Quality of Service) function helps to prioritize the internet traffic based on your needs. You can determine the priority level for the traffic by specifying the tag. The tag ranges from 1 to 7. None means the packet will be forwarded without any operation.QoS Tag is only available when VLAN is enabled.
Secondary Connection Select the connection type required by your ISP.Static IP: Select this if your ISP provides you with a fixed IP address and subnet mask for the secondary connection. You need to specify theIP Address, Subnet Mask, Default Gateway (Optional), Primary DNS Server (Optional), and Secondary DNS Server (Optional) provided by your ISP.Dynamic IP: Select this if your ISP automatically assigns the IP address and subnet mask for the secondary connection.
MAC AddressUse Default MAC Address: The WAN port uses the default MAC address to set up the internet connection. It's recommended to use the default MAC address unless required otherwise.Customize MAC Address: The WAN port uses a customized MAC address to set up the internet connection and you need to specify the MAC address. Typically, this is required when your ISP bound the MAC address with your account or IP address. If you are not sure, contact the ISP.

■ PPTP

Choose Connection Type as PPTP and configure the following parameters. Then click Apply.

WAN IPv4 Connection Type: PPTP Username: Password: VPN Server/Domain Name: Get IP address from ISP: Enable Primary DNS Server: . . . (Optional) Secondary DNS Server: . . . (Optional) Connection Mode: Connect Automatically Connect Manually Time-based Redial Interval: 10 Seconds (1-99999) MTU: 1420 (5…

Username: Enter the PPTP username provided by your ISP.

Password: Enter the PPTP password provided by your ISP.

VPN Server / Domain Name: Enter the VPN Server/Domain Name provided by your ISP.

Get IP address from ISP

With this option enabled, the gateway obtains its IP address from the ISP when establishing the WAN connection.

With this option disabled, you must specify the IP address provided by your ISP.

Primary DNS Server / Secondary DNS Server

Enter the IP address of the DNS server provided by your ISP, if applicable.

Connection Mode Connect Automatically: The gateway activates the connection automatically when the connection is down. You need to specify the Redial Interval, which decides how often the gateway tries to redial after the connection is down.
Connect Manually: You can manually activate or terminate the connection.
Time-Based: During the specified period, the gateway will automatically activate the connection. You need to specify the Time Range when the connection is up.
MTU Specify the MTU (Maximum Transmission Unit) of the WAN port.
MTU is the maximum data unit transmitted in the physical network. When the connection type is PPTP, MTU can be set in the range of 576-1420 bytes. The default value is 1420.
VLAN Add the WAN port to a VLAN and you need to specify the VLAN. Generally, you don't need to manually configure it unless required by your ISP.
QoS TagThe QoS (Quality of Service) function helps to prioritize the internet traffic based on your needs. You can determine the priority level for the traffic by specifying the tag. The tag ranges from 1 to 7. None means the packet will be forwarded without any operation.
QoS Tag is only available when VLAN is enabled.
Secondary Connection Select the connection type required by your ISP.
Static IP: Select this if your ISP provides you with a fixed IP address and subnet mask for the secondary connection. You need to specify the IP Address, Subnet Mask, Default Gateway (Optional), Primary DNS Server (Optional), and Secondary DNS Server (Optional) provided by your ISP.
Dynamic IP: Select this if your ISP automatically assigns the IP address and subnet mask for the secondary connection.

MAC Address

Use Default MAC Address: The WAN port uses the default MAC address to establish the internet connection. It is recommended to use the default MAC address unless otherwise required.

Customize MAC Address: The WAN port uses a customized MAC address to establish the internet connection, and you must specify the MAC address. This is typically required when your ISP has bound the MAC address to your account or IP address. If you are unsure, contact your ISP.

- Set Up IPv6 Connection

For IPv6 connections, check the box to enable the IPv6 connection, then select the internet connection type according to your ISP's requirements.

Connection Type

Dynamic IP (SLAAC/DHCPv6): If your ISP uses dynamic IPv6 address assignment, either DHCPv6 or SLAAC+Stateless DHCP, select Dynamic IP (SLAAC/DHCPv6).

Static IP: If your ISP provides you with a fixed IPv6 address, select Static IP.

PPPoE: If your ISP uses PPPoEv6 and provides a username and password, select PPPoE.

6to4 Tunnel: If your ISP uses 6to4 deployment for assigning IPv6 addresses, select 6to4 Tunnel. 6to4 is an internet transition mechanism for migrating from IPv4 to IPv6, a system that allows IPv6 packets to be transmitted over an IPv4 network. The IPv6 packet is encapsulated in an IPv4 packet and transmitted to the IPv6 destination through the IPv4 network.

Pass-Through (Bridge): In Pass-Through (Bridge) mode, the gateway works as a transparent bridge. The IPv6 packets received from the WAN port will be transparently forwarded to the LAN port and vice versa. No extra parameter is required.

■ Dynamic IP (SLAAC/DHCPv6)

Choose Connection Type as Dynamic IP (SLAAC/DHCPv6) and configure the following parameters. Then click Apply.

IPv6 IPv6: Enable Connection Type: Dynamic IP (SLAAC/DHCPv6) Get IPv6 Address: Automatically Via SLAAC Via DHCPv6 Prefix Delegation: Enable Prefix Delegation Size: (48-64) DNS Address: Get from ISP Dynamically Use the Following DNS Addresses

Get IPv6 AddressSelect the proper method whereby your ISP assigns IPv6 address to your gateway.Automatically: With this option selected, the gateway will automatically select SLAAC or DHCPv6 to get IPv6 addresses.Via SLAAC: With SLAAC (Stateless Address Auto-Configuration) selected, your ISP assigns the IPv6 address prefix to the gateway and the gateway automatically generates its own IPv6 address. Also, your ISP assigns other parameters including the DNS server address to the gateway.Via DHCPv6: With DHCPv6 selected, your ISP assigns an IPv6 address and other parameters including the DNS server address to the gateway using DHCPv6.
Prefix DelegationSelect Enable to get an address prefix by DHCPv6 server from your ISP, or Disable to designate an address prefix for your LAN port manually. Clients in LAN will get an IPv6 address with this prefix.
Prefix Delegation SizeWith Prefix Delegation enabled, enter the Prefix Delegation Size to determine the length of the address prefix. If you are not sure about the value, you can ask your ISP.
DNS AddressSelect whether to get the DNS address dynamically from your ISP or designate the DNS address manually.Get from ISP Dynamically: The DNS address will be automatically assigned by the ISP.Use the Following DNS Addresses: Enter the DNS address provided by the ISP.

■ Static IP

Choose Connection Type as Static IP and configure the following parameters. Then click Apply.

IPv6 IPv6: Enable Connection Type: Static IP IPv6 Address: (Format: 2001::) Prefix Length: (1-128) Default Gateway: (Format: 2001::) Primary DNS Server: (Format: 2001::) Secondary DNS Server: (Optional. Format: 2001::)

IPv6 Address: Enter the static IPv6 address information received from your ISP.

Prefix Length: Enter the prefix length of the IPv6 address received from your ISP.

Default Gateway: Enter the default gateway provided by your ISP.

Primary DNS Server: Enter the IP address of the primary DNS server provided by your ISP.

Secondary DNS Server (Optional): Enter the IP address of the secondary DNS server, which provides redundancy in case the primary DNS server goes down.

■ PPPoE

Choose Connection Type as PPPoE and configure the following parameters. Then click Apply.

IPv6 IPv6: Enable Connection Type: PPPoE Share the same PPPoE session with IPv4 Username: Password: Get IPv6 Address: Automatically Via SLAAC Via DHCPv6 Specified by ISP Prefix Delegation: Enable Prefix Delegation Size: (48-64) DNS Address: Get from ISP Dynamically Use the Following DNS Addresses

Share the same PPPoE session with IPv4

If your ISP provides only one PPPoE account for both IPv4 and IPv6 connections, and you have already established an IPv4 connection on this WAN port, you can check the box, then the WAN port will use the PPP session of IPv4 PPPoE connection to get the IPv6 address. In this case, you do not need to enter the username and password of the PPPoE account. If your ISP provides two separate PPPoE accounts for the IPv4 and IPv6 connections, or the IPv4 connection of this WAN port is not based on PPPoE, do not check the box and manually enter the username and password for the IPv6 connection.

Username: Enter the username of your PPPoE account provided by your ISP.

Password Enter the password of your PPPoE account provided by your ISP.

Get IPv6 AddressSelect the proper method whereby your ISP assigns IPv6 address to your gateway.Automatically: With this option selected, the gateway will automatically select the method to get IPv6 addresses between SLAAC and DHCPv6.Via SLAAC: With SLAAC (Stateless Address Auto-Configuration) selected, your ISP assigns the IPv6 address prefix to the gateway and the gateway automatically generates its own IPv6 address. Also, your ISP assigns other parameters including the DNS server address to the gateway.Via DHCPv6: With DHCPv6 selected, your ISP assigns an IPv6 address and other parameters including the DNS server address to the gateway using DHCPv6.Specified by ISP: With this option selected, enter the IPv6 address you get from your ISP.
Prefix DelegationSelect Enable to get an address prefix by DHCPv6 server from your ISP, or Disable to designate an address prefix for your LAN port manually. Clients in LAN will get an IPv6 address with this prefix.
Prefix Delegation SizeWith Prefix Delegation enabled, enter the Prefix Delegation Size to determine the length of the address prefix. If you are not sure about the value, you can ask your ISP.
DNS AddressSelect whether to get the DNS address dynamically from your ISP or designate the DNS address manually.Get from ISP Dynamically: The DNS address will be automatically assigned by the ISP.Use the Following DNS Addresses: Enter the DNS address provided by the ISP.

■ 6to4 Tunnel

Choose Connection Type as 6to4 Tunnel and configure the following parameters. Then click Apply.

IPv6 IPv6: Enable Connection Type: 6to4 Tunnel DNS Address: Get from ISP Dynamically Use the Following DNS Addresses

DNS Address

Select whether to get the DNS address dynamically from your ISP or designate the DNS address manually.

Get from ISP Dynamically: The DNS address will be automatically assigned by the ISP.

Use the Following DNS Addresses: Enter the DNS address provided by the ISP.

■ Pass-Through (Bridge)

Choose Connection Type as Pass-Through (Bridge) and no configuration is required for this type of connection. Then click Apply.

IPv6 IPv6: Enable Connection Type: Pass-Through (Bridge)

Select WAN Mode Configure WAN Connections (Optional) Configure Load Balancing

Note:

Load Balancing is only available when you configure more than one WAN port.

Go to Settings > Wired Networks > Internet to load the following page. In Load Balancing, configure the following parameters and click Apply.

Load Balancing

Load Balancing Weight:

1

1

Pre-Populate

Application Optimized Routing:

TP-LINK Omada OC200 - Load Balancing - 1

Enable

TP-LINK Omada OC200 - Load Balancing - 2

Link Backup:

TP-LINK Omada OC200 - Load Balancing - 3

Enable

Backup WAN:

Please Select...

TP-LINK Omada OC200 - Load Balancing - 4

Primary WAN:

Please Select...

TP-LINK Omada OC200 - Load Balancing - 5

Backup Mode:

TP-LINK Omada OC200 - Load Balancing - 6

Link Backup

TP-LINK Omada OC200 - Load Balancing - 7

TP-LINK Omada OC200 - Load Balancing - 8

Always Link Primary

TP-LINK Omada OC200 - Load Balancing - 9

Mode:

TP-LINK Omada OC200 - Load Balancing - 10

Enable backup link when any primary WAN fails

TP-LINK Omada OC200 - Load Balancing - 11

Enable backup link when all primary WANs fail

Load Balancing Weight Specify the ratio of network traffic that each WAN port carries.

Alternatively, you can click Pre-Populate to test the speed of WAN ports and automatically fill in the appropriate ratio according to test result.
Application Optimized RoutingWith Application Optimized Routing enabled, the router will consider the source IP address and destination IP address (or destination port) of the packets as a whole and record the WAN port they pass through. Then the packets with the same source IP address and destination IP address ( or destination port) will be forwarded to the recorded WAN port.This feature ensures that multi-connected applications work properly.
Link BackupWith Link Backup enabled, the router will switch all the new sessions from dropped lines automatically to another to keep an always on-line network.
Backup WAN / Primary WANThe backup WAN port backs up the traffic for the primary WAN ports under the specified condition.
Backup ModeLink Backup: The system will switch all the new sessions from dropped line automatically to another to keep an always on-link network.Always Link Primary: Traffic is always forwarded through the primary WAN port unless it fails. The system will try to forward the traffic via the backup WAN port when it fails, and switch back when it recovers.

Mode Select whether to enable backup link when any primary WAN fails or all primary WANs fail.

4.3.2 Configure LAN Networks

Overview

The LAN function allows you to configure wired internal network. Based on 802.1Q VLAN, Omada Controller provides a convenient and flexible way to separate and deploy the network. The network can be logically segmented by departments, application, or types of users, without regard to geographic locations.

Configuration

To create a LAN, follow the guidelines:

1) Create a Network with specific purpose. For Layer 2 isolation, create a network as VLAN. To realize inter-VLAN routing, create a network as Interface, which is configured with a VLAN interface. 2) Create a port profile for the network. The profile defines how the packets in both ingress and egress directions are handled. 3) Assign the port profile to the desired ports of the switch to activate the LAN.

Create a Network Create a Port Profile Assign the Port Profile to the Ports

① Note:

A default Network (default VLAN) named LAN is preconfigured as Interface and is associated with all LAN ports of the Omada Gateway and all switch ports. The VLAN ID of the default Network is 1. The default Network can be edited, but not deleted.

  1. Go to Settings > Wired Networks > LAN > Networks to load the following page.

NAME PURPOSE SUBNET PORTAL ACCESS CONTROL RULE RATE LIMIT VLAN ACTION LAN Interface 192.168.0.1/24 1 Showing 1:1 of 1 records < 1 > 16 /page Go To page: 50 + Create New LAN

  1. Click + Create New LAN to load the following page, enter a name to identify the network, and select the purpose for the network.

Create New LAN Name: Purpose: Interface VLAN

Purpose

Interface: Create the network with a Layer 3 interface, which is required for inter-VLAN routing.

VLAN: Create the network as a Layer 2 VLAN.

  1. Configure the parameters according to the purpose for the network.

■ Interface

Create New LAN Name: Purpose: Interface VLAN LAN Interfaces: WAN/LAN1 WAN/LAN2 LAN1 LAN2 VLAN: (1-4090) Gateway/Subnet: . . . / Domain Name: (Optional) IGMP Snooping: Enable DHCP Server: Enable DHCP Range: . . . . DNS Server: Auto Manual Lease Time: 120 minutes (2-2880) Default Gateway: Auto Manual…

LAN Interface

Select the physical interfaces of the Omada Gateway that this network will be associated with.

VLAN Enter a VLAN ID with the values between 1 and 4090. Each VLAN can be uniquely identified by VLAN ID, which is transmitted and received as IEEE 802.1Q tag in an Ethernet frame.
Gateway/SubnetEnter the IP address and subnet mask in the CIDR format. The CIDR Notation here includes the IP address and subnet mask of the default gateway. The summary of the information that you entered will show up below in realtime.
Domain Name Enter the domain name.
IGMP SnoopingClick the checkbox to monitor IGMP (Internet Group Management Protocol) traffic and thereby manage multicast traffic.
DHCP ServerClick the checkbox to allow the Omada Gateway to serve as the DHCP server for this network. A DHCP server assigns IP addresses, DNS server, default gateway, and other parameters to all devices in the network. Uncheck the box if there is already a DHCP server in the network.
DHCP RangeEnter the starting and ending IP addresses of the DHCP address pool in the fields provided. For quick operation, click theUpdate DHCP Rangebeside theGateway/Subnetentry to get the IP address range populated automatically, and edit the range according to your needs.
DNS Server Select a method to configure the DNS server for the network.
Auto: The DHCP server automatically assigns DNS server for devices in the network. It uses the IP address specified in theGateway/Subnetentry as the DNS server address.
Manual: Specify DNS servers manually. Enter the IP address of a server in each DNS server field.
Lease Time Specify how long a client can use the IP address assigned from this address pool.
Default Gateway Enter the IP address of the default gateway.
Auto: The DHCP server automatically assigns default gateway for devices in the network. It uses the IP address specified in the Gateway/Subnet entry as the default gateway address.
Manual: Specify default gateway manually. Enter the IP address of the default gateway in the field.
DHCP Omada ControllerEnter the IP address of the Omada Controller. The DHCP server uses this IP address as Option 138 in DHCP packets to tell clients where the controller is.
Legal DHCP ServersClick the checkbox to specify legal DHCP servers for the network. With legal DHCP servers configured, Omada Gateways and Switches ensure that clients get IP addresses only from the DHCP servers specified here.
Option 60Enter the value for DHCP Option 60. DHCP clients use this field to optionally identify the vendor type and configuration of a DHCP client. Mostly it is used in the scenario where the APs apply for different IP addresses from different servers according to the needs.
Option 66Enter the value for DHCP Option 66. It specifies the TFTP server information and supports a single TFTP server IP address.

Option 138

Enter the value for DHCP Option 138. It is used in discovering the devices by the Omada controller.

You can configure IPv6 connections for the LAN clients based on your needs. First, determine the method whereby the gateway assigns IPv6 addresses to the clients in the local network. Some clients may support only a few of these connection types, so you should choose it according to the compatibility of clients in the local network.

TP-LINK Omada OC200 - ■ Interface - 2

Configure IPv6

IPv6 Interface Type:

Gateway/Subnet:

DHCP Range:

Lease Time:

DHCPv6 DNS:

DHCPv6 1440 minutes (1-11520) Auto Manual

TP-LINK Omada OC200 - Configure IPv6 - 2

Auto

TP-LINK Omada OC200 - Configure IPv6 - 3

Manual

IPv6 Interface Type

Configure the type of assigning IPv6 address to the clients in the local network.

None: IPv6 connection is not enabled for the clients in the local network.

DHCPv6: The gateway assigns an IPv6 address and other parameters including the DNS server address to each client using DHCPv6.

SLAAC+Stateless DHCP: The gateway assigns the IPv6 address prefix to each client and the client automatically generates its own IPv6 address. Also, the gateway assigns other parameters including the DNS server address to each client using DHCPv6.

SLAAC+RDNSS: The gateway assigns the IPv6 address prefix to each client and the client automatically generates its own IPv6 address. Also, the gateway assigns other parameters including the DNS server address to each client using the RDNSS option in RA (Router Advertisement).

Pass-Through: Select this type if the WAN ports of the gateway use the Pass-Through for IPv6 connections.

With DHCPv6 selected, configure the following parameters.

Gateway/Subnet

Enter the IP address and subnet mask in the CIDR format. The CIDR notation here includes the IP address and subnet mask of the default gateway. The summary of the information that you entered will show up below in real time.

DHCP Range

Enter the starting and ending IP addresses of the DHCP address pool in the fields provided. For quick operation, click the Update DHCP Range beside the Gateway/Subnet entry to get the IP address range populated automatically, and edit the range according to your needs.

Lease TimeThis entry determines how long the assigned IPv6 address remains valid. Either keep the default 1440 minutes or change it if required by your ISP.
DHCPv6 DNSSelect a method to configure the DNS server for the network. With Auto selected, the DHCP server automatically assigns DNS server for devices in the network. With Manual selected, enter the IP address of a server in each DNS server field.
With SLAAC+Stateless DHCP selected, configure the following parameters.
Prefix Configure the IPv6 address prefix for each client in the local network.Manual Prefix: With Manual Prefix selected, enter the prefix in the Address Prefix field.Get from Prefix Delegation: With Get from Prefix Delegation selected, select the WAN port with Prefix Delegation configured, and the clients will get the address prefix from the Prefix Delegation.
IPv6 Prefix IDWith Get from Prefix Delegation selected, enter the Prefix ID, which will be added to the prefix to obtain a /64 subnet.The range of IPv6 Prefix ID is determined by the larger value of Prefix Delegation Size and Prefix Delegation Length (obtained from the ISP). Note that if the Prefix Delegation Length is larger than 64, the IPv6 Prefix ID cannot be obtained from Prefix Delegation, please select another method. Go to Settings > Wired Network > Internet to configure Prefix Delegation Size.
DNS Server Select a method to configure the DNS server for the network.Auto: With Auto selected, the DHCP server automatically assigns DNS server for devices in the network.Manual: With Manual selected, enter the IP address of a server in each DNS server field.
With SLAAC+RDNSS selected, configure the following parameters.
Prefix Configure the IPv6 address prefix for each client in the local network.Manual Prefix: With Manual Prefix selected, enter the prefix in the Address Prefix field.Get from Prefix Delegation: With Get from Prefix Delegation selected, select the WAN port with Prefix Delegation configured, and the clients will get the address prefix from the Prefix Delegation.
IPv6 Prefix IDWith Get from Prefix Delegation selected, enter the Prefix ID, which will be added to the prefix to obtain a /64 subnet.
DNS Server Select a method to configure the DNS server for the network.Auto: With Auto selected, the DHCP server automatically assigns DNS server for devices in the network.Manual: With Manual selected, enter the IP address of a server in each DNS server field.
With Pass-Through selected, configure the following parameters.

IPv6 Prefix Delegation: Select the WAN port using Pass-Through (Bridge) for the IPv6 connection. Interface

Create New LAN Name: Purpose: Interface VLAN VLAN: (1-4090) IGMP Snooping: Enable Legal DHCP Servers: Enable . . . . . . . . . . Save Cancel

VLAN Enter a VLAN ID with the values between 1 and 4090. Each VLAN can be uniquely identified by VLAN ID, which is transmitted and received as IEEE 802.1Q tag in an Ethernet frame.
IGMP SnoopingClick the checkbox to monitor IGMP (Internet Group Management Protocol) traffic and thereby manage multicast traffic.
Legal DHCP ServersClick the checkbox to specify legal DHCP servers for the network. With legal DHCP servers configured, Omada Gateways and Switches ensure that clients get IP addresses only from the DHCP servers specified here.
  1. Click Save. The new LAN is added to the LAN list. You can click ☑ in the ACTION column to edit the LAN. You can click 🔒 in the ACTION column to delete the LAN.

NAME PURPOSE SUBNET PORTAL ACCESS CONTROL RULE RATE LIMIT VLAN ACTION LAN Interface 192.158.0-1/24 1 tp link VLAN 16 Showing 1-2 of 2 records < 1 > 10 /page Go to page: GO + Create New LAN

Create a Network

Create a Port Profile

Assign the Port Profile to the Ports

TP-LINK Omada OC200 - Assign the Port Profile to the Ports - 1

Note:

- Three default port profiles are preconfigured on the controller. They can be viewed, but not edited or deleted.

All: In the All profile, all networks except the default network (LAN) are configured as Tagged Network, and the native network is the default network (LAN). This profile is assigned to all switch ports by default.

Disable: In the Disable profile, no networks are configured as the native network, Tagged Networks, or Untagged Networks. With this profile assigned to a port, the port does not belong to any VLAN.

LAN: In the LAN profile, the native network is the default network (LAN), and no networks are configured as Tagged Networks or Untagged Networks.

- When a network is created, the system will automatically create a profile with the same name and configure the network as the native network for the profile. In this profile, the network itself is configured as the Untagged Networks, while no networks are configured as Tagged Networks. The profile can be viewed and deleted, but not edited.

1. Go to Wired Networks > LAN > Profiles to load the following page.

NAME PoE NATIVE NETWORK ISOLATION STORM CONTROL ACTION AI Keep the Device's Settings LAN Off Disable Keep the Device's Settings None Off LAN Keep the Device's Settings LAN Off Showing 1-3 of 3 records < 1 > 10 /page Go to page: GO + Create New Port Profile

  1. Click + Create New Port Profile to load the following page, and configure the following parameters.

Create New Port Profile NAME: PoE: Keep the Device's Settings Enable Disable Networks/VLANs Native Network: LAN Tagged Networks: All LAN Support PE VLAN Product VLAN Operation VLAN admin R&D Marketing Untagged Networks: All LAN Support PE VLAN Product VLAN Operation VLAN admin R&D Marketing Voice Ne…

Name: Enter a name to identify the port profile.

PoE: Select the PoE mode for the ports.

Keep the Device's Settings: PoE remains enabled or disabled according to the switches' settings. By default, the switches enable PoE on all PoE ports.

Enable: Enables PoE on PoE ports.

Disable: Disables PoE on PoE ports.

Native NetworkSelect the native network from all networks. The native network determines the Port VLAN Identifier (PVID) for switch ports. When a port receives an untagged frame, the switch inserts a VLAN tag to the frame based on the PVID, and forwards the frame in the native network. Each physical switch port can have multiple networks attached, but only one of them can be native.
Tagged NetworksSelect the Tagged Networks. Frames sent out of a Tagged Network are kept with VLAN tags. Usually networks that connect the switch to network devices like routers and other swithes, or VoIP devices like IP phones should be configured as Tagged Networks.
Untagged NetworksSelect the Untagged Networks. Frames that sent out of an Untagged Network are stripped of VLAN tags. Usually networks that connect the switch to endpoint devices like computers should be configured as Untagged Networks. Note that the native network is untagged.
Voice NetworkSelect the network that connects VoIP devices like IP phones as the Voice Network. Omada Switches will prioritize the voice traffic by changing its 802.1p priority. To configure a network as Voice Network, configure it as Tagged Network first, and then enable LLDP-MED. Only tagged networks can be configured as Voice Network, and Voice Network will take effect with LLDP-MED enabled.
802.1X ControlSelect 802.1X Control mode for the ports. To configure the 802.1X authentication globally, go to Settings > Authentication > 802.1X.Auto:The port is unauthorized until the client is authenticated by the authentication server successfully.Force Authorized:The port remains in the authorized state, sends and receives normal traffic without 802.1X authentication of the client.Force Unauthorized:The port remains in the unauthorized state, ignoring all attempts by the client to authenticate. The switch cannot provide authentication services to the client through the port.
Port IsolationClick the checkbox to enable Port Isolation. An isolated port cannot communicate directly with any other isolated ports, while the isolated port can send and receive traffic to non-isolated ports.
Loopback ControlChoose the method for loopback control, which helps ensure that you do not create loops when you have redundant paths in the network.Off: Disable loopback control on the port.Loopback Detection: Select loopback detection and it helps prevent loops on the port. It is used to detect loops that occur on a specific port. When a loop is detected on a port, the switch will block the corresponding port.Spanning Tree: Select STP (Spanning Tree Protocol) to prevent loops in the network. STP helps block specific ports of the switches to build a loop-free topology and detect topology changes and automatically generate a new loop-free topology.If you want to enable Spanning Tree for the switch, you also need to select the Spanning Tree protocol in the Device Config page. For details, refer to6.3 Configure and Monitor Switches.
LLDP-MED Click the checkbox to enable LLDP-MED (Link Layer Discovery Protocol-Media Endpoint Discovery) for device discovery and auto-configuration of VoIP devices.
Bandwidth ControlSelect the type of Bandwidth Control functions to control the traffic rate and traffic threshold on each port to ensure network performance.Off: Disable Bandwidth Control for the port.Rate Limit: Select Rate limit to limit the ingress/egress traffic rate on each port. With this function, the network bandwidth can be reasonably distributed and utilized.Storm Control: Select Storm Control to allow the switch to monitor broadcast frames, multicast frames and UL-frames (Unknown unicast frames) in the network. If the transmission rate of the frames exceeds the set rate, the frames will be automatically discarded to avoid network broadcast storm.
Ingress Rate LimitWhen Rate Limit selected, click the checkbox and specify the upper rate limit for receiving packets on the port.
Egress Rate LimitWhen Rate Limit selected, click the checkbox and specify the upper rate limit for sending packets on the port.
Broadcast ThresholdWhen Storm Control selected, click the checkbox and specify the upper rate limit for receiving broadcast frames. The broadcast traffic exceeding the limit will be processed according to the Action configurations.
Multicast ThresholdWhen Storm Control selected, click the checkbox and specify the upper rate limit for receiving multicast frames. The multicast traffic exceeding the limit will be processed according to the Action configurations.
UL-Frame ThresholdWhen Storm Control selected, click the checkbox and specify the upper rate limit for receiving unknown unicast frames. The traffic exceeding the limit will be processed according to the Action configurations..
ActionWhen Storm Control selected, select the action that the switch will take when the traffic exceeds its corresponding limit. With Drop selected, the port will drop the subsequent frames when the traffic exceeds the limit. With Shutdown selected, the port will be shutdown when the traffic exceeds the limit.
  1. Click Save. The new port profile is added to the profile list. You can click ☑ in the ACTION column to edit the port profile. You can click 🔒 in the ACTION column to delete the port profile.
NAMEPoENATIVE NETWORKISOLATIONSTORM CONTROLACTION
AllKeep the Deviké's SettingsLANOff
DisableKeep the Deviké's SettingsNoneOff
LANKeep the Deviké's SettingsLANOff
tp-linkKeep the Deviké's SettingsLANOff

Create a Network Create a Port Profile Assign the Port Profile to the Ports

TP-LINK Omada OC200 - Create a Network Create a Port Profile Assign the Port Profile to the Ports - 1

Note:

By default, there is a port profile named All, which is assigned to all switch ports by default. In the All profile, all networks except the default network (LAN) are configured as Tagged Network, and the native network is the default network (LAN).

  1. Go to Devices, and click the switch in the devices list to reveal the Properties window. Go to Ports, you can either click ☑ in the Action column to assign the port profile to a single port, or select the desired ports and click Edit Selected on the top to assign the port profile to multiple ports in batch.

Port LAG Edit Selected Name Status Profile ACTION 1 Port1 All ✓ 2 Port2 FAE ✓ 3 Port3 All ✓ 4 Port4 All ✓ 5 Port5 All ✓

  1. Select the profile from the drop-down list to assign the port profile to the desired ports of the switch. You can enable profile overrides to customize the settings for the ports, and all the configuration here overrides the port profile. For details, refer to Chapter 6. Configure and Monitor Omada Managed Devices.

Edit Port1 Name: Port1 Profile: All Manage Profiles Profile Overrides Apply Cancel

4.4 Configure Wireless Networks

Wireless networks enable your wireless clients to access the internet. Once you set up a wireless network, your EAPs typically broadcast the network name (SSID) in the air, through which your wireless clients connect to the wireless network and access the internet.

A WLAN group is a combination of wireless networks. Configure each group so that you can flexibly apply these groups of wireless networks to different EAPs according to your needs.

After setting up basic wireless networks, you can further configure WLAN Schedule, 802.11 Rate Control, and MAC Filter among other advanced settings.

4.4.1 Set Up Basic Wireless Networks

Configuration

To create, configure and apply wireless networks, follow these steps:

1) Create a WLAN group. 2) Create Wireless Networks 3) Apply the WLAN group to your EAPs

Create a WLAN Group

the Wireless Networks Apply the WLAN Group

Note:

By default, there is a WLAN group named Default, which is applied to all EAPs. If you simply want to configure wireless networks for the default WLAN group and apply it to all your EAPs, skip this step.

  1. Go to Settings > Wireless Networks to load the following page.

WLAN Group: Default SSID NAME SECURITY BAND GUEST NETWORK Portal ACCESS CONTROL RULE RATE LIMIT VLAN ACTION No wireless networks yet + Create New Wireless Network

  1. Select + Create New Group from the drop-down list of WLAN Group to load the following page. Enter a name to identify the WLAN group.

Add New WLAN Group Name: Copy WLANs: Copy All SSIDs from the WLAN Group Default Save Cancel

  1. (Optional) If you want to create a new WLAN group based on an existing one, check Copy All SSIDs from the WLAN Group and select the desired WLAN group. Then you can further configure wireless networks based on current settings.

Add New WLAN Group Name: test Copy WLANs: ✓ Copy All SSIDs from the WLAN Group Default Default Default tp-link Save Cancel

  1. Click Save. The new WLAN Group is added to the WLAN Group list. You can select a WLAN Group from the list to further create and configure its wireless networks. You can click ☑ to edit the name of the WLAN Group. You can click 🔒 to delete the WLAN Group.

WLAN Group: test SSID NAME Default test tp-Ink + Create New Group BAND GUEST NETWORK Portal ACCESS CONTROL RULE RATE LIMIT VLAN ACTION No wiret + Create

Create a WLAN Group Create Wireless Networks Apply the WLAN Group

  1. Select the WLAN group for which you want to configure wireless networks from the drop-down list of WLAN Group.

WLAN Group: Default SSID NAME SECURITY BAND GUEST NETWORK Portal ACCESS CONTROL RULE RATE LIMIT VLAN ACTION No wireless networks yet + Create New Wireless Network

  1. Click + Create New Wireless Network to load the following page. Configure the basic parameters for the network.

Create New Wireless Network Network Name (SSID): Band: 2.4GHz 5GHz Guest Network: Enable i Security: None WEP WPA-Personal WPA-Enterprise Security Key: + Advanced Settings + WLAN Schedule + 802.11 Rate Control i + MAC Filter Apply Cancel

Network Name (SSID)Enter the network name (SSID) to identify the wireless network. The users of wireless clients choose to connect to the wireless network according to the SSID, which appears on the WLAN settings page of wireless clients.
Band Enable 2.4 GHz and/or 5 GHz radio band for the wireless network.
Guest NetworkWith Guest Network enabled, all the clients connecting to the SSID are blocked from reaching any private IP subnet.
  1. Select the security strategy for the wireless network.

■ None

With None selected, the hosts can access the wireless network without authentication, which is applicable to lower security requirements.

■ WEP

Traffic is encrypted with a WEP Key, which you need to specify. WEP is not recommended because it's insecure.

Security: None WEP WPA-Personal WPA-Enterprise WEP KEY: .... Ø 1

■ WPA-Personal

Traffic is encrypted with a Security Key, which you need to specify. WPA-Personal is more secure than WEP.

Security: None WEP WPA-Personal WPA-Enterprise Security Key: ............

■ WPA-Enterprise

WPA-Enterprise requires an authentication server to authenticate wireless clients, and probably an accounting server to record the traffic statistics.

Security: None WEP WPA-Personal WPA-Enterprise RADIUS Profile: Please Select...

Select a RADIUS Profile, which records the settings of the authentication server and accounting server. You can create a RADIUS Profile by clicking + Create New Radius Profile from the drop-down list of RADIUS Profile. For details, refer to 4.9 Authentication.

Create New RADIUS Profile Name: VLAN Assignment: Enable VLAN Assignment for Wireless Network Authentication Server IP: . . . Authentication Port: 1812 (1-65535) Authentication Password: RADIUS Accounting: Enable Confirm Cancel

  1. (Optional) You can also configure 4.4.2 Advanced Settings, 4.4.3 WLAN Schedule, 4.4.4 802.11 Rate Control, and 4.4.5 MAC Filter according to your needs. Related topics are covered later in this chapter.
  2. Click Apply. The new wireless network is added to the wireless network list under the WLAN group. You can click ☑ in the ACTION column to edit the wireless network. You can click 📄 in the ACTION column to delete the wireless network.

WLAN Group: t2-link SSID NAME SECURITY BAND GUEST NETWORK Portal ACCESS CONTROL RULE RATE LIMIT VLAN ACTION wireless network 1 WPA-Personal 2.6GHz, 6GHz wireless network 2 WPA-Personal 2.6GHz, 6GHz Showing 1-2 of 2 records < 1 > Go To page: GO + Create New Wireless Network

Create a WLAN Group Create Wireless Networks Apply the WLAN Group

! Note:

By default, there is a WLAN group named Default, which is applied to all EAPs. If you simply want to configure wireless networks for the default WLAN group and apply it to all your EAPs, skip this step.

■ Apply to a Single EAP

Go to Devices, select the EAP to which you want to apply the WLAN group. In the Properties window, go to Config > WLANs, and select the WLAN group you want to apply to the EAP.

| Category | Value | | ------------------ | ----- | | b/g/n mixed 2.4G | 41% Utilized | | a/n/ac mixed 5G | 17% Utilized | | Rx Frames | Good | | Tx Frames | Good | | Interference | Good | | Free | Good | | General | ✓ | | IP Settings | ✓ | | Radios | ✓ | | WLANs | ✓ | | WLAN Group: Default | ✓ | |…

■ Apply to EAPs in batch

  1. Go to Devices, select the APs tab, click Batch Action, and then select Batch Config. Check the boxes of the EAPs to which you want to apply the WLAN group, and click Done.

Search or select tag All Gateway/Switches APs Overview Mesh Performance Config Edit Selected DEVICE NAME IP ADDRESS STATUS MODEL VERSION UPTIME CLIENTS DOWN UP CHANNEL ACTION EA-23-61-06-22-52 10.0.1.70 CONNECTED EAP225- Outdoor(EU) v1.0 2.0.0 1 days 07.54.00 0 2.11 GB 368.62 MB 11(2.4G) 36(5G) EA-2…

  1. In the Properties window, go to Config > WLANs, and select the WLAN group you want to apply to the EAP.

WLANs WLAN Group: Default

4.4.2 Advanced Settings

Go to Settings > Wireless Networks, click the checkmark in the ACTION column of the wireless network you want to configure, and click + Advanced Settings to load the following page. Configure the parameters and click Apply.

TP-LINK Omada OC200 - Advanced Settings - 1

Advanced Settings

SSID Broadcast:

VLAN:

Rate Limit:

Download Limit:

Upload Limit:

TP-LINK Omada OC200 - Advanced Settings - 1

Enable

TP-LINK Omada OC200 - Advanced Settings - 2

Enable

3

Custom

TP-LINK Omada OC200 - Advanced Settings - 3

Enable

16000

TP-LINK Omada OC200 - Advanced Settings - 4

Enable

2000

TP-LINK Omada OC200 - Advanced Settings - 5

Kbps

V

Kbps

(1-10240000)

(1-10240000)

SSID Broadcast

With SSID Broadcast enabled, EAPs broadcast the SSID (network name) in the air so that wireless clients can connect to the wireless network, which is identified by the SSID. With SSID Broadcast disabled, users of wireless clients must enter the SSID manually to connect to the wireless network.

VLAN

To set a wireless VLAN for the wireless network, enable this option and set a VLAN ID from 1 to 4094.

With this option enabled, traffic in different wireless networks is marked with different VLAN tags according to the configured VLAN IDs. Then the EAPs work together with the switches which also support 802.1Q VLAN, to distribute the traffic to different VLANs according to the VLAN tags. As a result, wireless clients in different VLANs cannot directly communicate with each other.

WEP ModeIf you select WEP as the security strategy, you can select the WEP Mode including the WEP authentication type, the WEP key format, and the WEP key length.Select the WEP authentication type.Open System: Wireless clients can pass the authentication and connect to the wireless network without any password. However, the correct password is required for data transmission.Shared Key: The correct password is required for wireless clients to pass the authentication, connect to the wireless network, and transmit data.Auto: EAPs automatically decide whether to use Open System or Shared Key in the authentication process.Select the WEP key format.ASCII: ASCII format stands for any combination of keyboard characters of the specified length.Hexadecimal: Hexadecimal format stands for any combination of hexadecimal digits (0-9, A-F) with the specified length.Select the WEP key length.64Bit: The WEP key is 10 hexadecimal digits or 5 ASCII characters.128Bit: The WEP key is 26 hexadecimal digits or 13 ASCII characters.152Bit: The WEP key is 32 hexadecimal digits or 16 ASCII characters.
WPA ModeIf you select WPA-Personal or WPA-Enterprise as the security strategy, you can select the WPA Mode including the version of WPA, and the encryption type.Select the version of WPA according to your needs.Select the encryption type. Some encryption type is only available under certain circumstances.TKIP: TKIP stands for Temporal Key Integrity Protocol.AES: AES stands for Advanced Encryption Standard. We recommend that you select AES as the encryption type for it is more secure than TKIP.Auto: EAPs automatically decide whether to use TKIP or AES in the authentication process.
Group Key Update PeriodIf you select WPA-Personal or WPA-Enterprise as the security strategy, you can specify whether and how often the security key changes. If you want the security key to change periodically, enable GIK rekeying and specify the time period.
Rate LimitYou can limit the download and upload rate of each client to balance bandwidth usage.Download Limit: Set the download rate for each client to receive the traffic.Upload Limit: Set the upload rate for each client to transmit the traffic.

4.4.3 WLAN Schedule

Overview

WLAN Schedule can turn on or off your wireless network in the specific time period as you desire.

Configuration

Go to Settings > Wireless Networks, click ☑ in the ACTION column of the wireless network which you want to configure, and click + WLAN Schedule to load the following page. Enable WLAN schedule and configure the parameters. Then click Apply.

WLAN Schedule WLAN Schedule: Enable Action: Radio on i Radio off i Time Range: Please select a Time Range entry. Manage Time Range Entries

ActionRadio On: Turn on your wireless network within the time range you set, and turn it off beyond the time range.
Radio Off: Turn off your wireless network within the time range you set, and turn it on beyond the time range.
Time RangeSelect the Time Range for the action to take effect. You can create a Time Range entry by clicking + Create New Time Range Entry from the drop-down list of Time Range. For details, refer to 4.8 Create Profiles.

4.4.4 802.11 Rate Control

Overview

Note:

802.11 Rate Control is only available for certain devices.

802.11 Rate Control can improve performance for higher-density networks by disabling lower bit rates and only allowing the higher. However, 802.11 Rate Control might make some legacy devices incompatible with your networks, and limit the range of your wireless networks.

Configuration

Go to Settings > Wireless Networks, click ☑ in the ACTION column of the wireless network which you want to configure, and click + 802.11 Rate Control to load the following page. Select 2.4 GHz and/or 5

GHz band to enable minimum data rate control according to your needs, move the slider to determine what bit rates your wireless network allows, and configure the parameters. Then click Apply.

802.11 Rate Control 2.4 GHz Data Rate Control: Enable Minimum Data Rate Control 6 Mbps 54 Mbps Lower Density Higher Density Limited range and no connectivity for 802.11b devices. Disable CCK Rates (1/2/5.5/11 Mbps) Require Clients to Use Rates at or Above the Specified Value Send Beacons at 1 Mbps 5…

Disable CCK Rates (1/2/5.5/11 Mbps)Select whether to disable CCK (Complementary Code Keying), the modulation scheme which works with 802.11b devices. Disable CCK Rates (1/2/5.5/11 Mbps) is only available for 2.4 GHz band.
Require Clients to Use Rates at or Above the Specified ValueSelect whether or not to require clients to use rates at or above the value that the slider indicates.
Send Beacons at 1 Mbps/6 MbpsSelect whether or not to send Beacons at the minimum rate of 1Mbps for 2.4 GHz band or 6Mbps for 5 GHz band.

4.4.5 MAC Filter

Overview

MAC Filter allows or blocks connections from wireless clients with specific MAC addresses.

Configuration

Go to Settings > Wireless Networks, click the checkbox in the ACTION column of the wireless network you want to configure, and click + MAC Filter to load the following page. Enable MAC Filter and configure the parameters. Then click Apply.

MAC Filter MAC Filter: Enable Policy: Allow List i Deny List i MAC Addresses List: Please select a MAC Group. Manage MAC Groups Apply Cancel

PolicyAllow List: Allow the connection of the clients whose MAC addresses are in the specified MAC Address List, while blocking others.
Deny List: Block the connection of the clients whose MAC address are in the specified MAC Addresses List, while allowing others.
MAC Address ListSelect the MAC Group which you want to allow or block according to the policy. You can create new MAC group by clicking + Create New MAC Group from the drop-down list of MAC Address List. For details, refer to 4.8 Create Profiles.

4.5 Network Security

Network Security is a portfolio of features designed to improve usability and ensure the safety of your network and data. Network security services include 4.5.1 ACL, 4.5.2 URL Filtering, 4.5.3 Attack Defense, and 4.5.4 Firewall, which implement policies and controls on multiple layers of defense in the network.

4.5.1 ACL

Overview

ACL (Access Control List) allows a network administrator to create rules to restrict access to network resources. ACL rules filter traffic based on specified criteria such as source IP addresses, destination IP addresses, and port numbers, and determine whether to forward the matched packets. These rules can be applied to specific clients or groups whose traffic passes through the gateway, switches, and EAPs.

The system filters traffic against the rules in the list sequentially. The first match determines whether the packet is accepted or dropped, and other rules are not checked after the first match. Therefore, the order of the rules is critical. By default, the rules are prioritized by their creation time. The rule created earlier is checked for a match with higher priority. To reorder the rules, select a rule and drag it to a new position. If no rules match, the device forwards the packet because of an implicit Permit All clause.

The system provides three types of ACL:

■ Gateway ACL

After Gateway ACLs are configured on the controller, they can be applied to the gateway to control traffic that is sourced from LAN ports and forwarded to the WAN ports.

You can set the Network, IP address, and port number of a packet as packet-filtering criteria in the rule.

■ Switch ACL

After Switch ACLs are configured on the controller, they can be applied to the switch to control inbound and outbound traffic through switch ports.

You can set the Network, IP address, port number and MAC address of a packet as packet-filtering criteria in the rule.

EAP ACL

After EAP ACLs are configured on the controller, they can be applied to the EAPs to control traffic in wireless networks.

You can set the Network, IP address, port number and SSID of a packet as packet-filtering criteria in the rule.

Configuration

To complete the ACL configuration, follow these steps:

1) Create an ACL with the specified type. 2) Define packet-filtering criteria of the rule, including protocols, source, and destination, and determine whether to forward the matched packets.

■ Configuring Gateway ACL

  1. Go to Settings > Network Security > ACL. On Gateway ACL tab, click + Create New Rule to load the following page.

Create New Rule Name: Policy: Deny Permit Protocols: All Rule: Source Type: Network LAN 0/1 Items Destination Type: IP Group Deny IPGroup_Any 0/1 Items + Create Apply Cancel

  1. Define packet-filtering criteria of the rule, including protocols, source, and destination, and determine whether to forward the matched packets. Refer to the following table to configure the required parameters and click Apply.

Name Enter a name to identify the ACL.

Policy Select the action to be taken when a packet matches the rule.
Permit: Forward the matched packet.
Deny: Discard the matched packet.
ProtocolsSelect one or more protocol types to which the rule applies from the drop-down list. The default is All, indicating that packets of all protocols will be matched. When you select one of TCP and UDP or both of them, you can set the IP address and port number of a packet as packet-filtering criteria in the rule.

From the Source drop-down list, choose one of these options to specify the source of the packets to which this ACL applies:

NetworkSelect the network you have created. If no networks have been created, you can select the default network (LAN), or go to Settings > Wired Networks > LAN to create one. The gateway will examine whether the packets are sourced from the selected network.
IP GroupSelect the IP Group you have created. If no IP Groups have been created, click +Create on this page or go to Settings > Profiles > Groups to create one. The gateway will examine whether the source IP address of the packet is in the IP Group.
IP-Port GroupSelect the IP-Port Group you have created. If no IP-Port Groups have been created, click +Create on this page or go to Settings > Profiles > Groups to create one. The gateway will examine whether the source IP address and port number of the packet are in the IP-Port Group.

From the Destination drop-down list, choose one of these options to specify the destination of the packets to which this ACL applies:

IP GroupSelect the IP Group you have created. If no IP Groups have been created, click +Create on this page or go to Settings >Profiles >Groups to create one. The gateway will examine whether the destination IP address of the packet is in the IP Group.
IP-Port GroupSelect the IP-Port Group you have created. If no IP-Port Groups have been created, click +Create on this page or go to Settings >Profiles >Groups to create one. The gateway will examine whether the destination IP address and port number of the packet are in the IP-Port Group.

■ Configuring Switch ACL

  1. Go to Settings > Network Security > ACL. Under the Switch ACL tab, click + Create New Rule to load the following page.

Create New Rule

Name:

Status:

Policy:

Protocols:

Ethertype:

Bi-Directional:

Rule:

SourceDestination
Type: NetworkType: IP Group
□ LAN □ Test BDeny□ IPGroup_Any
□ 0/2 Items□ 0/1 Items + Create

- ACL Binding

Binding Type:

Ports:

TP-LINK Omada OC200 - - ACL Binding - 1

Ports

○ VLAN

All Ports

○ Custom Ports

  1. Define packet-filtering criteria of the rule, including protocols, source, and destination, and determine whether to forward the matched packets. Refer to the following table to configure the required parameters.
Name Enter a name to identify the ACL.
Status Click the checkbox to enable the ACL.
Policy Select the action to be taken when a packet matches the rule.
Permit: Forward the matched packet.
Deny: Discard the matched packet.
ProtocolsSelect one or more protocol types to which the rule applies from the drop-down list. The default is All, indicating that packets of all protocols will be matched. When you select one of TCP and UDP or both of them, you can set the IP address and port number of a packet as packet-filtering criteria in the rule.
EthertypeClick the checkbox if you want the switch to check the ethertype of the packets, and configure the Ethertype based on needs.
Bi-DirectionalClick the checkbox to enable the switch to create another symmetric ACL with the name "xxx_reverse", where "xxx" is the name of the current ACL. The two ACLs target at packets with the opposite direction of each other.

From the Source drop-down list, choose one of these options to specify the source of the packets to which this ACL applies:

NetworkSelect the network you have created. If no networks have been created, you can select the default network (LAN), or go to Settings > Wired Networks > LAN to create one. The switch will examine whether the packets are sourced from the selected network.
IP GroupSelect the IP Group you have created. If no IP Groups have been created, click +Create on this page or go to Settings > Profiles > Groups to create one. The switch will examine whether the source IP address of the packet is in the IP Group.
IP-Port GroupSelect the IP-Port Group you have created. If no IP-Port Groups have been created, click +Create on this page or go to Settings > Profiles > Groups to create one. The switch will examine whether the source IP address and port number of the packet are in the IP-Port Group.
MAC GroupSelect the MAC Group you have created. If no MAC Groups have been created, click +Create on this page or go to Settings > Profiles > Groups to create one. The switch will examine whether the source MAC address of the packet is in the MAC Group.

From the Destination drop-down list, choose one of these options to specify the destination of the packets to which this ACL applies:

NetworkSelect the network you have created. If no networks have been created, you can select the default network (LAN), or go to Settings > Wired Networks > LAN to create one. The switch will examine whether the packets are forwarded to the selected network.
IP GroupSelect the IP Group you have created. If no IP Groups have been created, click +Create on this page or go to Settings > Profiles > Groups to create one. The switch will examine whether the destination IP address of the packet is in the IP Group.
IP-Port GroupSelect the IP-Port Group you have created. If no IP-Port Groups have been created, click +Create on this page or go to Settings > Profiles > Groups to create one. The switch will examine whether the destination IP address and port number of the packet are in the IP-Port Group.
MAC GroupSelect the MAC Group you have created. If no MAC Groups have been created, click +Create on this page or go to Settings > Profiles > Groups to create one. The switch will examine whether the destination MAC address of the packet is in the MAC Group.

3. Bind the switch ACL to a switch port or a VLAN and click Apply. Note that a switch ACL takes effect only after it is bound to a port or VLAN.

Binding Type: Specify whether to bind the ACL to ports or a VLAN.

Ports: Select All ports or Custom ports as the interfaces to be bound with the ACL. With All ports selected, the rule is applied to all ports of the switch. With Custom ports selected, the rule is applied to the selected ports of the switch. Click the ports from the Device List to select the binding ports.

Device List ✓ Device Name Ports/Lags Status Model Firmware Version ✓ switch Port 1 2 3 4 5 6 7 8 9 10 CONNECTED TL-SG2210MP 1.0.0 Build 20200608 Rel7560

VLAN: Select a VLAN from the drop-down list as the interface to be bound with the ACL. If no VLANs have been created, you can select the default VLAN 1 (LAN), or go to Settings > Wired Networks > LAN to create one.

Configuring EAP ACL

  1. Go to Settings > Network Security > ACL. Under the EAP ACL tab, click + Create New Rule to load the following page.

Create New Rule Name: Status: Enable Policy: Deny Permit Protocols: All Rule: Source Type: IP Group IPGroup_Any 0/1 Items + Create Deny Destination Type: IP Group IPGroup_Any 0/1 Items + Create Apply Cancel

  1. Define packet-filtering criteria of the rule, including protocols, source, and destination, and determine whether to forward the matched packets. Refer to the following table to configure the required parameters and click Apply.

Name: Enter a name to identify the ACL.

Status: Click the checkbox to enable the ACL.

Policy Select the action to be taken when a packet matches the rule.
Permit: Forward the matched packet.
Deny: Discard the matched packet.
ProtocolsSelect one or more protocol types to which the rule applies from the drop-down list. The default is All, indicating that packets of all protocols will be matched. When you select one of TCP and UDP or both of them, you can set the IP address and port number of a packet as packet-filtering criteria in the rule.

From the Source drop-down list, choose one of these options to specify the source of the packets to which this ACL applies:

NetworkSelect the network you have created. If no networks have been created, you can select the default network (LAN), or go to Settings > Wired Networks > LAN to create one. The EAP will examine whether the packets are sourced from the selected network.
IP GroupSelect the IP Group you have created. If no IP Groups have been created, click +Create on this page or go to Settings > Profiles > Groups to create one. The EAP will examine whether the source IP address of the packet is in the IP Group.
IP-Port GroupSelect the IP-Port Group you have created. If no IP-Port Groups have been created, click +Create on this page or go to Settings > Profiles > Groups to create one. The EAP will examine whether the source IP address and port number of the packet are in the IP-Port Group.
SSIDSelect the SSID you have created. If no SSIDs have been created, go to Settings > Wireless Networks to create one. The EAP will examine whether the SSID of the packet is the SSID selected here.

From the Destination drop-down list, choose one of these options to specify the destination of the packets to which this ACL applies:

NetworkSelect the network you have created. If no networks have been created, you can select the default network (LAN), or go to Settings > Wired Networks > LAN to create one. The EAP will examine whether the packets are forwarded to the selected network.
IP GroupSelect the IP Group you have created. If no IP Groups have been created, click +Create on this page or go to Settings > Profiles > Groups to create one. The EAP will examine whether the destination IP address of the packet is in the IP Group.
IP-Port GroupSelect the IP-Port Group you have created. If no IP-Port Groups have been created, click +Create on this page or go to Settings > Profiles > Groups to create one. The EAP will examine whether the destination IP address and port number of the packet are in the IP-Port Group.

4.5.2 URL Filtering

Overview

URL Filtering allows a network administrator to create rules to block or allow certain websites, which protects the network from web-based threats and denies access to malicious websites.

In URL filtering, the system compares the URLs in HTTP, HTTPS, and DNS requests against the lists of URLs defined in URL Filtering rules, and intercepts requests directed at blocked URLs. These rules can be applied to specific clients or groups whose traffic passes through the gateway and EAPs.

The system filters traffic against the rules in the list sequentially. The first match determines whether the packet is accepted or dropped, and other rules are not checked after the first match. Therefore, the order of the rules is critical. By default, the rules are prioritized based on the sequence in which they are created. The rule created earlier is checked for a match with a higher priority. To reorder the rules, select a rule and drag it to a new position. If no rules match, the device forwards the packet because of an implicit Permit All clause.

Note that URL Filtering rules take effect with a higher priority over ACL rules. That is, the system will process the URL Filtering rule first when the URL Filtering rule and ACL rules are configured at the same time.

Configuration

To complete the URL Filtering configuration, follow these steps:

1) Create a new URL Filtering rule with the specified type. 2) Define filtering criteria of the rule, including source and URLs, and determine whether to forward the matched packets.

■ Configuring Gateway Rules

  1. Go to Settings > Network Security > URL Filtering. Under the Gateway Rules tab, click to load the following page.

Create New Rule Name: Status: Enable Policy: Deny Permit Source Type: Network Network: Please Select... URLs: http(s):// Apply Cancel Add URL

  1. Define filtering criteria of the rule, including source and URLs, and determine whether to forward the matched packets. Refer to the following table to configure the required parameters and click Apply.

Name: Enter a name to identify the URL Filtering rule.

Status: Click the checkbox to enable the URL Filtering rule.

Policy: Select the action to be taken when a packet matches the rule.

Deny: Discard the matched packet and the clients cannot access the URLs.

Permit: Forward the matched packet and clients can access the URLs.

Source Type: Select the source of the packets to which this rule applies.

Network: With Network selected, select the network you have created from the Network drop-down list. If no networks have been created, you can select the default network (LAN), or go to Settings > Wired Networks > LAN to create one. The gateway will filter the packets sourced from the selected network.

IP Group: With IP Group selected, select the IP Group you have created from the IP Group drop-down list. If no IP Groups have been created, click +Create New IP Group on this page or go to Settings > Profiles > Groups to create one. The gateway will examine whether the source IP address of the packet is in the IP Group.

URLs: Enter the URL address using up to 128 characters.

URL address should be given in a valid format. The URL which contains a wildcard(*) is supported. One URL with a wildcard(*) can match multiple subdomains. For example, with *.tp-link.com specified, community.tp-link.com will be matched.

■ Configuring EAP Rules

  1. Go to Settings > Network Security > URL Filtering. On the EAP Rules tab, click + Create New Rule to load the following page.

Create New Rule Name: Status: Enable Policy: Deny Permit Source Type: SSID SSID: Please Select... URLs: http(s):// Add URL Apply Cancel

  1. Define filtering criteria of the rule, including source and URLs, and determine whether to forward the matched packets. Refer to the following table to configure the required parameters and click Apply.

Name: Enter a name to identify the URL Filtering rule.

Status: Click the checkbox to enable the URL Filtering rule.

Policy: Select the action to be taken when a packet matches the rule.

Deny: Discard the matched packet and the clients cannot access the URLs.

Permit: Forward the matched packet and clients can access the URLs.

Source Type: Select the SSID of the packets to which this rule applies.

URLs Enter the URL address using up to 128 characters.

URL address should be given in a valid format. The URL which contains a wildcard(*) is supported. One URL with a wildcard(*) can match multiple subdomains. For example, with *.tp-link.com specified, community.tp-link.com will be matched.

4.5.3 Attack Defense

Overview

Attacks initiated by utilizing inherent bugs of communication protocols or improper network deployment have negative impacts on networks. In particular, attacks on a network device can cause the device or network paralysis.

With the Attack Defense feature, the gateway can identify and discard various attack packets in the network, and limit the packet receiving rate. In this way, the gateway can protect itself and the connected network against malicious attacks.

The gateway provides two types of Attack Defense:

■ Flood Defense

If an attacker sends a large number of fake packets to a target device, the target device is busy with these fake packets and cannot process normal services. Flood Defense detects flood packets in real time and limits the receiving rate of the packets to protect the device.

Flood attacks include TCP SYN flood attacks, UDP flood attacks, and ICMP flood attacks.

■ Packet Anomaly Defense

Anomalous packets are packets that do not conform to standards or contain errors that make them unsuitable for processing. Packet Anomaly Defense discards the illegal packets directly.

Configuration

■ Configuring Flood Defense

Go to Settings > Network Security > Attack Defense. In the Flood Defense, click the checkbox and set the corresponding limit of the rate at which specific packets are received.

Flood Defense

Multi-Connections TCP SYN Flood10000Pkt/s(100-99999)
Multi-Connections UDP Flood20000Pkt/s(100-99999)
Multi-Connections ICMP Flood1500Pkt/s(100-99999)
Stationary Source TCP SYN Flood4000Pkt/s(100-99999)
Stationary Source UDP Flood6000Pkt/s(100-99999)
Stationary Source ICMP Flood600Pkt/s(100-99999)
Multi-Connections TCP SYN FloodA TCP SYN flood attack occurs when the attacker sends the target system with a succession of SYN (synchronize) requests. When the system responds, the attacker does not complete the connections, thus leaving the connection half-open and flooding the system with SYN messages. No legitimate connections can then be made.With this feature enabled, the gateway limits the rate of receiving TCP SYN packets from all the clients to the specified rate.
Multi-Connections UDP FloodA UDP flood attack occurs when the attacker sends a large number of UDP packets to a target host in a short time, the target host is busy with these UDP packets and cannot process normal services.With this feature enabled, the gateway limits the rate of receiving UDP packets from all the clients to the specified rate.
Multi-Connections ICMP FloodIf an attacker sends many ICMP Echo messages to the target device, the target device is busy with these Echo messages and cannot process other data packets. Therefore, normal services are affected.With this feature enabled, the system limits the rate of receiving ICMP packets from all the clients to the specified rate.
Stationary Source TCP SYN FloodA TCP SYN flood attack occurs when the attacker sends the target system with a succession of SYN (synchronize) requests. When the system responds, the attacker does not complete the connections, thus leaving the connection half-open and flooding the system with SYN messages. No legitimate connections can then be made.With this feature enabled, the gateway limits the rate of receiving TCP SYN packets from a single client to the specified rate.
Stationary Source UDP FloodA UDP flood attack occurs when the attacker sends a large number of UDP packets to a target host in a short time, the target host is busy with these UDP packets and cannot process normal services.With this feature enabled, the gateway limits the rate of receiving UDP packets from a single client to the specified rate.
Stationary Source ICMP FloodIf an attacker sends many ICMP Echo messages to the target device, the target device is busy with these Echo messages and cannot process other data packets. Therefore, normal services are affected.With this feature enabled, the system limits the rate of receiving ICMP packets from a single clients to the specified rate.

■ Configuring Packet Anomaly Defense

Go to Settings > Network Security > Attack Defense. In the Packet Anomaly Defense, click the checkbox and set the corresponding limit of the rate at which specific packets are received.

Packet Anomaly Defense

√ Block Fragment Traffic

√ Block TCP Scan (Stealth FIN/Xmas/Null)

√ Block Ping of Death

□ Block Large Ping

√ Block Ping from WAN

Block WinNuke Attack

√ Block TCP Packets with SYN and FIN Bits Set

√ Block TCP Packets with FIN Bit but No ACK Bit Set

√ Block Packets with Specified Options

√ Security Option

√ Loose Source Route Option

Strict Source Route Option

Record Route Option

Stream Option

Timestamp Option

No Operation Option

Block Fragment Traffic

With this option enabled, the fragmented packets without the first part of the packet will be discarded.

Block TCP Scan (Stealth FIN/Xmas/Null)With this option enabled, the gateway will block the anomalous packets in the following attack scenarios:Stealth FIN Scan: The attacker sends the packet with its SYN field and the FIN field set to 1. The SYN field is used to request initial connection whereas the FIN field is used to request disconnection. Therefore, the packet of this type is illegal.Xmas Scan: The attacker sends the illegal packet with its TCP index, FIN, URG and PSH field set to 1.Null Scan: The attacker sends the illegal packet with its TCP index and all the control fields set to 0. During the TCP connection and data transmission, the packets with all control fields set to 0 are considered illegal.
Block Ping of DeathWith this option enabled, the gateway will block Ping of Death attack. Ping of Death attack means that the attacker sends abnormal ping packets which are smaller than 64 bytes or larger than 65535 bytes to cause system crash on the target computer.
Block Large PingWith this option enabled, the router will block the ping packets which are larger than 1024 packets to protect the system from Large Ping attack.
Block Ping from WAN With this option enabled, the router will block the ICMP request from WAN.
Block WinNuke AttackWith this option enabled, the router will block WinNuke attacks. WinNuke attack refers to a remote DoS (denial-of-service) attack that affects some Windows operating systems, such as the Windows 95. The attacker sends a string of OOB (Out of Band) data to the target computer on TCP port 137, 138 or 139, causing system crash or Blue Screen of Death.
Block TCP Packets with SYN and FIN Bits SetWith this option enabled, the router will filter the TCP packets with both SYN Bit and FIN Bit set.
Block TCP Packets with FIN Bit but No ACK Bit SetWith this option enabled, the router will filter the TCP packets with FIN Bit set but without ACK Bit set.
Block Packets with Specified OptionsWith this option enabled, the router will filter the packets with specified IP options including Security Option, Loose Source Route Option, Strict Source Route Option, Record Route Option, Stream Option, Timestamp Option, and No Operation Option.You can choose the options according to your needs.

4.5.4 Firewall

Overview

Firewall is used to enhance network security. In State Timeouts, you can specify a number of timeouts for sessions including TCP, UDP, and ICMP connections. The packets will be forwarded within the specified timeout. When there is no response after the specified time, the session or status will be closed. State timeout will help close inactive sessions and thus avoid network malfunction. In Firewall Options, you can further configure the gateway to prevent attacks like SYN flood attacks and broadcast ping.

Configuration

Configuring State Timeouts

Go to Settings > Network Security > Firewall. In the State Timeouts, set the time limit for the different sessions.

State Timeouts

ICMP:60Seconds(1-21474836)i
Other:600Seconds(1-21474836)i
TCP Close:10Seconds(1-21474836)i
TCP Close Wait:60Seconds(1-21474836)i
TCP Established:7440Seconds(1-21474836)i
TCP FIN Wait:120Seconds(1-21474836)i
TCP Last ACK:30Seconds(1-21474836)i
TCP SYN Recv:60Seconds(1-21474836)i
TCP SYN Sent:120Seconds(1-21474836)i
TCP Time Wait:120Seconds(1-21474836)i
UDP Other:60Seconds(1-21474836)i
UDP Stream:180Seconds(1-21474836)i

ICMP: The ICMP session will be closed if there is no response after the set time.

OtherThe sessions for protocols excluding TCP, UDP, and ICMP will be closed if there is no response after the set time.
TCP Close The TCP Close status will be closed if there is no response after the set time.
TCP Close WaitThe TCP Close Wait status will be closed if there is no response after the set time.
TCP EstablishedThe TCP Established status will be closed if there is no response after the set time.
TCP FIN Wait The TCP FIN Wait status will be closed if there is no response after the set time.
TCP Last ACK The TCP Last ACK status will be closed if there is no response after the set time.
TCP SYN RecvThe TCP SYN (Synchronize) Recv status will be closed if there is no response after the set time.
TCP SYN SentThe TCP SYN (Synchronize) Sent status will be closed if there is no response after the set time.
TCP Time WaitThe TCP Time Wait status will be closed if there is no response after the set time.
UDP OtherThe UDP connections with traffic in only one direction will be stopped if there is no response after the set time.
UDP StreamThe UDP connections with bidirectional traffic will be stopped if there is no response after the set time.

■ Configuring Firewall Options

Go to Settings > Network Security > Firewall. In the State Timeouts, set the time limit for the different sessions.

Firewall Options
Broadcast Ping:i
Receive Redirects:i
Send Redirects:i
SYN Cookies:i

Broadcast Ping: With it enabled, the gateway will reply to broadcast pings.

Receive Redirects: With it enabled, the gateway will accept ICMP redirects.

Send Redirects: With it enabled, the gateway will send ICMP redirects.

SYN Cookies: With it enabled, the SYN cookies will be used to resist SYN flood attacks that want to open ports on the gateway.

TP-LINK Omada OC200 - ■ Configuring Firewall Options - 1

4.6 Transmission

Transmission helps you control network traffic in multiple ways. You can add policies and rules to control transmission routes and limit the session and bandwidth.

4.6.1 Routing

Overview

■ Static Route

Network traffic is oriented to a specific destination, and Static Route designates the next hop or interface where to forward the traffic.

■ Policy Routing

Policy Routing designates which WAN port the router uses to forward the traffic based on the source, the destination, and the protocol of the traffic.

Configuration

■ Static Route

  1. Go to Setting > Transmission > Routing > Static Route. Click + Create New Route to load the following page and configure the parameters.

Create New Route

Name:

TP-LINK Omada OC200 - Create New Route - 1

Status:

TP-LINK Omada OC200 - Create New Route - 2

Enable

Destination IP/Subnet:

TP-LINK Omada OC200 - Create New Route - 3

TP-LINK Omada OC200 - Create New Route - 4

TP-LINK Omada OC200 - Create New Route - 5

Add Subnet

Route Type:

TP-LINK Omada OC200 - Create New Route - 6

Next Hop

TP-LINK Omada OC200 - Create New Route - 7

Interface

Next Hop:

TP-LINK Omada OC200 - Create New Route - 8

Metric:

TP-LINK Omada OC200 - Create New Route - 9

Create

Cancel

Name: Enter the name to identify the Static Route entry.

Status: Enable or disable the Static Route entry.

Destination IP/SubnetDestination IP/Subnet identifies the network traffic which the Static Route entry controls. Specify the destination of the network traffic in the format of 192.168.0.1/24. You can click + Add Subnet to specify multiple Destination IP/Subnets and click 📄 to delete them.
Route TypeNext Hop: With Next Hop selected, your devices forward the corresponding network traffic to a specific IP address. You need to specify the IP address as Next Hop.Interface: With Interface selected, your devices forward the corresponding network traffic through a specific interface. You need to specify the Interface according to your needs.
Metric Define the priority of the Static Route entry. A smaller value means a higher priority. If multiple entries match the Destination IP/Subnet of the traffic, the entry of higher priority takes precedence. In general, you can simply keep the default value.
  1. Click Create. The new Static Route entry is added to the table. You can click ☑ to edit the entry. You can click 🔒 to delete the entry.

Search Static Route Entry NAME ENABLED DESTINATION IP TYPE INTERFACE NEXT HOP METRIC ACTION tp-link ● 192.168.2.3/24 Next Hop 192.168.3.1 0 Showing 1-1 of 1 records < 1 > 10 /page Go To page: GO + CreateNewRoute

■ Policy Routing

  1. Go to Setting > Transmission > Routing > Policy Routing. Click + Create New Routing to load the following page and configure the parameters.

Create New Routing Name: Status: Enable Protocols: All WAN: Please Select... Use the other WAN port if the current one is down: Enable Routing Legend Source Type: Network LAN MGMT VLAN 0/2 Items Destination Type: IP Group Please Select... IPGroup_Any 0/1 Items + Create Create Cancel

Name: Enter the name to identify the Policy Routing entry.

Status: Enable or disable the Policy Routing entry.

Protocols

Select the protocols of the traffic which the Policy Routing entry controls. The Policy Routing entry takes effect only when the traffic matches the criteria of the entry including the protocols.

WAN: Select the WAN port to forward the traffic through. If you want to forward the traffic through the other WAN port when the current WAN is down, enable Use the other WAN port if the current WAN is down.

Routing LegendThe Policy Routing entry takes effect only when the traffic using specified protocols matches the source and destination which are specified in the Routing Legend.Select the type of the traffic source and destination.Network: Select the LAN Interfaces for the traffic source or destination.IP Group: Select the IP Group for the traffic source or destination. You can click + Create to create a new IP Group.IP-Port Group: Select the IP-Port Group for the traffic source or destination. You can click + Create to create a new IP-Port Group.
  1. Click Create. The new Policy Routing entry is added to the table. You can click ☑ to edit the entry. You can click 🔒 to delete the entry.
NAMEENABLEPROTOCOLSOURCEDESTINATIONWANACTION
tp-tekAllIPGroup_AvgWAN
+ CreateNewRouting

4.6.2 NAT

Overview

■ Port Forwarding

You can configure Port Forwarding to allow internet users to access local hosts or use network services which are deployed in the LAN.

Port Forwarding helps establish network connections between a host on the internet and another in the LAN by letting traffic pass through the specific port of the gateway. Without Port Forwarding, hosts in the LAN are typically inaccessible from the internet for the sake of security.

ALG

ALG ensures that certain application-level protocols function appropriately through your gateway.

Configuration

■ Port Forwarding

  1. Go to Setting > Transmission > NAT > Port Forwarding. Click + Create New Rule to load the following page and configure the parameters.

Port Forwarding ALG Create New Rule Name: Status: Enable Source IP: Any Limited IP Address Interface: WAN × DMZ: Enable Source Port: (1-65535. e.g. 80 or 80-100) Destination IP: . . . . Destination Port: (1-65535. e.g. 80 or 80-100) Protocol: All TCP UDP Create Cancel

Name: Enter the name to identify the Port Forwarding rule.

Status: Enable or disable the Port Forwarding rule.

Source IPAny: The rule applies to traffic from any source IP address.
Limited IP Address: The rule only applies to traffic from specific IP addresses. With this option selected, specify the IP addresses and subnets according to your needs.
InterfaceSelect the interface which the rule applies to. Traffic which is received through the interface is forwarded according to the rule.
DMZWith DMZ enabled, all the traffic is forwarded to the Destination IP in the LAN, port to port. You need to specify the Destination IP.
With DMZ disabled, only the traffic which matches the Source Port and the Protocol is forwarded. The traffic is forwarded to the Destination Port of the Destination IP in the LAN. You need to specify the Source Port, Destination IP, Destination Port, and Protocol.
Source PortThe gateway uses the Source Port to receive the traffic from the internet. Only the traffic which matches the Source Port and the Protocol is forwarded.
Destination IPThe traffic is forwarded to the host of the Destination IP in the LAN.
Destination PortThe traffic is forwarded to the Destination Port of the host in the LAN.
ProtocolNetwork traffic is transmitted using either TCP or UDP protocol. Only the traffic which matches the Source Port and the Protocol is forwarded.
If you want both TCP traffic and UDP traffic to be forwarded, select All.
  1. Click Create. The new Port Forwarding entry is added to the table. You can click ☑ to edit the entry. You can click 🔒 to delete the entry.
NAMEENABLEPROTOCOLSOURCEDESTINATIONWANACTION
tp-tekAllIPGroup_AntWAN
+ CreateNewRouting

ALG

Go to Setting > Transmission > NAT > ALG. Enable or disable certain types of ALG according to your needs and click Apply.

ALG FTP ALG: ✓ Enable H.323 ALG: ✓ Enable PPTP ALG: ✓ Enable SIP ALG: ✓ Enable IPsec ALG: ✓ Enable Apply Cancel

FTP ALGFTP ALG allows the FTP server and client to transfer data using the FTP protocol in one of the following scenarios:The FTP server is in the LAN, while the FTP client is on the internet.The FTP server is on the internet, while the FTP client is in the LAN.The FTP server and FTP client are in different LANs.
H.323 ALGH.323 ALG allows the IP phones and multimedia devices to set up connections using the H.323 protocol in one of the following scenarios:One of the endpoints is in the LAN, while the other is on the internet.The endpoints are in different LANs.
PPTP ALG PPTP ALGPPTP ALG allows the PPTP server and client to set up a PPTP VPN in one of the following scenarios:The PPTP server is in the LAN, while the PPTP client is on the internet.The PPTP server is on the internet, while the PPTP client is in the LAN.The PPTP server and PPTP client are in different LANs.
SIP ALGSIP ALG allows the IP phones and multimedia devices to set up connections using the SIP protocol in one of the following scenarios:One of the endpoints is in the LAN, while the other is on the internet.The endpoints are in different LANs.
IPsec ALGIPsec ALG allows the IPsec endpoints to set up an IPsec VPN in one of the following scenarios:One of the endpoints is in the LAN, while the other is on the internet.The endpoints are in different LANs.

4.6.3 Session Limit

Overview

Session Limit optimizes network performance by limiting the maximum sessions of specific sources.

Configuration

  1. Go to Setting > Transmission > Session Limit. In Session Limit, enable Session Limit globally and click Apply.

Session Limit Session Limit: Apply

  1. In Session Limit Rule List, click + Create New Rule to load the following page and configure the parameters.

Create New Rule Name: Status: Enable Source Type: Network IP Group Network: Please Select... Maximum Sessions: (1-999999) Create Cancel

Name: Enter the name to identify the Session Limit rule.

Status: Enable or disable the Session Limit rule.

Source Type:

Network: Limit the maximum sessions of specific LAN networks. With this option selected, select the networks, which you can customize in Wired Networks > LAN Networks. For detailed configuration of networks, refer to 4.3.2 Configure LAN Networks.

IP Group: Limit the maximum sessions of specific IP Groups. With this option selected, select the IP Groups, which you can customize in Profiles > Groups. For detailed configuration of IP groups, refer to 4.8 Create Profiles.

Maximum Sessions: Enter the maximum sessions of the specific sources.

  1. Click Create. The new Session Limit rule is added to the list. You can click ☑ to edit the rule. You can click 🔒 to delete the rule.

Session Limit Rule List NAME ENABLED SOURCE MAXIMUM SESSIONS ACTION tplink ● Network: LAN 50000 + CreateNewRule

4.6.4 Bandwidth Control

Overview

Bandwidth Control optimizes network performance by limiting the bandwidth of specific sources.

Configuration

  1. Go to Setting > Transmission > Bandwidth Control. In Bandwidth Control, enable Bandwidth Control globally and configure the parameters. Then click Apply.

Bandwidth Control Threshold Control: Enable Bandwidth Control when bandwidth usage reaches 80% WAN Upstream Bandwidth: Kbps (100-999999) Test Speed Downstream Bandwidth: Kbps (100-999999) Apply Cancel

Threshold Control

With Threshold Control enabled, Bandwidth Control takes effect only when total bandwidth usage reaches the specified percentage. You need to specify the total Upstream Bandwidth and Downstream Bandwidth of the WAN ports. It's recommended to use the Test Speed tool to decide the actual Upstream Bandwidth and Downstream Bandwidth.

  1. In Bandwidth Control Rule List, click + Create New Rule to load the following page and configure the parameters.

Create New Rule Name: Status: Enable Source Type: Network IP Group Network: Please Select... WAN: Please Select... Upstream Bandwidth: Kbps (100-999999) Downstream Bandwidth: Kbps (100-999999) Mode: Shared Individual Create Cancel

Name: Enter the name to identify the Bandwidth Control rule.

Status: Enable or disable the Bandwidth Control rule.

Source Type:

Network: Limit the maximum bandwidth of specific LAN networks. With this option selected, select the networks, which you can customize in Wired Networks > LAN Networks. For detailed configuration of networks, refer to 4.3.2 Configure LAN Networks.

IP Group: Limit the maximum bandwidth of specific IP Groups. With this option selected, select the IP Groups, which you can customize in Profiles > Groups. For detailed configuration of IP groups, refer to 4.8 Create Profiles.

WAN: Select the WAN port which the rule applies to.

Upstream BandwidthSpecify the limit of Upstream Bandwidth, which the specific local hosts use to transmit traffic to the internet through the gateway.
Downstream BandwidthSpecify the limit of Downstream Bandwidth, which the specific local hosts use to receive traffic from the internet through the gateway.
Mode Specify the bandwidth control mode for the specific local hosts.
Shared: The total bandwidth for all the local hosts is equal to the specified values.
Individual: The bandwidth for each local host is equal to the specified values.
  1. Click Create. The new Bandwidth Control rule is added to the list. You can click ☑ to edit the rule. You can click 🔒 to delete the rule.
Bandwidth Control Rule List
NAMEENABLEDSOURCEWANUPSTREAM BANDWIDTHDOWNSTREAM BANDWIDTHMODEACTION
Ip-linkNetwork: LANWANLAN15000Kbps5000KbpsShared
+ CreateNewRule

4.7 Configure VPN

VPN (Virtual Private Network) provides a means for secure communication between remote computers across a public wide area network (WAN), such as the internet. Omada managed gateways supports various types of VPN. VPN configurations include 4.7.1 VPN and 4.7.2 VPN User.

4.7.1 VPN

Overview

VPN (Virtual Private Network) gives remote LANs or users secure access to LAN resources over a public network such as the internet. Virtual indicates the VPN connection is based on the logical end-to-end connection instead of the physical end-to-end connection. Private indicates users can establish the VPN connection according to their requirements and only specific users are allowed to use the VPN connection.

The core of VPN connection is to realize tunnel communication, which fulfills the task of data encapsulation, data transmission and data decompression via the tunneling protocol. The gateway supports common tunneling protocols that a VPN uses to keep the data secure:

IPsec

IPsec (IP Security) can provide security services such as data confidentiality, data integrity and data authentication at the IP layer. IPsec uses IKE (Internet Key Exchange) to handle negotiation of protocols and algorithms based on the user-specified policy, and to generate the encryption and authentication keys to be used by IPsec. IPsec can be used to protect one or more paths between a pair of hosts, between a pair of security gateways, or between a security gateway and a host.

■ PPTP

PPTP (Point-to-Point Tunneling Protocol) is a network protocol that enables the secure transfer of data from a remote client to a private enterprise server by creating a VPN across TCP/IP-based data networks. PPTP uses the username and password to validate users.

L2TP

L2TP (Layer 2 Tunneling Protocol) provides a way for a dialup user to make a virtual Point-to-Point Protocol (PPP) connection to an L2TP network server (LNS), which can be a security gateway. L2TP sends PPP frames through a tunnel between an L2TP access concentrator (LAC) and the LNS. Because of the lack of confidentiality inherent in the L2TP protocol, it is often implemented along with IPsec. L2TP uses the username and password to validate users.

OpenVPN

OpenVPN uses OpenSSL for encryption of UDP and TCP for traffic transmission. OpenVPN uses a client-server connection to provide secure communications between a server and a remote client over the internet. One of the most important steps in setting up OpenVPN is obtaining a certificate which is used for authentication. Omada SDN controller supports generating the certificate which can be downloaded as a file on your computer. With the certificate imported, the remote clients are checked out by the certificate and granted access to the LAN resources.

There are many variations of virtual private networks, with the majority based on two main models:

■ Site-to-Site VPN

A Site-to-Site VPN creates a connection between two networks at different geographic locations. Typically, headquarters set up Site-to-Site VPN with the subsidiary to provide the branch office with access to the headquarters' network.

graph LR A["Site-to-Site VPN"] --> B["Internet"] B --> C["Building 1"] B --> D["Building 2"]

Branch Office Headquarters

Omada managed gateway supports two types of Site-to-Site VPNs:

- Auto IPsec

The controller automatically creates an IPsec VPN tunnel between two sites on the same controller. The VPN connection is bidirectional. That is, creating an Auto IPsec VPN from site A to site B also provides connectivity from site B to site A, and nothing is needed to be configured on site B.

- Manual IPsec

You create an IPsec VPN tunnel between two peer routers over the internet manually, from a local router to a remote router that supports IPsec. The Omada managed gateway on this site is the local peer router.

■ Client-to-Site VPN

A Client-to-Site VPN creates a connection to the LAN from a remote host. It is useful for teleworkers and business travelers to access their central LAN from a remote location without compromising privacy and security.

The first step to build a Client-to-Site VPN connection is to determine the role of the gateways and which VPN tunneling protocol to use:

- VPN Server

The gateway on the central LAN works as a VPN server to provide a remote host with access to the local network. The gateway that functions as a VPN server can use L2TP, PPTP, IPsec, or OpenVPN as the tunneling protocol.

- VPN Client

Either the remote user's gateway or the remote user's laptop or PC works as the VPN client.

When the remote user's gateway works as the VPN client, the gateway helps create VPN tunnels between its connected hosts and the VPN server. The gateway that functions as a VPN client can use L2TP, PPTP, or OpenVPN as the tunneling protocol.

graph LR A["Remote User"] --> B["Gateway (Client) Gateway (Server)"] B --> C["Internet"] C --> D["Headquarters"]

When the remote user's laptop or PC works as the VPN client, the laptop or PC uses VPN client software to create VPN tunnels between itself and the VPN server. The VPN client software can use L2TP, PPTP, IPsec, or OpenVPN as the tunneling protocol.

graph LR A["Remote User (Client)"] --> B["Gateway Gateway (Server)"] B --> C["Internet"] C --> D["Headquarters"]

TP-LINK Omada OC200 - ■ Client-to-Site VPN - 3

Note:

In scenario 1, you need to configure VPN client and VPN server separately on the gateways, while remote hosts can access the local networks without running VPN client software.

In scenario 2, you need to configure VPN server on the gateway, and then configure the VPN client software on the remote user's laptop or PC, while the remote user's gateway doesn't need any VPN configuration.

Here is an infographic to provide a quick overview of VPN solutions.

TP-LINK Omada OC200 - Note: - 1

Create a VPN Policy

TP-LINK Omada OC200 - Create a VPN Policy - 1

Select the purpose of the VPN

Site-to-Site VPN

graph LR A["Building"] --> B["Internet"] B --> C["Cityscape"]

Branch Office Headquarters

Auto IPsec VPN

The controller automatically creates an IPsec VPN tunnel between two sites on the same controller.

Manual IPsec VPN

You manually create an IPsec VPN tunnel between two peer routers over the internet, from a local router to a remote router that supports IPsec.

Client-to-Site VPN

graph LR A["Remote User"] --> B["Gateway (Client) Gateway (Server)"] B --> C["Internet"] C --> D["Headquarters"]

graph LR A["Remote User (Client)"] --> B["Gateway"] B --> C["Internet"] C --> D["Gateway (Server)"] D --> E["Headquarters"]

TP-LINK Omada OC200 - Client-to-Site VPN - 3

Select the role of the gateway and VPN tunneling protocol

VPN Server

L2TP

PPTP

IPsec

OpenVPN

VPN Client

L2TP

PPTP

IPsec (Only for VPN client software)

PN

Configuration

To complete the VPN configuration, follow these steps:

1) Create a new VPN policy and select the purpose of the VPN according to your needs. Select Site-to-Site if you want the network connected to another. Select Client-to-Site if you want some hosts connected to the network. 2) Select the VPN tunneling protocol and configure the VPN policy based on the protocol.

■ Configuring Site-to-Site VPN

Omada managed gateway supports two types of Site-to-Site VPNs: Auto IPsec and Manual IPsec.

- Configuring Auto IPsec VPN

  1. Go to Settings >VPN. Click + Create New VPN Policy to load the following page.

Create New VPN Policy

Name:

Purpose:

TP-LINK Omada OC200 - Create New VPN Policy - 1

Site-to-Site VPN

TP-LINK Omada OC200 - Create New VPN Policy - 2

Client-to-Site VPN

VPN Type:

TP-LINK Omada OC200 - Create New VPN Policy - 3

Auto IPsec

TP-LINK Omada OC200 - Create New VPN Policy - 4

Manual IPsec

Status:

TP-LINK Omada OC200 - Create New VPN Policy - 5

Enable

Remote Site:

Please Select...

Create

Cancel

  1. Enter a name to identify the VPN policy and select the purpose as Site-to-Site VPN. Refer to the following table to configure the required parameters and click Create.

Name: Enter a name to identify the VPN policy.

Purpose: Select the purpose for the VPN as Site-to-Site VPN.

VPN Type: Select the VPN type as Auto IPsec.

Status: Click the checkbox to enable the VPN policy.

Remote Site

Select the site on the other end of the Auto IPsec VPN tunnel. Make sure that the selected remote site has an online Omada managed gateway within the same controller.

- Configuring Manual IPsec VPN

  1. Go to Settings > VPN. Click + Create New VPN Policy to load the following page.

Create New VPN Policy Name: Purpose: Site-to-Site VPN Client-to-Site VPN VPN Type: Auto IPsec Manual IPsec Status: Enable Remote Gateway: Remote Subnets: . . . / Local Networks: All Pre-Shared Key: WAN: Please Select... + Advanced Settings Create Cancel

  1. Enter a name to identify the VPN policy and select the purpose as Site-to-Site VPN. Refer to the following table to configure the basic parameters and click Create.
Name Enter a name to identify the VPN policy.
Purpose Select the purpose for the VPN as Site-to-Site VPN.
VPN Type Select the VPN type as Manual IPsec.
Status Click the checkbox to enable the VPN policy.
Remote GatewayEnter an IP address or a domain name as the gateway on the remote peer of the VPN tunnel.
Remote Subnets Enter the IP address range of LAN on the remote peer of the VPN tunnel.
Local NetworksSelect the networks on the local side of the VPN tunnel. The VPN policy will be only applied to the selected local networks.
Pre-Shared KeyEnter the pre-shared key(PSK). Both peer gateways must use the same pre-shared secret key for authentication.
A pre-shared key is a string of characters that is used as an authentication key. Both peer gateways create a hash value based on the same pre-shared key and other information. The hash values are then exchanged and verified to authenticate the other party.
The pre-shared keys should be long and random for security. Short or predictable pre-shared keys can be easily broken in brute-force attacks. To maintain a high level of security, administrators are recommended to update the pre-shared key periodically.

WAN: Select the WAN port on which the IPsec VPN tunnel is established.

3. Click Advanced Settings to load the following page.

Advanced Settings Phase-1 Settings Key Exchange Version: IKEv1 IKEv2 Proposal: SHA1 - AES256 - DH2 Exchange Mode: Main Mode Aggressive Mode Negotiation Mode: Initiator Mode Responder Mode Local ID Type: IP Address Name Remote ID Type: IP Address Name SA Lifetime: 28800 seconds (60-604800) DPD: Enabl…

Advanced settings include Phase-1 settings and Phase-2 settings. Phase-1 is used to set up a secure encrypted channel which the two peers can negotiate Phase-2, and then establish the IKE Security Associations (IKE SA). Phase-2 is used to negotiate about a set of parameters that

define what traffic can go through the VPN, and how to encrypt and authenticate the traffic, then establish the IPsec Security Associations (IPsec SA).

Refer to the following table to complete the configurations according to your actual needs and click Create.

For Phase-1 Settings:

Phase-1 SettingsThe IKE version you select determines the available Phase-1 settings and defines the negotiation process. Both VPN gateways must be configured to use the same IKE version and Phase-1 settings.
Internet Key Exchange VersionSelect the version of Internet Key Exchange (IKE) protocol which is used to set up security associations for IPsec. Both IKEv1 and IKEv2 are supported with Omada managed gateways, but IKEv1 is available only when the VPN policy is applied to a single Remote Subnet and a single Local Network.Note that both peer gateways must be configured to use the same IKE version.
Proposal Specify the proposal for IKE negotiation phase-1. An IKE proposal lists the encryption algorithm, authentication algorithm and Diffie-Hellman (DH) groups to be negotiated with the remote IPsec peer—Authentication algorithms verify the data integrity and authenticity of a message. The types of authentication includes MD5 and SHA1.Encryption algorithms protect the data from being read by a third-party. The types of encryption algorithm includes DES, 3DES, AES128, AES192, and AES256.Diffie-Hellman (DH) groups determine the strength of the key used in the key exchange process. The DH group includes DH1, DH2, DH5, DH14, DH15, DH16, DH19, DH20, DH21, DH25, and DH26.Note that both peer gateways must be configured to use the same Proposal.
Exchange Mode Specify the IKE Exchange Mode when IKEv1 is selected.Main Mode: This mode provides identity protection and exchanges more information, which applies to scenarios with higher requirements for identity protection.Aggressive Mode: This mode establishes a faster connection but with lower security, which applies to scenarios with lower requirements for identity protection.
Negotiation Mode Specify the IKE Negotiation Mode as Initiator Mode or Responder Mode.Initiator Mode: This mode means that the local device initiates a connection to the peer.Responder Mode: This mode means that the local device waits for the connection request initiated by the peer.
Local ID TypeSpecify the type of Local ID which indicates the authentication identifier sent to the peer for IKE negotiation.
IP Address: Select IP Address to use the IP address for authentication.
Name: Select Name, and then enter the name in the Local ID field to use the name as the ID for authentication.
Note that the type and value of Local ID should be the same as Remote ID given for the remote peer of the VPN tunnel.
Local ID When the Local ID Type is configured as Name, enter a name for the local device as the ID in IKE negotiation. The name should be in the format of FQDN (Fully Qualified Domain Name).
Remote ID TypeSpecify the type of Remote ID which indicates the authentication identifier received from the peer for IKE negotiation.
IP Address: Select IP Address to use the IP address for authentication.
Name: Select Name, and then enter the name in the Remote ID field to use the name as the ID for authentication.
Note that the type and value of Remote ID should be the same as Local ID given for the remote peer of the VPN tunnel.
Remote ID When the Remote ID Type is configured as Name, enter a name of the remote peer as the ID in IKE negotiation. The name should be in the format of FQDN (Fully Qualified Domain Name).
SA LifetimeSpecify ISAKMP SA (Security Association) Lifetime in IKE negotiation. If the SA lifetime expired, the related ISAKMP SA will be deleted.
DPD Check the box to enable DPD (Dead Peer Detect) function. If enabled, the IKE endpoint can send a DPD request to the peer to inspect whether the IKE peer is alive.
DPD IntervalSpecify the interval between sending DPD requests with DPD enabled. If the IKE endpoint receives a response from the peer during this interval, it considers the peer alive. If the IKE endpoint does not receive a response during the interval, it considers the peer dead and deletes the SA.
For Phase-2 Settings:
Phase-2 SettingsThe purpose of Phase 2 negotiations is to establish the Phase-2 SA (also called the IPsec SA). The IPsec SA is a set of traffic specifications that tell the device what traffic to send over the VPN, and how to encrypt and authenticate that traffic.
Encapsulation ModeSpecify the Encapsulation Mode as Tunnel Mode or Transport Mode. When both ends of the tunnel are hosts, either mode can be chosen. When at least one of the endpoints of a tunnel is a security gateway, such as a router or firewall, Tunnel Mode is recommended to ensure safety.
Proposal Specify the proposal for IKE negotiation phase-2. An IPsec proposal lists the encryption algorithm, authentication algorithm and protocol to be negotiated with the remote IPsec peer.
Note that both peer gateways must be configured to use the same Proposal.
PFS Select the DH group to enable PFS (Perfect Forward Security) for IKE mode, then the key generated in phase-2 will be irrelevant with the key in phase-1, which enhance the network security. With None selected, it means PFS is disabled and the key in phase-2 will be generated based on the key in phase-1.
SA LifetimeSpecify IPsec SA (Security Association) Lifetime in IKE negotiation. If the SA lifetime expired, the related IPsec SA will be deleted.

■ Configuring Client-to-Site VPN

Omada managed gateway supports seven types of client-to-Site VPNs depending on the role of your Omada managed gateway and the protocol that you used:

Configuring the gateway as a VPN server using L2TP Configuring the gateway as a VPN server using PPTP Configuring the gateway as a VPN server using IPsec Configuring the gateway as a VPN server using OpenVPN Configuring the gateway as a VPN client using L2TP Configuring the gateway as a VPN client using PPTP Configuring the gateway as a VPN client using OpenVPN

- Configuring the gateway as a VPN server using L2TP

  1. Go to Settings > VPN. Click + Create New VPN Policy to load the following page.

Create New VPN Policy Name: Purpose: Site-to-Site VPN Client-to-Site VPN VPN Type: VPN Server - L2TP Status: Enable IPsec Encryption: Encrypted Unencrypted Auto Local Networks: All Pre-Shared Key: WAN: Please Select... IP Pool: . . . /

  1. Enter a name to identify the VPN policy and select the purpose as Client-to-Site VPN. Refer to the following table to configure the required parameters and click Create.
Name Enter a name to identify the VPN policy.
Purpose Select the purpose for the VPN as Client-to-Site VPN.
VPN Type Select the VPN type as VPN Server - L2TP.
Status Click the checkbox to enable the VPN policy.
IPsec Encryption Specify whether to enable the encryption for the tunnel.
Encrypted: Select Encrypted to encrypt the L2TP tunnel by IPsec (L2TP over IPsec). With Encrypted selected, enter the Pre-shared Key for IKE authentication. VPN server and VPN client must use the same pre-shared secret key for authentication.
Unencrypted: With Unencrypted selected, the L2TP tunnel will not be encrypted by IPsec.
Auto: With Auto selected, the L2TP server will determine whether to encrypt the tunnel according to the client 's encryption settings. And enter the Pre-shared Key for IKE authentication. VPN server and VPN client must use the same pre-shared secret key for authentication.
Local NetworksSelect the networks on the local side of the VPN tunnel. The VPN policy will be only applied to the selected local networks.
Pre-shared KeyEnter the pre-shared secret key when IPsec Encryption is selected as Encrypted and Auto. Both peer routers must use the same pre-shared secret key for authentication.
WAN Select the WAN port on which the L2TP VPN tunnel is established. Each WAN port supports only one L2TP VPN tunnel when the gateway works as a L2TP server.
IP Pool Enter the IP address and subnet mask to decide the range of the VPN IP pool.
The VPN server will assign IP address to the remote host when the tunnel is established. You can specify any reasonable IP address that will not cause overlap with the IP address of the LAN on the local peer router.
  1. Add the VPN users account to validate remote hosts. To create VPN users, refer to 4.7.2 VPN User.

- Configuring the gateway as a VPN server using PPTP

  1. Go to Settings > VPN. Click + Create New VPN Policy to load the following page.

Create New VPN Policy Name: Purpose: Site-to-Site VPN Client-to-Site VPN VPN Type: VPN Server - PPTP Status: Enable MPPE Encryption: Encrypted Unencrypted Auto Local Networks: All WAN: Please Select... IP Pool: . . . /

  1. Enter a name to identify the VPN policy and select the purpose as Client-to-Site VPN. Refer to the following table to configure the required parameters and click Create.
Name Enter a name to identify the VPN policy.
Purpose Select the purpose for the VPN as Client-to-Site VPN.
VPN Type Select the VPN type as VPN Server - PPTP.
Status Click the checkbox to enable the VPN policy.
MPPE EncryptionSpecify whether to enable MPPE (Microsoft Point-to-Point Encryption) for the tunnel.Encrypted: With Encrypted selected, the PPTP tunnel will be encrypted by MPPE.Unencrypted: With Unencrypted selected, the PPTP tunnel will be not encrypted by MPPE.
Local NetworksSelect the networks on the local side of the VPN tunnel. The VPN policy will be only applied to the selected local networks.
WAN Select the WAN port on which the PPTP VPN tunnel is established. Each WAN port supports only one PPTP VPN tunnel when the gateway works as a PPTP server.
IP Pool Enter the IP address and subnet mask to decide the range of the VPN IP pool.The VPN server will assign IP address to the remote host when the tunnel is established. You can specify any reasonable IP address that will not cause overlap with the IP address of the LAN on the local peer router.
  1. Add the VPN users account to validate remote hosts. To create VPN users, refer to 4.7.2 VPN User.

- Configuring the gateway as a VPN server using IPsec

  1. Go to Settings > VPN. Click + Create New VPN Policy to load the following page.

Create New VPN Policy Name: Purpose: Site-to-Site VPN Client-to-Site VPN VPN Type: VPN Server - IPsec Status: Enable Remote Host: Local Networks: All Pre-Shared Key: WAN: Please Select... IP Pool: . . . / + Advanced Settings

  1. Enter a name to identify the VPN policy and select the purpose as Client-to-Site VPN. Refer to the following table to configure the basic parameters and click Create.
Name Enter a name to identify the VPN policy.
Purpose Select the purpose for the VPN as Client-to-Site VPN.
VPN Type Select the VPN type as VPN Server - IPsec.
Status Click the checkbox to enable the VPN policy.
Remote Host Enter an IP address or a domain name of the host on the remote peer of the VPN tunnel. 0.0.0.0 represents any IP address.
Local NetworksSelect the networks on the local side of the VPN tunnel. The VPN policy will be only applied to the selected local networks.
Pre-Shared KeyEnter the pre-shared key(PSK). Both peer gateways must use the same pre-shared secret key for authentication.A pre-shared key is a string of characters that is used as an authentication key. Both VPN peers create a hash value based on the same pre-shared key and other information. The hash values are then exchanged and verified to authenticate the other party.The pre-shared keys should be long and random for security. Short or predictable pre-shared keys can be easily broken in brute-force attacks. To maintain a high level of security, administrators are recommended to update the pre-shared key periodically.

WAN Select the WAN port on which the IPsec VPN tunnel is established.

IP Pool Enter the IP address and subnet mask to decide the range of the VPN IP pool.

The VPN server will assign IP address to the remote host when the tunnel is established. You can specify any reasonable IP address that will not cause overlap with the IP address of the LAN on the local peer router.

3. Click Advanced Settings to load the following page.

Advanced Settings Phase-1 Settings Key Exchange Version: IKEv1 IKEv2 Proposal: SHA1 - AES256 - DH2 Exchange Mode: Main Mode Aggressive Mode Negotiation Mode: Initiator Mode Responder Mode Local ID Type: IP Address Name Remote ID Type: IP Address Name SA Lifetime: 28800 seconds (60-604800) DPD: Enabl…

Advanced settings include Phase-1 settings and Phase-2 settings. Phase-1 is used to set up a secure encrypted channel through which the two peers can negotiate Phase-2, and then establish the IKE Security Associations (IKE SA). Phase-2 is used to negotiate a set of parameters that

define what traffic can go through the VPN, and how to encrypt and authenticate the traffic, then establish the IPsec Security Associations (IPsec SA).

Refer to the following table to complete the configurations according to your actual needs and click Create.

For Phase-1 Settings:

Phase-1 SettingsThe IKE version you select determines the available Phase-1 settings and defines the negotiation process. Both VPN gateways must be configured to use the same IKE version and Phase-1 settings.
Internet Key Exchange VersionSelect the version of Internet Key Exchange (IKE) protocol which is used to set up security associations for IPsec. Both IKEv1 and IKEv2 are supported with Omada managed gateways, but IKEv1 is available only when the VPN policy is applied to a single Remote Subnet and a single Local Network.Note that both VPN peers must be configured to use the same IKE version.
Proposal Specify the proposal for IKE negotiation phase-1. An IKE proposal lists the encryption algorithm, authentication algorithm and Diffie-Hellman (DH) groups to be negotiated with the remote IPsec peer—Authentication algorithms verify the data integrity and authenticity of a message. The types of authentication includes MD5 and SHA1.Encryption algorithms protect the data from being read by a third-party. The types of encryption algorithm includes DES, 3DES, AES128, AES192, and AES256.Diffie-Hellman (DH) groups determine the strength of the key used in the key exchange process. The DH group includes DH1, DH2, DH5, DH14, DH15, DH16, DH19, DH20, DH21, DH25, and DH26.Note that both VPN peers must be configured to use the same Proposal.
Exchange Mode Specify the IKE Exchange Mode when IKEv1 is selected.Main Mode: This mode provides identity protection and exchanges more information, which applies to scenarios with higher requirements for identity protection.Aggressive Mode: This mode establishes a faster connection but with lower security, which applies to scenarios with lower requirements for identity protection.
Negotiation Mode Specify the IKE Negotiation Mode as Initiator Mode or Responder Mode.Initiator Mode: This mode means that the local device initiates a connection to the peer.Responder Mode: This mode means that the local device waits for the connection request initiated by the peer.
Local ID TypeSpecify the type of Local ID which indicates the authentication identifier sent to the peer for IKE negotiation.
IP Address: Select IP Address to use the IP address for authentication.
Name: Select Name, and then enter the name in the Local ID field to use the name as the ID for authentication.
Note that the type and value of Local ID should be the same as Remote ID given for the remote peer of the VPN tunnel.
Local ID When the Local ID Type is configured as Name, enter a name for the local device as the ID in IKE negotiation. The name should be in the format of FQDN (Fully Qualified Domain Name).
Remote ID TypeSpecify the type of Remote ID which indicates the authentication identifier received from the peer for IKE negotiation.
IP Address: Select IP Address to use the IP address for authentication.
Name: Select Name, and then enter the name in the Remote ID field to use the name as the ID for authentication.
Note that the type and value of Remote ID should be the same as Local ID given for the remote peer of the VPN tunnel.
Remote ID When the Remote ID Type is configured as Name, enter a name of the remote peer as the ID in IKE negotiation. The name should be in the format of FQDN (Fully Qualified Domain Name).
SA LifetimeSpecify ISAKMP SA (Security Association) Lifetime in IKE negotiation. If the SA lifetime expired, the related ISAKMP SA will be deleted.
DPD Check the box to enable DPD (Dead Peer Detect) function. If enabled, the IKE endpoint can send a DPD request to the peer to inspect whether the IKE peer is alive.
DPD IntervalSpecify the interval between sending DPD requests with DPD enabled. If the IKE endpoint receives a response from the peer during this interval, it considers the peer alive. If the IKE endpoint does not receive a response during the interval, it considers the peer dead and deletes the SA.
For Phase-2 Settings:
Phase-2 SettingsThe purpose of Phase 2 negotiations is to establish the Phase-2 SA (also called the IPsec SA). The IPsec SA is a set of traffic specifications that tell the device what traffic to send over the VPN, and how to encrypt and authenticate that traffic.
Encapsulation ModeSpecify the Encapsulation Mode as Tunnel Mode or Transport Mode. When both ends of the tunnel are hosts, either mode can be chosen. When at least one of the endpoints of a tunnel is a security gateway, such as a router or firewall, Tunnel Mode is recommended to ensure safety.
Proposal Specify the proposal for IKE negotiation phase-2. An IPsec proposal lists the encryption algorithm, authentication algorithm and protocol to be negotiated with the remote IPsec peer. Note that both peer gateways must be configured to use the same Proposal.
PFS Select the DH group to enable PFS (Perfect Forward Security) for IKE mode, then the key generated in phase-2 will be irrelevant with the key in phase-1, which enhance the network security. With None selected, it means PFS is disabled and the key in phase-2 will be generated based on the key in phase-1.
SA LifetimeSpecify IPsec SA (Security Association) Lifetime in IKE negotiation. If the SA lifetime expired, the related IPsec SA will be deleted.

- Configuring the gateway as a VPN server using OpenVPN

  1. Go to Settings > VPN. Click + Create New VPN Policy to load the following page.

Create New VPN Policy Name: Purpose: Site-to-Site VPN Client-to-Site VPN VPN Type: VPN Server - OpenVPN Status: Enable Protocol: TCP UDP Service Port: 1194 (1-65535) Local Networks: All WAN: Please Select... IP Pool: . . . /

  1. Enter a name to identify the VPN policy and select the purpose as Client-to-Site VPN. Refer to the following table to configure the required parameters and click Create.
Name Enter a name to identify the VPN policy.
Purpose Select the purpose for the VPN as Client-to-Site VPN.
VPN Type Select the VPN type as VPN Server - OpenVPN.
Status Click the checkbox to enable the VPN policy.
Protocol Select the communication protocol for the gateway which works as an OpenVPN Server. Two communication protocols are available: TCP and UDP.
Service Port Enter a VPN service port to which a VPN device connects.
Local NetworksSelect the networks on the local side of the VPN tunnel. The VPN policy will be only applied to the selected local networks.
WAN Select the WAN port on which the VPN tunnel is established. Each WAN port supports only one OpenVPN tunnel when the gateway works as a OpenVPN server.
IP Pool Enter the IP address and subnet mask to decide the range of the VPN IP pool.The VPN server will assign IP address to the remote host when the tunnel is established. You can specify any reasonable IP address that will not cause overlap with the IP address of the LAN on the local peer router.
  1. After clicking Create to save the VPN policy, go to VPN Policy List and click in the Action column to export the OpenVPN file that ends in .ovpn which is to be used by the remote client. The exported OpenVPN file contains the certificate and configuration information.

NAME ENABLED PURPOSE VPN TYPE INTERFACE WAN ACTION OpenVPN Client-to-Site VPN OpenVPN(Server) LAN WAN Showing 1-2 of 2 records < 10 iPage Go To page: GO + Create New VPN Policy

- Configuring the gateway as a VPN client using L2TP

  1. Go to Settings > VPN. Click + Create New VPN Policy to load the following page.

Create New VPN Policy Name: Purpose: Site-to-Site VPN Client-to-Site VPN VPN Type: VPN Client - L2TP Status: Enable Working Mode: NAT Routing Username: Password: IPsec Encryption: Encrypted Unencrypted Auto Remote Server: Remote Subnets: . . . / Local Networks: All Pre-Shared Key: WAN: Please Select…

  1. Enter a name to identify the VPN policy and select the purpose as Client-to-Site VPN. Refer to the following table to configure the required parameters and click Create.

Name: Enter a name to identify the VPN policy.

Purpose: Select the purpose for the VPN as Client-to-Site VPN.

VPN Type: Select the VPN type as VPN Client - L2TP.

Status: Click the checkbox to enable the VPN policy.

Working Mode Specify the Working Mode as NAT or Routing.

NAT: With NAT (Network Address Translation) mode selected, the L2TP client uses the assigned IP address as its source addresses of original IP header when forwarding L2TP packets.

Routing: With Routing selected, the L2TP client uses its own IP address as its source addresses of original IP header when forwarding L2TP packets.

Username Enter the username used for the VPN tunnel. This username should be the same as that of the L2TP server.
Password Enter the password of user. This password should be the same as that of the L2TP server.
IPsec Encryption Specify whether to enable the encryption for the tunnel.Encrypted: Select Encrypted to encrypt the L2TP tunnel by IPsec (L2TP over IPsec). With Encrypted selected, enter the Pre-shared Key for IKE authentication. VPN server and VPN client must use the same pre-shared secret key for authentication.Unencrypted: With Unencrypted selected, the L2TP tunnel will be not encrypted by IPsec.
Remote Server Enter the IP address or domain name of the L2TP server.
Remote SubnetsEnter the IP address and subnet mask to specify the remote network. It's always the IP address range of LAN on the remote peer of the VPN tunnel.
Local NetworksSelect the networks on the local side of the VPN tunnel. The VPN policy will be only applied to the selected local networks.
Pre-shared KeyEnter the pre-shared secret key when the L2TP tunnel is encrypted by IPsec. Both peer gateways must use the same pre-shared secret key for authentication.
WAN Select the WAN port on which the VPN tunnel is established.

- Configuring the gateway as a VPN client using PPTP

  1. Go to Settings > VPN. Click + Create New VPN Policy to load the following page.

Create New VPN Policy Name: Purpose: Site-to-Site VPN Client-to-Site VPN VPN Type: VPN Client - PPTP Status: Enable Working Mode: NAT Routing Username: Password: MPPE Encryption: Encrypted Unencrypted Auto Remote Server: Remote Subnets: . . . / Local Networks: All WAN: Please Select... Create Cancel…

  1. Enter a name to identify the VPN policy and select the purpose as Client-to-Site VPN. Refer to the following table to configure the required parameters and click Create.

Name Enter a name to identify the VPN policy.

Purpose Select the purpose for the VPN as Client-to-Site VPN.

VPN Type Select the VPN type as VPN Client - PPTP.

Status Click the checkbox to enable the VPN policy.

Working Mode Specify the Working Mode as NAT or Routing.

NAT: With NAT (Network Address Translation) mode selected, the PPTP client uses the assigned IP address as its source addresses of original IP header when forwarding PPTP packets.

Routing: With Routing selected, the PPTP client uses its own IP address as its source addresses of original IP header when forwarding PPTP packets.

Username Enter the username used for the VPN tunnel. This username should be the same as that of the PPTP server.
Password Enter the password of user. This password should be the same as that of the PPTP server.
MPPE Encryption Specify whether to enable the encryption for the tunnel.Encrypted: Select Encrypted to encrypt the PPTP tunnel by MPPE.Unencrypted: With Unencrypted selected, the PPTP tunnel will be not encrypted by MPPE.
Remote Server Enter the IP address or domain name of the PPTP server.
Remote SubnetsEnter the IP address and subnet mask to specify the remote network. It's always the IP address range of LAN on the remote peer of the VPN tunnel.
Local NetworksSelect the networks on the local side of the VPN tunnel. The VPN policy will be only applied to the selected local networks.
WAN Select the WAN port on which the VPN tunnel is established.

- Configuring the gateway as a VPN client using OpenVPN

  1. Go to Settings > VPN. Click + Create New VPN Policy to load the following page.

Create New VPN Policy

Name:

Purpose:

TP-LINK Omada OC200 - Create New VPN Policy - 1

Site-to-Site VPN

TP-LINK Omada OC200 - Create New VPN Policy - 2

Client-to-Site VPN

VPN Type:

VPN Client - OpenVPN

Status:

TP-LINK Omada OC200 - Create New VPN Policy - 3

Enable

Remote Server:

TP-LINK Omada OC200 - Create New VPN Policy - 4

Local Networks:

TP-LINK Omada OC200 - Create New VPN Policy - 5

WAN:

TP-LINK Omada OC200 - Create New VPN Policy - 6

Configuration:

TP-LINK Omada OC200 - Create New VPN Policy - 7

Create

Cancel

  1. Enter a name to identify the VPN policy and select the purpose as Client-to-Site VPN. Refer to the following table to configure the required parameters and click Create.
Name Enter a name to identify the VPN policy.
Purpose Select the purpose for the VPN as Client-to-Site VPN.
VPN Type Select the VPN type as VPN Client - OpenVPN.
Status Click the checkbox to enable the VPN policy.
Remote Server Enter the IP address or domain name of the OpenVPN server.
Local NetworksSelect the networks on the local side of the VPN tunnel. The VPN policy will be only applied to the selected local networks.
WAN Select the WAN port on which the VPN tunnel is established.
ConfigurationClickImportto import the OpenVPN file that ends in .ovpn generated by the OpenVPN server. Only one file can be imported.If the certificate file and configuration file are generated singly by the OpenVPN server, combine two files and import the whole file.

4.7.2 VPN User

Overview

VPN User is used to configure and record your custom settings for VPN configurations, and it allows you to configure VPN users that can be used for multiple VPN servers, including L2TP servers and PPTP servers. It saves you from setting the VPN users with the same configurations repeatedly when you want to apply the user in different VPN servers.

Configuration

To configure the VPN users, follow these steps:

  1. Go to Settings > VPN > VPN User. Click +Create New VPN User to add a new entry of VPN User.

VPN VPN User Search Name or VPN Service NAME VPN SERVER MODE ACTION ① No entry in the table. + Create New VPN User

  1. Specify the parameters and select the VPN policy with the type of VPN Server-L2TP/PPTP that the VPN user is applied to and click Create.

Create New VPN User

Username:

Password:

VPN Server:

Mode:

Please Select...

TP-LINK Omada OC200 - Create New VPN User - 1

Client

TP-LINK Omada OC200 - Create New VPN User - 2

TP-LINK Omada OC200 - Create New VPN User - 3

Network Extension Mode

TP-LINK Omada OC200 - Create New VPN User - 4

Maximum Connections:

3

(1-100)

Create

Cancel

UsernameEnter the username used for the VPN tunnel. The client use the username for the validation before accessing the network.
PasswordEnter the password of user. The client uses the password for the validation before accessing the network.
VPN ServerSelect the VPN policy with the type of VPN Server-L2TP/PPTP that the VPN user is applied to.
Mode Specify the connection mode for the VPN users.
Client: This mode allows the client to request for an IP address and the server supplies the IP addresses from the VPN IP Pool. With this mode selected, set maximum number of concurrent VPN connections with the same account in Maximum Connections.
Network Extension Mode: This mode allows only clients from the configured subnet to connect to the server and obtain VPN services. With this mode selected, specify the subnet in Remote Subnets.
Maximum ConnectionsWith Client mode selected, set maximum number of concurrent VPN connections with the same account.
Remote SubnetsWith Network Extension Mode selected, only clients from the configured subnet are allowed to connect to the server and obtain VPN services. Click Add Subnet to specify the subnet.

To edit or delete the VPN users, click the icon in the Action column. You can further filter the entries based on the VPN Server.

VPN VPN User Search Name or VPN Service NAME VPN SERVER MODE ACTION user L2TP Server: VPN Server 1 Client Showing 1-1 of 1 records < 1 > 10 /page Go To page: GO + Create New VPN User

TP-LINK Omada OC200 - Create New VPN User - 6

Filter the entries.

TP-LINK Omada OC200 - Create New VPN User - 7

View and edit the account information of users.

TP-LINK Omada OC200 - Create New VPN User - 8

Delete the VPN user.

4.8 Create Profiles

The Profiles section is used to configure and record your custom settings for site configurations. It includes Time Range and Groups profiles. In the Time Range section, you can configure time templates for wireless schedule, PoE schedule, etc. In the Groups section, you can configure groups based on IP, IP-Port, and MAC addresses for ACL, Routing, NAT, etc. After creating the profiles, you can apply them to multiple configurations for different sites, saving you from repeatedly setting up the same information.

4.8.1 Time Range

Overview

The Time Range section allows you to customize time-related configurations. You can set different time range templates which can be shared and applied to wireless schedule, PoE schedule, etc. in site configuration.

Configuration

To configure the time range profiles, follow these steps:

  1. Go to Settings > Profiles > Time Range. Click + Create New Time Range to add a new time range entry. By default, there is no entry in the list.
NAMEDAY MODETIME RANGEACTION
i No time range profiles yet.
+ Create New Time Range
  1. Enter a Name for the new entry, select the Day Mode, and specify the time range. Click Apply to save the entry. After saving the newly added entry, you can apply them to site configuration. To

apply the customized time range profiles in configuration, refer to 4.4.3 WLAN Schedule, and 4.10.6 PoE Schedule.

Create New Time Range Name: Day Mode: Every Day Weekday Weekend Customized Every Day 08:00 am 06:00 pm Apply Cancel

Name: Enter a name for the new entry. It is a string with 1 to 64 ASCII symbols.

Day ModeSelect Every Day, Weekday, Weekend, or Customized first before specifying the time range for each day.Every Day: You only need to set the time range once, and it will repeat every day.Weekday: You only need to set the time range once, and it will repeat every weekday from Monday to Friday.Weekend: You only need to set the time range once, and it will repeat every Saturday and Sunday.Customized: You are able to set different time range for the chosen day(s) based on your needs. When a day is not chosen, the WiFi is open all day by default.

You can view the name, day mode, and time range in the list.

NAME DAY MODE TIME RANGE ACTION Time Range 1 Every Day 08:00 am-06:00 pm Showing 1-1 of 1 records < 1 > 10 /page Go To page: GO + Create New Time Range

To edit or delete the time range entry, click the icon in the Action column.

TP-LINK Omada OC200 - Configuration - 3

TP-LINK Omada OC200 - Configuration - 4

Edit the parameters in the entry.

Delete the entry.

4.8.2 Groups

Overview

The Groups section allows you to customize client groups based on IP, IP-Port, or MAC Address. You can set different rules for the group profiles, which can be shared and applied to ACL, Routing, NAT, etc., in site configuration.

Configuration

To configure the group profiles, follow these steps:

  1. Go to Settings > Profiles > Groups. By default, there is an entry covering all IPs, and it is not editable and deletable. Click +Create New Group to add a new group entry.

NAME TYPE COUNT ACTION IPGroup_Any IP Group 1 Showing 1-1 of 1 records < 1 > 10 /page Go To page: GO

  1. Enter a name for the new group profile entry, and select the type for the new entry.

Create New Group Name: Type: IP Group IP-Port Group MAC Group IP Subnets: . . . / Apply Cancel Add Subnet

■ Based on IP Group

To configure a group profile based on IP Group, you are required to specify the IP subnets, while subnet mask is optional. You can click +Add Subnet to add new subnets, and click 📄 to delete them.

Create New Group Name: IP Group 1 Type: IP Group IP-Port Group MAC Group IP Subnets: 192 . 168 . 0 . 1 / 192 . 168 . 0 . 2 / Apply Cancel Add Subnet

■ Based on IP-Port Group

To configure a group profile based on IP-Port Group, you are required to specify the port(s) for the entry, while it is optional to specify the IP subnet(s). If you only specify the port(s) without entering any IP subnet, it means the group contains the specified port(s) for all IPs. You can click +Add Subnet to add new IP subnets, click +Add Port to add ports, and click 📋 to delete them.

Create New Group Name: IP-Port Group 1 Type: IP Group IP-Port Group MAC Group IP Subnets Add Subnet Port: 80 (0-65535. e.g. 80 or 80-100) Add Port 8080 (0-65535. e.g. 80 or 80-100)

■ Based on MAC Group

To configure a group profile based on MAC Group, you are required to enter MAC Address(es) in the MAC Addresses List. There are three ways to add MAC address(es) to the MAC Addresses List.

Create New Group Name: MAC Group 1 Type: IP Group IP-Port Group MAC Group MAC Addresses List Add Batch Add Add from Client List MAC Address ↑ NAME ACTION Apply Cancel Add MAC address singly. Batch Add Add MAC addresses in batches. You can enter the MAC addresses and names in the input box or import…

3. Click Apply to save the entry.

After saving the newly added entry, you can apply them to site configuration. To apply the customized profiles in configuration, refer to 4.5.1 ACL, 4.6.1 Routing, 4.6.2 NAT.

You can view the name, type, and count in the list.

NAMETYPECOUNTACTION
IP Group 1IP Group2
IP-Port Group 1IP-Port Group5
IPGroup_AnyIP Group1
MAC Group 1MAC Group4
Showing 1-4 of 4 records< 1 > 10 /page Go To page: GO

TP-LINK Omada OC200 - Click Apply to save the entry. - 1

To view, edit or delete the group entry, click the icon in the Action column.

TP-LINK Omada OC200 - Click Apply to save the entry. - 2

View and edit the parameters in the entry. You cannot change the type when editing the entry.

TP-LINK Omada OC200 - Click Apply to save the entry. - 3

Delete the entry.

4.8.3 Rate Limit

Overview

Rate Limit allows you to customize rate-related configurations. You can set different rate limit templates. They can be bound with wireless networks to limit the upload/download rate of clients connected to the SSID, and applied to specific types of Portal, such as Local User and Voucher. After creating the profiles, you can apply them to multiple configurations, saving you from repeatedly setting up the same information.

Configuration

To configure the rate limit profiles, follow these steps:

  1. Go to Settings > Profiles > Rate Limit. By default, there is an entry with no limits, and it cannot be deleted. Click +Create New Rate Limit Profile to add a new group entry.

NAME Download Limit Upload Limit ACTION Default Unlimited Unlimited Showing 1-1 of 1 records < 1 > 10 /page Go To page: GO + Create New Rate Limit Profile

  1. Enter a name and specify the download/upload rate limit for the new entry. After saving the newly added entry, you can apply them to other configurations. To apply the customized rate limit profiles in the related configurations, refer to 4.9.1 Portal, 4.4.1 Set Up Basic Wireless Networks, and 7.1.3 Using the Properties Window to Monitor and Manage the Clients.

Create New Rate Limit Profile Name: Download Limit: ✓ Enable Kbps ✓ (1-10485760) Upload Limit: ✓ Enable Kbps ✓ (1-10485760) Apply Cancel

Name: Enter a name to identify the created rate limit profile.

Download LimitEnable the download limit, and specify the rate limit correspondingly in Kbps or Mbps.
Upload LimitEnable the upload limit, and specify the rate limit correspondingly in Kbps or Mbps.
  1. Click Apply to save the entry. After saving the newly added entry, you can apply them to site configuration. To apply the customized rate limit profiles in the related configurations, refer to 4.9.1 Portal, and 4.4.1 Set Up Basic Wireless Networks.

You can view the name, download limit, and upload limit in the list.

NAME Download Limit Upload Limit ACTION Default Unlimited Unlimited Limit-Day 20000 Kbps 20000 Kbps Limit-Night 50000 Kbps 50000 Kbps Showing 1-3 of 3 records < 1 > 10 /page Go To page: GO + Create New Rate Limit Profile

To view, edit, or delete the rate limit profile, click the icon in the Action column.

TP-LINK Omada OC200 - Configuration - 4

View and edit the parameters in the entry. You cannot change the type when editing the entry.

TP-LINK Omada OC200 - Configuration - 5

Delete the entry.

4.9 Authentication

Authentication is a portfolio of features designed to authorize network access to clients, which enhances network security. Authentication services include 4.9.1 Portal, 4.9.2 802.1X, and 4.9.3 MAC-Based Authentication, covering all the needs to authenticate both wired and wireless clients.

4.9.1 Portal

Overview

Portal authentication provides convenient authentication services to clients that only need temporary access to the network, such as customers in a restaurant or supermarket. To access the network, these clients need to enter the authentication login page and use the correct login information to pass authentication. In addition, you can customize the authentication login page and specify a URL to which authenticated clients will be redirected.

Portal authentication takes effect on SSIDs and LAN networks. EAPs authenticate wireless clients that connect to the SSID with Portal configured, and the gateway authenticates wired clients that connect to the network with Portal configured. To make Portal authentication available for wired and wireless clients, ensure that both the gateway and EAPs are connected and working properly.

The controller provides six types of Portal authentication:

■ No Authentication

With this authentication type configured, clients can pass authentication and access the network without providing any login information. Clients just need to accept the terms (if configured) and click the Login button.

■ Simple Password

With this authentication type configured, clients are required to enter the correct password to pass authentication. All clients use the same password, which is configured in the controller.

Hotspot

With this authentication type configured, clients can access the network after passing any type of the following authentication:

- Voucher

Clients can use the unique voucher codes generated by the controller within a predefined time usage. Voucher codes can be printed out from the controller, so you can print the codes and distribute them to your customers to tie network access to consumption.

- Local User

Clients are required to enter the correct username and password of the login account to pass authentication.

- SMS

Clients can get verification codes using their mobile phones and enter the received codes to pass the authentication.

- RADIUS

Clients are required to enter the correct username and password which are stored in the RADIUS server to pass the authentication.

■ External RADIUS Server

Clients are required to enter the correct username and password created on the RADIUS server to pass the authentication.

■ External Portal Server

The option of External Portal Server is designed for the developers. They can customize their own authentication type like Google account authentication according to the interface provided by Omada Controller.

■ Facebook

With Facebook Portal configured, when clients connect to your Wi-Fi, they will be redirected to your Facebook page. To access the internet, clients need to log in their account or enter the password code in the Facebook page.

Portal authentication can work with Access Control Policy, which grant specific network access to the users with valid identities. You can determine that the clients which didn't pass Portal authentication can only access the network resources allowed by Access Control Policy.

■ Pre-Authentication Access

Pre-Authentication Access allows unauthenticated clients to access the specific network resources.

■ Authentication-Free Client

Authentication-Free Clients allows the specific clients to access the specific network resources without authentication.

Configuration

To complete the Portal configuration, follow these steps:

1) Click + Create New Portal to create a new Portal entry. 2) Click to enable Portal, select the SSIDs and LAN networks for the portal to take effect on, and configure basic parameters including authentication type, authentication timeout, and so on. 3) Customize the Portal page including the background picture, logo picture, and so on. 4) (Optional) Configure access control policies including Pre-Authentication Access and Authentication-Free Clients if needed.

The following part introduces how to configure each type of Portal authentication: No Authentication, Simple Password, Hotspot (Voucher, Local User, SMS, RADIUS), External RADIUS Server, External Portal Server, and Facebook.

■ Configuring Portal with No Authentication

  1. Go to Settings > Authentication > Portal. On the Portal tab, click + Create New Portal to create a new portal entry. Then click ▼ to enable Portal and load the following page.

Create New Portal Portal Name: Portal: Controller Online Required. SSID & Network: Please Select... Authentication Type: No Authentication Authentication Timeout: 8 Hours Daily Limit: Enable i HTTPS Redirection: Enable i Landing Page: The Original URL The Promotional URL http://

  1. Select the SSIDs and LAN networks for the portal to take effect on, and configure basic parameters including authentication type, authentication timeout, and so on.
Portal Name Enter a name to identify the created Portal entry.
PortalClick ➕ to enable Portal.
SSID & NetworkSelect one or more SSIDs or LAN networks for the portal. The clients connected to the selected SSIDs or LAN networks have to log into a web page to establish verification before accessing the network.
Authentication Type Select the type of Portal authentication as No Authentication.
Authentication TimeoutSelect the login duration. Clients will be off-line after the authentication timeout.
Daily LimitClick the checkbox to enable Daily Limit. With this feature enabled, after authentication times out, clients cannot get authenticated again until the next day. With this feature disabled, after authentication times out, clients can get authenticated again without limit.
HTTPS RedirectionClick the checkbox to enable HTTPS Redirection. With this feature enabled, the unauthorized clients will be redirected to the Portal page when they are trying to browse HTTPS websites. With this feature disabled, the unauthorized clients cannot browse HTTPS websites and are not redirected to the Portal page.

Landing Page

Select which page the client will be redirected to after a successful authentication.

The Original URL: Clients are directed to the URL they request for after they pass Portal authentication.

The Promotional URL: Clients are directed to the specified URL after they pass Portal authentication.

  1. In the Portal Customization section, customize the Portal page including the background picture, logo picture, and so on.

Portal Customization

Type:

Edit Current Page

○ Import Customized Page

Default Language:

English

TP-LINK Omada OC200 - Portal Customization - 1

TP-LINK Omada OC200 - Portal Customization - 2

Background:

○ Solid Color

Picture

Background Picture:

Choose

TP-LINK Omada OC200 - Portal Customization - 3

Logo:

Enable

Logo Picture:

Choose

TP-LINK Omada OC200 - Portal Customization - 4

Logo Position:

Middle

TP-LINK Omada OC200 - Portal Customization - 5

Button Color:

0492eb

100

TP-LINK Omada OC200 - 0492eb - 1

Button Text color:

ffffff

100

TP-LINK Omada OC200 - ffffff - 1

Button Position:

Middle

TP-LINK Omada OC200 - ffffff - 2

Welcome Information:

Enable

Terms of Service:

Enable

Copyright:

Enable

Type Select the type of the Portal page.
Edit Current Page: Edit the related parameters to customize the Portal page based on the provided page.
Import Customized Page: Click Import to import your unique Portal page for branding it as per your business.
Default LanguageSelect the default language displayed on the Portal page. The controller automatically adjusts the language displayed on the Portal page according to the system language of the clients. If the language is not supported, the controller will use the default language specified here.
Background Select the background type.
Solid Color: Configure your desired background color by entering the hexadecimal HTML color code manually or through the color picker.
Picture: Click Choose and select a picture from your PC as the background.
Logo Click to show the logo on the portal page.
Logo PictureClick Choose and select a picture from your PC as the logo.
Logo Position Select the logo position in the Portal page.
Button ColorConfigure your desired background color for the button by entering the hexadecimal HTML color code manually or through the color picker.
Button Text ColorConfigure your desired text color for the button by entering the hexadecimal HTML color code manually or through the color picker.
Button Position Select the button position in the Portal page.
Welcome InformationClick the checkbox and enter text as the welcome information. And you can configure your desired text color for the welcome information by entering the hexadecimal HTML color code manually or through the color picker.
Terms of ServiceClick the checkbox and enter text as the terms of service in the following box.
Copyright Click the checkbox and enter text as the copyright in the following box.

Click Advertisement Options and customize advertisement pictures on the authentication page.

TP-LINK Omada OC200 - ffffff - 3

Advertisement:

TP-LINK Omada OC200 - Advertisement Options - 1

Enable

Picture Resource:

Choose

(1-5 Pictures)

TP-LINK Omada OC200 - Advertisement Options - 2

Advertisement Duration Time:

seconds

(1-30)

Picture Carousel Interval:

seconds

(1-10)

Allow Users To Skip Advertisement:

TP-LINK Omada OC200 - Advertisement Options - 3

Enable

AdvertisementClick the checkbox to enable the Advertisement feature. With this feature enabled, you can add advertisement pictures on the authentication page. These advertisement pictures will be displayed before the login page appears.
Picture ResourceClick Choose and select pictures from your PC as the advertisement pictures. When several pictures are added, they will be played in a loop.
Advertisement Duration TimeEnter the duration time for the advertisement pictures. For this duration, the pictures will be played in a loop. If the duration time is not enough for all the pictures, the rest will not be displayed.
Picture Carousel IntervalEnter the picture carousel interval. For example, if this value is set as 5 seconds, the first picture will be displayed for 5 seconds, followed by the second picture for 5 seconds, and so on.
Allow Users To Skip AdvertisementClick the checkbox to allow users to skip the advertisement.
  1. (Optional) Configure access control rules including Pre-Authentication Access and Authentication-Free Policy if needed. Go to Settings > Authentication > Portal. On the Access Control tab, click the checkbox to enable Pre-Authentication Access and Authentication-Free Policy.

Access Control Pre-Authentication Access: ✓ Enable ⓘ Pre-Authentication Access List: TYPE INFORMATION ACTION ⓘ No Pre-Authentication Access entries have been configured. Authentication-Free Client: ✓ Enable ⓘ Authentication-Free Client List TYPE INFORMATION ACTION ⓘ No Authentication-Free Client hav…

Pre-Authentication AccessClick the checkbox to enable Pre-Authentication Access. With this feature enabled, unauthenticated clients are allowed to access the subnets and web resources specified in the Pre-Authentication Access List below.
Pre-Authentication Access ListClick Add to configure the IP range or URL which unauthenticated clients are allowed to access.
Authentication-Free PolicyClick the checkbox to enable Authentication-Free Policy. With this feature enabled, you can allow certain clients to access the internet without Portal authentication.
Authentication-Free Client ListClick Add and enter the IP address or MAC address of Authentication-Free clients.

■ Configuring Portal with Simple Password

  1. Go to Settings > Authentication > Portal. On the Portal tab, click + Create New Portal to create a new portal entry. Then click ▼ to enable Portal and load the following page.

Create New Portal Portal Name: Portal: Controller Online Required. SSID & Network: Please Select... Authentication Type: Simple Password Password: Ø Authentication Timeout: 8 Hours HTTPS Redirection: Enable i Landing Page: The Original URL The Promotional URL

  1. Select the SSIDs and LAN networks for the portal to take effect on and configure basic parameters including authentication type, authentication timeout and so on.
SSID & NetworkSelect one or more SSIDs or LAN networks for the portal. The clients connected to the selected SSIDs or LAN networks have to log into a web page to establish verification before accessing the network.
Authentication Type Select the type of Portal authentication as Simple Password.
Password Specify the password for the portal.
Authentication TimeoutSelect the login duration. Clients will be off-line after the authentication timeout.
HTTPS RedirectionClick the checkbox to enable HTTPS Redirection. With this feature enabled, the unauthorized clients will be redirected to the Portal page when they are trying to browse HTTPS websites. With this feature disabled, the unauthorized clients cannot browse HTTPS websites and are not redirected to the Portal page.

Landing Page

Select which page the client will be redirected to after a successful authentication.

The Original URL: Clients are directed to the URL they request for after they pass Portal authentication.

The Promotional URL: Clients are directed to the specified URL here after they pass Portal authentication.

  1. In the Portal Customization section, customize the Portal page including the background picture, logo picture and so on.

Portal Customization

Type:

Edit Current Page

○ Import Customized Page

Default Language:

English

TP-LINK Omada OC200 - Portal Customization - 1

TP-LINK Omada OC200 - Portal Customization - 2

Background:

Solid Color

Picture

Background Picture:

Choose

TP-LINK Omada OC200 - Portal Customization - 3

Logo:

Enable

Logo Picture:

Choose

TP-LINK Omada OC200 - Portal Customization - 4

Logo Position:

Middle

TP-LINK Omada OC200 - Portal Customization - 5

Input Box Color:

TP-LINK Omada OC200 - Portal Customization - 6

ffffff

100

TP-LINK Omada OC200 - ffffff - 1

Input Text Color:

TP-LINK Omada OC200 - ffffff - 2

000000

100

TP-LINK Omada OC200 - 000000 - 1

Button Color:

TP-LINK Omada OC200 - 000000 - 2

100

TP-LINK Omada OC200 - 000000 - 3

Button Text color:

TP-LINK Omada OC200 - 000000 - 4

ffffff

100

TP-LINK Omada OC200 - ffffff - 1

Button Position:

Middle

TP-LINK Omada OC200 - ffffff - 2

Welcome Information:

TP-LINK Omada OC200 - ffffff - 3

Enable

Terms of Service:

TP-LINK Omada OC200 - ffffff - 4

Enable

Copyright:

TP-LINK Omada OC200 - ffffff - 5

Enable

Type: Select the type of the Portal page.

Edit Current Page: Edit the related parameters to customize the portal page based on the provided page.

Import Customized Page: Click Import to import your unique Portal page for branding it as per your business.

Default LanguageSelect the default language displayed on the Portal page. The controller automatically adjusts the language displayed on the Portal page according to the system language of the clients. If the language is not supported, the controller will use the default language specified here.
Background Select the background type.
Solid Color: Configure your desired background color by entering the hexadecimal HTML color code manually or through the color picker.Picture: Click Choose and select a picture from your PC as the background.
Logo Click to show the logo on the portal page.
Logo PictureClick Choose and select a picture from your PC as the logo.
Logo Position Select the logo position in the Portal page.
Input Box ColorConfigure your desired color of the input box for password by entering the hexadecimal HTML color code manually or through the color picker.
Input Text ColorConfigure your desired color of the input text for password by entering the hexadecimal HTML color code manually or through the color picker.
Button Text ColorConfigure your desired text color for the button by entering the hexadecimal HTML color code manually or through the color picker.
Button Position Select the button position in the Portal page.
Welcome InformationClick the checkbox and enter text as the welcome information. And you can configure your desired text color for the welcome information by entering the hexadecimal HTML color code manually or through the color picker.
Terms of ServiceClick the checkbox and enter text as the terms of service in the following box.
Copyright Click the checkbox and enter text as the copyright in the following box.

Click Advertisement Options and customize advertisement pictures on the authentication page.

TP-LINK Omada OC200 - ffffff - 6

Advertisement:

TP-LINK Omada OC200 - Advertisement Options - 1

Enable

Picture Resource:

Choose

(1-5 Pictures)

TP-LINK Omada OC200 - Advertisement Options - 2

Advertisement Duration Time:

seconds

(1-30)

Picture Carousel Interval:

seconds

(1-10)

Allow Users To Skip Advertisement:

TP-LINK Omada OC200 - Advertisement Options - 3

Enable

AdvertisementClick the checkbox to enable the Advertisement feature. With this feature enabled, you can add advertisement pictures on the authentication page. These advertisement pictures will be displayed before the login page appears.
Picture ResourceClick Choose and select pictures from your PC as the advertisement pictures. When several pictures are added, they will be played in a loop.
Advertisement Duration TimeEnter the duration time for the advertisement pictures. For this duration, the pictures will be played in a loop. If the duration time is not enough for all the pictures, the rest will not be displayed.
Picture Carousel IntervalEnter the picture carousel interval. For example, if this value is set as 5 seconds, the first picture will be displayed for 5 seconds, followed by the second picture for 5 seconds, and so on.
Allow Users To Skip AdvertisementClick the checkbox to allow users to skip the advertisement.
  1. (Optional) Configure access control rules including Pre-Authentication Access and Authentication-Free Policy if needed. Go to Settings > Authentication > Portal. On the Access Control tab, click the checkbox to enable Pre-Authentication Access and Authentication-Free Policy.

Access Control Pre-Authentication Access: ✓ Enable ⓘ Pre-Authentication Access List: TYPE INFORMATION ACTION ⓘ No Pre-Authentication Access entries have been configured. Authentication-Free Client: ✓ Enable ⓘ Authentication-Free Client List TYPE INFORMATION ACTION ⓘ No Authentication-Free Client hav…

Pre-Authentication AccessClick the checkbox to enable Pre-Authentication Access. With this feature enabled, unauthenticated clients are allowed to access the subnets and web resources specified in the Pre-Authentication Access List below.
Pre-Authentication Access ListClick Add to configure the IP range or URL which unauthenticated clients are allowed to access.
Authentication-Free PolicyClick the checkbox to enable Authentication-Free Policy. With this feature enabled, you can allow certain clients to access the internet without Portal authentication.
Authentication-Free Client ListClick Add and enter the IP address or MAC address of Authentication-Free clients.

Configuring Portal with Hotspot

  1. Go to Settings > Authentication > Portal. On the Portal tab, click + Create New Portal to create a new portal entry. Then click ▼ to enable the Portal and load the following page.

Create New Portal Portal Name: Portal: Controller Online Required. SSID & Network: Please Select... Authentication Type: Hotspot Type: Voucher Local User SMS RADIUS HTTPS Redirection: Enable Landing Page: The Original URL The Promotional URL http://

  1. Select the SSIDs and LAN networks for the portal to take effect on and configure basic parameters.
SSID & NetworkSelect one or more SSIDs or LAN networks for the portal. The clients connected to the selected SSIDs or LAN networks have to log into a web page to establish verification before accessing the network.
Authentication Type Select the type of Portal authentication as Hotspot.
Type Select one or more authentication types according to your needs. Clients can access the network after passing any type of the authentication.
HTTPS RedirectionClick the checkbox to enable HTTPS Redirection. With this feature enabled, the unauthorized clients will be redirected to the Portal page when they are trying to browse HTTPS websites. With this feature disabled, the unauthorized clients cannot browse HTTPS websites and are not redirected to the Portal page.
Landing PageSelect which page the client will be redirected to after a successful authentication.The Original URL: Clients are directed to the URL they request for after they pass Portal authentication.The Promotional URL: Clients are directed to the specified URL after they pass Portal authentication.
  1. With different types of Hotspot selected, configure the related parameters.

Configuring Voucher Portal

VoucherSelect Voucher and click to manage the voucher codes.Refer to 7.2.2 Vouchers for detailed information about how to create vouchers.

Configuring Local Portal

Local UserSelect Local User and click to manage the information of the login accounts.
Refer to 7.2.3 Local Users for detailed information about how to create Local Users.

Configuring SMS Portal

Select SMS and configure the required parameters in the SMS section.

SMS i We provide Twilio API service. Please configure your account information. Twilio SID: Auth Token: Operating Phone Number: + For example: +17704505791 Maximum User Number: Enable Authentication Timeout: 8 Hours Preset Country Code: + (Optional)

SMS Clients can get verification codes using their mobile phones and enter the received codes to pass the authentication.
Twilio SID Enter the Account SID for Twilio API Credentials.
Auth Token Enter the Authentication Token for Twilio API Credentials.
Operating Phone NumberEnter the phone number that is used to send verification messages to the clients.
Maximum User NumbersClick the checkbox and enter the maximum number of users allowed to be authenticated using the same phone number at the same time.
Authentication TimeoutSelect the login duration. The client needs to log in again on the web authentication page to access the network.
Preset Country CodeEnter the default country code that will be filled automatically on the authentication page.

Configuring RADIUS Portal

Select RADIUS and configure the required parameters in the RADIUS section.

RADIUS Authentication Timeout: 1 Hour RADIUS Profile: Please Select... Manage RADIUS Profile Authentication Mode: PAP CHAP NAS ID: TP-Link Disconnect Requests: Enable Receiver Port: 3799 (1-65535) Status: Disabled

Authentication TimeoutClients are required to enter the correct username and password which are stored in the RADIUS server to pass the authentication.
RADIUS Profile Select the RADIUS profile you have created. If no RADIUS profiles have been created, click + Create New RADIUS Profile from the drop-down list or Manage RADIUS Profile to create one. The RADIUS profile records the information of the RADIUS server which provides a method for storing the authentication information centrally.
Authentication ModeSelect the authentication protocol for the RADIUS server. Two authentication protocols are available: PAP and CHAP.
NAS ID Configure a Network Access Server Identifier (NAS ID) on the portal. Authentication request packets from the controller to the RADIUS server carry the NAS ID. The RADIUS server can classify users into different groups based on the NAS ID, and then choose different policies for different groups.
Disconnected RequestsWith the feature enabled, the controller will listen on the receiver port for disconnect requests from the RADIUS server. When the controller receives the disconnect requests in correct format, the controller will terminate the RADIUS authentication session of the clients. Note that the feature is available only when the controller is accessible to the RADIUS server.
Receiver PortSpecify the port on which the controller listens when there are disconnect requests from the RADIUS server. Make sure that the specified port is not in use.
StatusThe entry displays the status of the receiver port, including Running, Disabled, and Error. Running means that the port is available, Disabled means that the port is closed, and Error means that the port is already in use.
  1. In the Portal Customization section, customize the Portal page including the background picture, logo picture, and so on.

Portal Customization Type: Edit Current Page Import Customized Page Default Language: English i Background: Solid Color Picture Background Picture: Choose i Logo: Enable Logo Picture: Choose i Logo Position: Middle Input Box Color: #ffffff 100 Input Text Color: #000000 100 Button Color: #0492eb 100…

Type Select the type of the Portal page.
Edit Current Page: Edit the related parameters to customize the portal page based on the provided page.
Import Customized Page: Click Import to import your unique Portal page for branding it as per your business.
Default LanguageSelect the default language displayed on the Portal page. The controller automatically adjusts the language displayed on the Portal page according to the system language of the clients. If the language is not supported, the controller will use the default language specified here.
Background Select the background type.
Solid Color: Configure your desired background color by entering the hexadecimal HTML color code manually or through the color picker.
Picture: Click Choose and select a picture from your PC as the background.
Logo Click to show the logo on the portal page.
Logo PictureClick Choose and select a picture from your PC as the logo.
Logo Position Select the logo position in the Portal page.
Input Box ColorConfigure your desired color of the input box for password by entering the hexadecimal HTML color code manually or through the color picker.
Input Text ColorConfigure your desired color of the input text for password by entering the hexadecimal HTML color code manually or through the color picker.
Button ColorConfigure your desired background color for the button by entering the hexadecimal HTML color code manually or through the color picker.
Button Text ColorConfigure your desired text color for the button by entering the hexadecimal HTML color code manually or through the color picker.
Button Position Select the button position in the Portal page.
Welcome InformationClick the checkbox and enter text as the welcome information. And you can configure your desired text color for the welcome information by entering the hexadecimal HTML color code manually or through the color picker.
Terms of ServiceClick the checkbox and enter text as the terms of service in the following box.
Copyright Click the checkbox and enter text as the copyright in the following box.

Click Advertisement Options and customize advertisement pictures on the authentication page.

TP-LINK Omada OC200 - Configuring RADIUS Portal - 3

Advertisement:

TP-LINK Omada OC200 - Advertisement Options - 1

Enable

Picture Resource:

Choose

(1-5 Pictures)

TP-LINK Omada OC200 - Advertisement Options - 2

Advertisement Duration Time:

seconds

(1-30)

Picture Carousel Interval:

seconds

(1-10)

Allow Users To Skip Advertisement:

TP-LINK Omada OC200 - Advertisement Options - 3

Enable

AdvertisementClick the checkbox to enable the Advertisement feature. With this feature enabled, you can add advertisement pictures on the authentication page. These advertisement pictures will be displayed before the login page appears.
Picture ResourceClick Choose and select pictures from your PC as the advertisement pictures. When several pictures are added, they will be played in a loop.
Advertisement Duration TimeEnter the duration time for the advertisement pictures. For this duration, the pictures will be played in a loop. If the duration time is not enough for all the pictures, the rest will not be displayed.
Picture Carousel IntervalEnter the picture carousel interval. For example, if this value is set as 5 seconds, the first picture will be displayed for 5 seconds, followed by the second picture for 5 seconds, and so on.
Allow Users To Skip AdvertisementClick the checkbox to allow users to skip the advertisement.
  1. (Optional) Configure access control rules including Pre-Authentication Access and Authentication-Free Policy if needed. Go to Settings > Authentication > Portal. On Access Control tab, click the checkbox to enable Pre-Authentication Access and Authentication-Free Policy.

Access Control Pre-Authentication Access: ✓ Enable ⓘ Pre-Authentication Access List: TYPE INFORMATION ACTION ⓘ No Pre-Authentication Access entries have been configured. Authentication-Free Client: ✓ Enable ⓘ Authentication-Free Client List TYPE INFORMATION ACTION ⓘ No Authentication-Free Client hav…

Pre-Authentication AccessClick the checkbox to enable Pre-Authentication Access. With this feature enabled, unauthenticated clients are allowed to access the subnets and web resources specified in the Pre-Authentication Access List below.
Pre-Authentication Access ListClick Add to configure the IP range or URL which unauthenticated clients are allowed to access.
Authentication-Free PolicyClick the checkbox to enable Authentication-Free Policy. With this feature enabled, you can allow certain clients to access the internet without Portal authentication.
Authentication-Free Client ListClick Add and enter the IP address or MAC address of Authentication-Free clients.

■ Configuring Portal with External RADIUS Server

  1. Go to Settings > Authentication > Portal. Click 📋 to enable Portal and load the following page.

Create New Portal Portal Name: Portal: Controller Online Required. SSID & Network: Please Select... Authentication Type: External RADIUS Server Authentication Timeout: 8 Hours RADIUS Profile: Please Select... NAS ID: TP-Link Manage RADIUS Profile Disconnect Requests: Enable i Authentication Mode: PA…

  1. Select the SSIDs and LAN networks for the portal to take effect on and configure basic parameters including authentication type, authentication timeout and so on.
SSID & NetworkSelect one or more SSIDs or LAN networks for the portal. The clients connected to the selected SSIDs or LAN networks have to log into a web page to establish verification before accessing the network.
Authentication Type Select the type of Portal authentication as External RADIUS Server.
Authentication TimeoutSelect the login duration. Clients will be off-line after the authentication timeout.
RADIUS ProfileSelect the RADIUS profile you have created. If no RADIUS profiles have been created, click + Create New RADIUS Profile from the drop-down list or Manage RADIUS Profile to create one. The RADIUS profile records information of the RADIUS server including the IP address, port and so on.
NAS ID Configure a Network Access Server Identifier (NAS ID) on the portal. Authentication request packets from the controller to the RADIUS server carry the NAS ID. The RADIUS server can classify users into different groups based on the NAS ID, and then choose different policies for different groups.
Disconnected RequestsWith the feature enabled, the controller will listen on the receiver port for disconnect requests from the RADIUS server. When the controller receives the disconnect requests in correct format, the controller will terminate the RAIDIUS authentication session of the clients. Note that the feature is available only when the controller is accessible to the RADIUS server.
Receiver PortSpecify the port on which the controller listens when there are disconnect requests from the RADIUS server. Make sure that the specified port is not in use.
StatusThe entry displays the status of the receiver port, including Running, Disabled, and Error. Running means that the port is available, Disabled means that the port is closed, and Error means that the port is already in use.
Authentication Mode Select the authentication protocol for the RADIUS server.
Portal CustomizationSelect Local Web Portal or External Web Portal. The authentication login page of Local Web Portal is provided by the built-in portal server of the controller. The External Web Portal is provided by external portal server. Enter the authentication login page's URL provided by the external portal server in the External Web Portal URL field.
HTTPS RedirectionClick the checkbox to enable HTTPS Redirection. With this feature enabled, the unauthorized clients will be redirected to the Portal page when they are trying to browse HTTPS websites. With this feature disabled, the unauthorized clients cannot browse HTTPS websites and are not redirected to the Portal page.
Landing PageSelect which page the client will be redirected to after a successful authentication.The Original URL: Clients are directed to the URL they request for after they pass Portal authentication.The Promotional URL: Clients are directed to the specified URL here after they pass Portal authentication.
  1. If you choose Local Web Portal which is provided by the built-in portal server of the controller, customize the Portal page in the Portal Customization section, including the background picture, logo picture and so on.

Portal Customization

Type:

Edit Current Page

○ Import Customized Page

Default Language:

English

TP-LINK Omada OC200 - Portal Customization - 1

Background:

Solid Color

Picture

Background Picture:

Choose

TP-LINK Omada OC200 - Portal Customization - 2

Logo:

Enable

Logo Picture:

Choose

TP-LINK Omada OC200 - Portal Customization - 3

Logo Position:

Middle

TP-LINK Omada OC200 - Portal Customization - 4

Button Color:

TP-LINK Omada OC200 - Portal Customization - 5

0492eb

100

TP-LINK Omada OC200 - 0492eb - 1

Button Text color:

TP-LINK Omada OC200 - 0492eb - 2

ffffff

100

TP-LINK Omada OC200 - ffffff - 1

Button Position:

Middle

TP-LINK Omada OC200 - ffffff - 2

Welcome Information:

TP-LINK Omada OC200 - ffffff - 3

Enable

Terms of Service:

TP-LINK Omada OC200 - ffffff - 4

Enable

Copyright:

TP-LINK Omada OC200 - ffffff - 5

Enable

Type: Select the type of the Portal page.

Edit Current Page: Edit the related parameters to customize the portal page based on the provided page.

Import Customized Page: Click Import to import your unique Portal page for branding it as per your business.

Default LanguageSelect the default language displayed on the Portal page. The controller automatically adjusts the language displayed on the Portal page according to the system language of the clients. If the language is not supported, the controller will use the default language specified here.
Background Select the background type.
Solid Color: Configure your desired background color by entering the hexadecimal HTML color code manually or through the color picker.Picture: Click Choose and select a picture from your PC as the background.
Logo Click to show the logo on the portal page.
Logo PictureClick Choose and select a picture from your PC as the logo.
Logo Position Select the logo position in the Portal page.
Button ColorConfigure your desired background color for the button by entering the hexadecimal HTML color code manually or through the color picker.
Button Text ColorConfigure your desired text color for the button by entering the hexadecimal HTML color code manually or through the color picker.
Button Position Select the button position in the Portal page.
Welcome InformationClick the checkbox and enter text as the welcome information. And you can configure your desired text color for the welcome information by entering the hexadecimal HTML color code manually or through the color picker.
Terms of ServiceClick the checkbox and enter text as the terms of service in the following box.
Copyright Click the checkbox and enter text as the copyright in the following box.

Click Advertisement Options and customize advertisement pictures on the authentication page.

TP-LINK Omada OC200 - ffffff - 6

Advertisement:

TP-LINK Omada OC200 - Advertisement Options - 1

Enable

Picture Resource:

Choose

(1-5 Pictures)

TP-LINK Omada OC200 - Advertisement Options - 2

Advertisement Duration Time:

seconds

(1-30)

Picture Carousel Interval:

seconds

(1-10)

Allow Users To Skip Advertisement:

TP-LINK Omada OC200 - Advertisement Options - 3

Enable

AdvertisementClick the checkbox to enable the Advertisement feature. With this feature enabled, you can add advertisement pictures on the authentication page. These advertisement pictures will be displayed before the login page appears.
Picture ResourceClick Choose and select pictures from your PC as the advertisement pictures. When several pictures are added, they will be played in a loop.
Advertisement Duration TimeEnter the duration time for the advertisement pictures. For this duration, the pictures will be played in a loop. If the duration time is not enough for all the pictures, the rest will not be displayed.
Picture Carousel IntervalEnter the picture carousel interval. For example, if this value is set as 5 seconds, the first picture will be displayed for 5 seconds, followed by the second picture for 5 seconds, and so on.
Allow Users To Skip AdvertisementClick the checkbox to allow users to skip the advertisement.
  1. (Optional) Configure access control rules including Pre-Authentication Access and Authentication-Free Policy if needed. Go to Settings > Authentication > Portal. On Access Control tab, click the checkbox to enable Pre-Authentication Access and Authentication-Free Policy.

Access Control Pre-Authentication Access: ✓ Enable ⓘ Pre-Authentication Access List: TYPE INFORMATION ACTION ⓘ No Pre-Authentication Access entries have been configured. Authentication-Free Client: ✓ Enable ⓘ Authentication-Free Client List TYPE INFORMATION ACTION ⓘ No Authentication-Free Client hav…

Pre-Authentication AccessClick the checkbox to enable Pre-Authentication Access. With this feature enabled, unauthenticated clients are allowed to access the subnets and web resources specified in the Pre-Authentication Access List below.
Pre-Authentication Access ListClick Add to configure the IP range or URL which unauthenticated clients are allowed to access.
Authentication-Free PolicyClick the checkbox to enable Authentication-Free Policy. With this feature enabled, you can allow certain clients to access the internet without Portal authentication.
Authentication-Free Client ListClick Add and enter the IP address or MAC address of Authentication-Free clients.

■ Configuring Portal with External Portal Server

  1. Go to Settings > Authentication > Portal. On Portal tab, click + Create New Portal to create new portal entry. Then click ▼ to enable Portal and load the following page.

Create New Portal Portal Name: Portal: Controller Online Required. SSID & Network: Please Select... Authentication Type: External Portal Server Custom Portal Server: IP Address . . . . : : HTTPS Redirection: Enable i Landing Page: The Original URL The Promotional URL

  1. Select the SSIDs and LAN networks for the portal to take effect on and configure basic parameters including authentication type, custom portal server and so on.
SSID & NetworkSelect one or more SSIDs or LAN networks for the portal. The clients connected to the selected SSIDs or LAN networks have to log into a web page to establish verification before accessing the network.
Authentication Type Select the type of Portal authentication as External Portal Server.
Custom Portal Server Specify the IP address or URL that redirect to an external portal server.
HTTPS RedirectionClick the checkbox to enable HTTPS Redirection. With this feature enabled, the unauthorized clients will be redirected to the Portal page when they are trying to browse HTTPS websites. With this feature disabled, the unauthorized clients cannot browse HTTPS websites and are not redirected to the Portal page.
Landing PageSelect which page the client will be redirected to after a successful authentication.The Original URL: Clients are directed to the URL they request for after they pass Portal authentication.The Promotional URL: Clients are directed to the specified URL here after they pass Portal authentication.
  1. (Optional) Configure access control rules including Pre-Authentication Access and Authentication-Free Policy if needed. Go to Settings > Authentication > Portal. On Access Control tab, click the checkbox to enable Pre-Authentication Access and Authentication-Free Policy.

Access Control Pre-Authentication Access: ✓ Enable ⓘ Pre-Authentication Access List: TYPE INFORMATION ACTION ⓘ No Pre-Authentication Access entries have been configured. Authentication-Free Client: ✓ Enable ⓘ Authentication-Free Client List TYPE INFORMATION ACTION ⓘ No Authentication-Free Client hav…

Pre-Authentication AccessClick the checkbox to enable Pre-Authentication Access. With this feature enabled, unauthenticated clients are allowed to access the subnets and web resources specified in the Pre-Authentication Access List below.
Pre-Authentication Access ListClick Add to configure the IP range or URL which unauthenticated clients are allowed to access.
Authentication-Free PolicyClick the checkbox to enable Authentication-Free Policy. With this feature enabled, you can allow certain clients to access the internet without Portal authentication.
Authentication-Free Client ListClick Add and enter the IP address or MAC address of Authentication-Free clients.

■ Configuring Portal with Facebook

  1. Go to Settings > Authentication > Portal. Click 📋 to enable Portal and load the following page.

Create New Portal Portal Name: Portal: Controller Online Required. SSID & Network: Please Select... Authentication Type: Facebook Facebook Page Configuration: Configuration Facebook Checkin Location: None HTTPS Redirection: Enable i

  1. Select the SSIDs and LAN networks for the portal to take effect on and configure basic parameters.
SSID & NetworkSelect one or more SSIDs or LAN networks for the portal. The clients connected to the selected SSIDs or LAN networks have to log into a web page to establish verification before accessing the network.
Authentication Type Select the type of Portal authentication as Facebook.
Facebook Page Configuration:ClickConfigurationto specify the Facebook Page.
Facebook Checkin LocationWhen the Omada Controller successfully obtain the Facebook page, it will display the name of the Facebook page here.
HTTPS RedirectionClick the checkbox to enable HTTPS Redirection. With this feature enabled, the unauthorized clients will be redirected to the Portal page when they are trying to browse HTTPS websites. With this feature disabled, the unauthorized clients cannot browse HTTPS websites and are not redirected to the Portal page.
  1. In the Portal Customization section, customize the Portal page including the background picture, logo picture and so on.

Portal Customization

Type:

Edit Current Page

○ Import Customized Page

Default Language:

English

TP-LINK Omada OC200 - Portal Customization - 1

TP-LINK Omada OC200 - Portal Customization - 2

Background:

○ Solid Color

Picture

Background Picture:

Choose

TP-LINK Omada OC200 - Portal Customization - 3

Logo:

Enable

Logo Picture:

Choose

TP-LINK Omada OC200 - Portal Customization - 4

Logo Position:

Middle

TP-LINK Omada OC200 - Portal Customization - 5

Button Color:

TP-LINK Omada OC200 - Portal Customization - 6

0492eb

100

TP-LINK Omada OC200 - 0492eb - 1

Button Text color:

TP-LINK Omada OC200 - 0492eb - 2

ffffff

100

TP-LINK Omada OC200 - ffffff - 1

Button Position:

Middle

TP-LINK Omada OC200 - ffffff - 2

Welcome Information:

TP-LINK Omada OC200 - ffffff - 3

Enable

Terms of Service:

TP-LINK Omada OC200 - ffffff - 4

Enable

TP-LINK Omada OC200 - ffffff - 5

Enable

Type: Select the type of the Portal page.

Edit Current Page: Edit the related parameters to customize the portal page based on the provided page.

Import Customized Page: Click Import to import your unique Portal page for branding it as per your business.

Default LanguageSelect the default language displayed on the Portal page. The controller automatically adjusts the language displayed on the Portal page according to the system language of the clients. If the language is not supported, the controller will use the default language specified here.
Background Select the background type.
Solid Color: Configure your desired background color by entering the hexadecimal HTML color code manually or through the color picker.Picture: Click Choose and select a picture from your PC as the background.
Logo Click to show the logo on the portal page.
Logo PictureClick Choose and select a picture from your PC as the logo.
Logo Position Select the logo position in the Portal page.
Theme ColorConfigure your desired background color for the button by entering the hexadecimal HTML color code manually or through the color picker.
Button Text ColorConfigure your desired text color for the button by entering the hexadecimal HTML color code manually or through the color picker.
Button Position Select the button position in the Portal page.
Welcome InformationClick the checkbox and enter text as the welcome information. And you can configure your desired text color for the welcome information by entering the hexadecimal HTML color code manually or through the color picker.
Terms of ServiceClick the checkbox and enter text as the terms of service in the following box.
Copyright Click the checkbox and enter text as the copyright in the following box.

Click Advertisement Options and customize advertisement pictures on the authentication page.

TP-LINK Omada OC200 - ffffff - 6

Advertisement:

TP-LINK Omada OC200 - Advertisement Options - 1

Enable

Picture Resource:

Choose

(1-5 Pictures)

TP-LINK Omada OC200 - Advertisement Options - 2

Advertisement Duration Time:

seconds

(1-30)

Picture Carousel Interval:

seconds

(1-10)

Allow Users To Skip Advertisement:

TP-LINK Omada OC200 - Advertisement Options - 3

Enable

AdvertisementClick the checkbox to enable the Advertisement feature. With this feature enabled, you can add advertisement pictures on the authentication page. These advertisement pictures will be displayed before the login page appears.
Picture ResourceClick Choose and select pictures from your PC as the advertisement pictures. When several pictures are added, they will be played in a loop.
Advertisement Duration TimeEnter the duration time for the advertisement pictures. For this duration, the pictures will be played in a loop. If the duration time is not enough for all the pictures, the rest will not be displayed.
Picture Carousel IntervalEnter the picture carousel interval. For example, if this value is set as 5 seconds, the first picture will be displayed for 5 seconds, followed by the second picture for 5 seconds, and so on.
Allow Users To Skip AdvertisementClick the checkbox to allow users to skip the advertisement.

Click Advertisement Options and customize advertisement pictures on the authentication page.

TP-LINK Omada OC200 - Advertisement Options - 4

Advertisement:

TP-LINK Omada OC200 - Advertisement Options - 1

Enable

Picture Resource:

Choose

(1-5 Pictures)

TP-LINK Omada OC200 - Advertisement Options - 2

Advertisement Duration Time:

seconds

(1-30)

Picture Carousel Interval:

seconds

(1-10)

Allow Users To Skip Advertisement:

TP-LINK Omada OC200 - Advertisement Options - 3

Enable

AdvertisementClick the checkbox to enable the Advertisement feature. With this feature enabled, you can add advertisement pictures on the authentication page. These advertisement pictures will be displayed before the login page appears.
Picture ResourceClick Choose and select pictures from your PC as the advertisement pictures. When several pictures are added, they will be played in a loop.
Advertisement Duration TimeEnter the duration time for the advertisement pictures. For this duration, the pictures will be played in a loop. If the duration time is not enough for all the pictures, the rest will not be displayed.
Picture Carousel IntervalEnter the picture carousel interval. For example, if this value is set as 5 seconds, the first picture will be displayed for 5 seconds, followed by the second picture for 5 seconds, and so on.
Allow Users To Skip AdvertisementClick the checkbox to allow users to skip the advertisement.
  1. (Optional) Configure access control rules including Pre-Authentication Access and Authentication-Free Policy if needed. Go to Settings > Authentication > Portal. On the Access Control tab, click the checkbox to enable Pre-Authentication Access and Authentication-Free Policy.

Access Control Pre-Authentication Access: ✓ Enable ⓘ Pre-Authentication Access List: TYPE INFORMATION ACTION ⓘ No Pre-Authentication Access entries have been configured. Authentication-Free Client: ✓ Enable ⓘ Authentication-Free Client List TYPE INFORMATION ACTION ⓘ No Authentication-Free Client hav…

Pre-Authentication AccessClick the checkbox to enable Pre-Authentication Access. With this feature enabled, unauthenticated clients are allowed to access the subnets and web resources specified in the Pre-Authentication Access List below.
Pre-Authentication Access ListClick Add to configure the IP range or URL which unauthenticated clients are allowed to access.
Authentication-Free PolicyClick the checkbox to enable Authentication-Free Policy. With this feature enabled, you can allow certain clients to access the internet without Portal authentication.
Authentication-Free Client ListClick Add and enter the IP address or MAC address of Authentication-Free clients.

4.9.2 802.1X

Overview

802.1X provides port-based authentication service to restrict unauthorized clients from accessing the network through publicly accessible switch ports. An 802.1X-enabled port allows only authentication messages and forbids normal traffic until the client passes authentication.

802.1X authentication uses a client-server model that contains three device roles: client/supplicant, authenticator, and authentication server. This is described in the figure below:

graph LR A["Clients"] --> B["Switch Authenticator"] B --> C["Authentication Server"]

■ Client

A client, usually a computer, is connected to the authenticator via a physical port. We recommend that you install TP-Link 802.1X authentication client software on the client hosts, enabling them to request 802.1X authentication to access the LAN.

- Authenticator

An authenticator is usually a network device that supports the 802.1X protocol. As the above figure shows, the switch is an authenticator.

The authenticator acts as an intermediate proxy between the client and the authentication server. The authenticator requests user information from the client and sends it to the authentication server; also, the authenticator obtains responses from the authentication server and sends them to the client. The authenticator allows authenticated clients to access the LAN through the connected ports but denies the unauthenticated clients.

■ Authentication Server

The authentication server is usually the host running the RADIUS server program. It stores information of clients, confirms whether a client is legal and informs the authenticator whether a client is authenticated.

Based on authenticated identity, 802.1X can also deliver customized services. For example, 802.1X and VLAN Assignment together make it possible to assign different authenticated users to different VLANs automatically.

Configuration

To complete the 802.1X configuration, follow these steps:

1) Click ▶ to enable 802.1X. 2) Select the RADIUS profile you have created and configure other parameters. 3) Select the ports on which 802.1X Authentication will take effect.

Enable 802.1X Configure RADIUS Profile and Parameters Select the Ports

Go to Settings > Authentication > 802.1X. Click ▶ to enable 802.1X.

802.1X

802.1X:

TP-LINK Omada OC200 - Enable 802.1X Configure RADIUS Profile and Parameters Select the Ports - 1

TP-LINK Omada OC200 - Enable 802.1X Configure RADIUS Profile and Parameters Select the Ports - 2

Switch Required.

Enable 802.1X Configure RADIUS Profile and Parameters

Select the RADIUS profile you have created. If no RADIUS profiles have been created, click + Create New RADIUS Profile from the drop-down list or to create one. The RADIUS

profile records the information of the RADIUS server which acts as the authentication server during 802.1X authentication.

Basic Info

RADIUS Profile:

Please Select...

TP-LINK Omada OC200 - Basic Info - 1

Manage RADIUS Profile

Authentication Protocol:

○ PAP

EAP

Authentication Type:

○ Port Based

MAC Based

MAB:

Enable

Authentication Protocol

Select the authentication protocol for exchanging messages between the switch and RADIUS server. As a bridge between the client and RADIUS server, the switch forwards messages for them. It uses EAP packets to exchange messages with the client, and processes the messages according to the specified authentication protocol before forwarding them to the RADIUS server.

PAP: The EAP packets are converted to other protocol (such as RADIUS) packets, and transmitted to the RADIUS server.

EAP: The EAP packets are encapsulated in other protocol (such as RADIUS) packets, and transmitted to the authentication server. To use this authentication mechanism, the RADIUS server should support EAP attributes.

Authentication Type: Select the 802.1X authentication type.

Port Based: After a client connected to the port gets authenticated successfully, other clients can access the network via the port without authentication.

MAC Based: Clients connected to the port need to be authenticated individually. The RADIUS server distinguishes clients by their MAC addresses.

VLAN Assignment

This feature allows the RADIUS server to send the VLAN configurations to the port dynamically. After the port is authenticated, the RADIUS server assigns the VLAN based on the username of the client connecting to the port. The username-to-VLAN mappings must be already stored in the RADIUS server database. This feature is available only when the 802.1X authentication type is Port Based.

MAB

MAB (MAC Authentication Bypass) allows clients to be authenticated without any client software installed. MAB is useful for authenticating devices without 802.1X capability like IP phones. When MAB is enabled on a port, the switch will learn the MAC address of the client automatically and send the authentication server a RADIUS access request frame with the client's MAC address as the username and password. MAB takes effect only when 802.1X authentication is enabled on the port.

Enable 802.1X Configure RADIUS Profile and Parameters Select the Ports

Select the ports to enable 802.1X authentication or MAB for them. To enable 802.1X authentication, click the unselected ports. 802.1X-enabled ports will be marked with ☑. To enable MAB, click the ports marked with ☑. You can enable MAB only on 802.1X-enabled ports. MAB-enabled ports will be marked with ☑.

DEVICE NAME PORTS STATUS MODEL FIRMWARE VERSION OSW-BQ-60W Port CONNECTED T1500G-10MPS 2.0.4

Note:

  • You are not recommended to enable 802.1X authentication on the switch ports which connects to network devices without 802.1X capability like the router and APs.
  • The switch authenticates wired clients which connect to the port with 802.1X enabled. And the gateway authenticates wired clients which connect to the network with Portal configured. Wired clients should pass Portal and 802.1X authentication to access the internet when both are configured.

4.9.3 MAC-Based Authentication

Overview

MAC-Based Authentication allows or disallows clients access to wireless networks based on the MAC addresses of the clients. In this authentication method, the controller takes wireless clients' MAC addresses as their usernames and passwords for authentication. The RADIUS server authenticates the MAC addresses against its database which stores the allowed MAC addresses. Clients can access the wireless networks configured with MAC-based authentication after passing authentication successfully.

TP-LINK Omada OC200 - Overview - 1

Note:

Both MAC-Based Authentication and Portal authentication can authenticate wireless clients. If both are configured on a wireless network, a wireless client needs to pass MAC-Based Authentication first and then Portal authentication for internet access. You can enable MAC-Based Authentication Fallback to allow clients to bypass MAC-Based Authentication, which means the client needs to pass either of the two authentication methods. The client tries MAC-Based Authentication first, and is allowed to try portal authentication if it fails MAC-Based Authentication.

Configuration

  1. Go to Settings > Authentication > MAC-Based Authentication. Click ▶ to enable MAC-Based Authentication.

MAC-Based Authentication

MAC-Based Authentication:

TP-LINK Omada OC200 - MAC-Based Authentication - 1

  1. In the Basic Info, select the SSIDs, RADIUS Profile, and other required parameters. Refer to the following table to configure the required parameters and click Save.

Basic Info SSID: Please Select... RADIUS Profile: Please Select... Manage RADIUS Profile MAC-Based Authentication Fallback: Enable ⓘ MAC Address Format: Please Select... Empty Password: Enable ⓘ Save Cancel

SSID: Select one or more SSIDs for MAC-based authentication to take effect.

RADIUS Profile

Select the RADIUS profile you have created. If no RADIUS profiles have been created, click + Create New RADIUS Profile from the drop-down list or Manage RADIUS Profile to create one. The RADIUS profile records the information of the RADIUS server which acts as the authentication server during MAC-Based Authentication.

MAC-Based Authentication FallbackFor the wireless network configured with both MAC-Based Authentication and Portal, if you enable this feature, a wireless client needs to pass only one authentication. The client tries MAC-Based Authentication first, and is allowed to try Portal authentication if it failed the MAC-Based Authentication. If you disable this feature as default, a wireless client needs to pass both the MAC-Based Authentication and portal authentication for internet access, and will be denied if it fails either of the authentication.
MAC Address FormatSelect clients' MAC address format which the controller uses for authentication. Then configure the MAC addresses in the specified format as usernames for the clients on the RADIUS server.
Empty PasswordClick to allow a blank password for MAC-Based Authentication. With this option disabled, the password will be the same as the username.

4.9.4 RADIUS Profile

Overview

RADIUS (Remote Authentication Dial In User Service) is a client/server protocol that provides for the AAA (Authentication, Authorization, and Accounting) needs in modern IT environments.

In authentication services including 802.1X, Portal, and MAC-Based Authentication, Omada devices operate as clients of RADIUS to pass user information to designated RADIUS servers. A RADIUS server maintains a database which stores the identity information of legal users. It authenticates users against the database when the users are requesting to access the network, and provides authorization and accounting services for them.

A RADIUS profile records your custom settings of a RADIUS server. After creating a RADIUS profile, you can apply it to multiple authentication policies like Portal and 802.1X, saving you from repeatedly entering the same information.

Configuration

  1. Go to Settings > Authentication > RADIUS Profile. Click + Create New RADIUS Profile to load the following page.

Create New RADIUS Profile

Name:

VLAN Assignment:

Authentication Server IP:

Authentication Port:

Authentication Password:

RADIUS Accounting:

TP-LINK Omada OC200 - Create New RADIUS Profile - 1

□ Enable VLAN Assignment for Wireless Network ⓘ

TP-LINK Omada OC200 - Create New RADIUS Profile - 2

1812 (1-65535)

TP-LINK Omada OC200 - Create New RADIUS Profile - 3

Enable

  1. Enter the information of the RADIUS servers. Refer to the following table to configure the required parameters and click Save.

Name Enter a name to identify the RADIUS profile.

VLAN Assignment

This feature allows the RADIUS server to place a wireless user into a specific VLAN based on the credentials supplied by the user. To use the feature, you should create the specific VLAN first. And the user-to-VLAN mappings must be already stored in the RADIUS server database.

Note:

  1. VLAN Assignment is not currently supported when a client is authenticated by Portal with External RADIUS Server or RADIUS Hotspot.
  2. VLAN Assignment is applicable only when the device supports the feature. To make this feature work properly, it is recommended to upgrade your devices to the latest firmware version.

Authentication Server IP

Enter the IP address of the authentication server.

Authentication Port

Enter the UDP destination port on the authentication server for authentication requests.

Authentication Password

Enter the password that will be used to validate the communication between Omada devices and the RADIUS authentication server.

RADIUS Accounting

Click the checkbox to enable RADIUS Accounting to meet billing needs. This feature is only available for Omada EAPs with Portal to account for wireless clients.

Interim UpdateClick the checkbox to enable Interim Update. By default, the RADIUS accounting process needs only start and stop messages to the RADIUS accounting server. With Interim Update enabled, Omada devices will periodically send an Interim Update (a RADIUS Accounting Request packet containing an “interim-update” value) to the RADIUS server. An Interim Update updates the user’s session duration and current data usage.
Interim Update IntervalEnter an appropriate interval between the updates of users’ session duration and current data usage.
Accounting Server IPEnter the IP address of the RADIUS accounting server.
Accounting PortEnter the UDP destination port on the RADIUS server for accounting requests.
Accounting PasswordEnter the password that will be used to validate the communication between Omada devices and the RADIUS accounting server.

TP-LINK Omada OC200 - Create New RADIUS Profile - 4

4.10 Services

Services provide convenient network services and facilitate network management. You can configure servers or terminals in DDNS, SNMP, UPnP, and SSH, schedule the devices in Reboot Schedule and PoE Schedule, and export the running logs in Export Data.

4. 10. 1 Dynamic DNS

Overview

The WAN IP address of your gateway can change periodically because your ISP typically employs DHCP among other techniques. This is where Dynamic DNS comes in. Dynamic DNS assigns a fixed domain name to the WAN port of your gateway, which facilitates remote users to access your local network through the WAN port.

Let's illustrate how Dynamic DNS works with the following figures.

Before:

  • The WAN IP address can change periodically if it's dynamically assigned by the ISP using DHCP among other techniques.
  • A remote user doesn't know what the WAN IP address is exactly at the moment, and cannot access the local network.

Not sure about the WAN IP address. Can't access the local network.

Remote UserTP-LINK Omada OC200 - Before: - 1

TP-LINK Omada OC200 - Before: - 2

WAN IP address changes: 2020/05/27: 172.217.174.196 2020/05/28: 172.217.174.208

WAN Port

GatewayTP-LINK Omada OC200 - Before: - 3

Local Network

After:

- A remote user can simply use the domain name to access the local network through the WAN port. In this example, the domain name is mysite.ddns.net.

graph LR A["Service Provider"] --> B["Internet"] B --> C["Remote User"] C --> D["Gateway"] D --> E["Local Network"] style A fill:#4CAF50,stroke:#388E3C style B fill:#2196F3,stroke:#333 style C fill:#FFA500,stroke:#333 style D fill:#2196F3,stroke:#333 style E fill:#2196F3,stroke:#333

Prerequisite:

  • Choose one Service Provider from the four that the controller supports, i.e. DynDNS, No-IP, Peanuthull, Comexe.
  • Register at your Service Provider, then you get your Username and Password. • Get your Domain Name from your Service Provider.

How Dynamic DNS works:

① Gateway informs Service Provider of WAN IP Address. ② Service Provider binds WAN IP Address with Domain Name and keeps it updated as WAN IP Address changes. ③ Remote User requests for WAN IP Address by sending Domain Name to Service Provider. ④ Service Provider replies with WAN IP Address, which Remote User actually uses to access Local Network through WAN Port.

graph TD A["Remote User"] -->|4| B["Service Provider"] B -->|3| C["Internet"] C -->|1| D["WAN Port LAN Port"] D --> E["Gateway"] F["Local Network"] -->|2| G["Dynamic DNS Binding: 2020/05/27: 172.217.174.196 --> mysite.ddns.net\n2020/05/28: 172.217.174.208 --> mysite.ddns.net ..."] H["WAN IP Address…

Configuration

Go to Settings > Services > Dynamic DNS. Click + Create New Dynamic DNS Entry, to load the following page. Configure the parameters and click Create.

Create New Dynamic DNS Entry

Service Provider:

DynDNS

Status:

Enable

Interface:

SFP WAN

○ WAN

Username:

Password:

Domain Name:

Update Interval:

Create

Cancel

Go To Register

TP-LINK Omada OC200 - Create New Dynamic DNS Entry - 1

Please Select.

Service Provider: Select your service provider which Dynamic DNS works with.

Status: Enable or disable the Dynamic DNS entry.

Interface: Select the WAN Port which the Dynamic DNS entry applies to.

Username

Enter your username for the service provider. If you haven't registered at the service provider, click Go To Register.

Password: Enter your password for the service provider.

Domain Name

Enter the Domain Name which is provided by your service provider. Remote users can use the Domain Name to access your local network through WAN port.

Update Interval: Select how often the WAN IP address is updated with the Domain Name.

4.10.2 SNMP

Overview

SNMP (Simple Network Management Protocol) provides a convenient and flexible method for you to configure and monitor network devices. Once you set up SNMP for the devices, you can centrally manage them with an NMS (Network Management Station).

The controller supports multiple SNMP versions including SNMPv1, SNMPv2c, and SNMPv3.

TP-LINK Omada OC200 - Overview - 1

Note:

If you use an NMS to manage devices that are managed by the controller, you can only read but not write SNMP objects.

Configuration

Go to Settings > Services > SNMP and configure the parameters. Then click Apply.

SNMPv1 & SNMPv2c

SNMPv1 & SNMPv2c:

TP-LINK Omada OC200 - SNMPv1 &amp; SNMPv2c - 1

Community String:

TP-LINK Omada OC200 - SNMPv1 &amp; SNMPv2c - 2

SNMPv3

SNMPv3:

TP-LINK Omada OC200 - SNMPv3 - 1

Username:

TP-LINK Omada OC200 - SNMPv3 - 2

Password:

TP-LINK Omada OC200 - SNMPv3 - 3

SNMPv1 & SNMPv2c Enable or disable SNMPv1 and SNMPv2c globally.

Community String

With SNMPv1 & SNMPv2c enabled, specify the Community String, which is used as a password for your NMS to access the SNMP agent. You need to configure the Community String correspondingly on your NMS.

SNMPv3 Enable or disable SNMPv3 globally.

Username

With SNMPv3 enabled, specify the username for your NMS to access the SNMP agent. You need to configure the username correspondingly on your NMS.

Password

With SNMPv3 enabled, specify the password for your NMS to access the SNMP agent. You need to configure the password correspondingly on your NMS.

4.10.3 UPnP

Overview

UPnP (Universal Plug and Play) is essential for applications including multiplayer gaming, peer-to-peer connections, real-time communication (such as VoIP or telephone conference) and remote assistance, etc. With the help of UPnP, the traffic between the endpoints of these applications can freely pass the gateway, thus realizing seamless connections.

Configuration

Go to Settings > Services > UPnP. Enable UPnP globally and configure the parameters. Then click Apply.

UPnP

UPnP:

Interface:

TP-LINK Omada OC200 - Configuration - 1

□ SFP WAN

WAN

0/5 Items

□ LAN □ user □ sdn controller □ sdn switch □ ipv6_test

Apply

Reset

Interface: Select the WAN port where UPnP takes effect.

Networks: Select the LAN interface where UPnP takes effect.

4.10.4 SSH

Overview

SSH (Secure Shell) provides a method for you to securely configure and monitor network devices via a command-line user interface on your SSH terminal.

TP-LINK Omada OC200 - Overview - 1

Note:

If you use an SSH terminal to manage devices which are managed by the controller, you can only get the User privilege.

Configuration

Go to Settings > Services > SSH. Enable SSH Login globally and configure the parameters. Then click Apply.

SSH SSH Login: SSH Server Port: 22 (22 or 1025-65535) Layer 3 Accessibility: Enable i Apply Reset

SSH Server PortSpecify the SSH Sever Port which your network devices use for SSH connections. You need to configure the SSH Server Port correspondingly on your SSH terminal.
Layer 3 AccessibilityWith this feature enabled, the SSH terminal from a different subnet can access your devices via SSH. With this feature disabled, only the SSH terminal in the same subnet can access your devices via SSH.

4.10.5 Reboot Schedule

Overview

Reboot Schedule can make your devices reboot periodically according to your needs. You can configure Reboot Schedule flexibly by creating multiple Reboot Schedule entries.

Configuration

  1. Go to Settings > Services > Reboot Schedule. Click + Create New Reboot Schedule to load the following page and configure the parameters.

Create New Reboot Schedule Name: Status: ✓ Enable Occurrence: Every Month on 1 at 12.00 in America/Bogota Devices List: DEVICE NAME STATUS MODEL FIRMWARE VERSION 88-86-77-99-44.20 CONNECTED TL.EF7300 1.0.0 Build 20200331 Rd.63799 00:00.FF.FF-0E.A0 CONNECTED EAP650 HD 1.0.0 Build 20200319 Rd. 78769 0…

Name: Enter the name to identify the Reboot Schedule entry.

Status: Enable or disable the Reboot Schedule entry.

Occurrence: Specify the date and time for the devices to reboot.

Devices List: Select the devices which the Reboot Schedule applies to.

  1. Click Create. The new Reboot Schedule entry is added to the table. You can click the edit icon to edit the entry. You can click the delete icon to delete the entry.

NAME ENABLED NEXT EXECUTION DEVICES ACTION SpBIX ●-Aug 01, 2029 12:08:00 CC-32-E5-M4-B1-AC Showing 1-1 of 1 records < 1 > 5/page Ga To page: GO + CreateNewRebootSchedule

4.10.6 PoE Schedule

Overview

PoE Schedule can make PoE devices which are connected to your PoE switches power on and work only in the specific time period as you desire. You can configure PoE Schedule flexibly by creating multiple PoE Schedule entries.

Configuration

  1. Go to Settings > Services > PoE Schedule. Click + Create New PoE Schedule to load the following page and configure the parameters.

Create New PoE Schedule Name: Status: Enable Time Range: Please select a Time Range entry. Manage Time Range Colors Devices List: DEVICE NAME PORTS STATUS MODEL FIRMWARE VERSION 00-0A-EB-45-F7-A5 CONNECTED TL-8G2210MP Showing 1-1 of 1 records < 1 > 5 page Go To page GO Create Cancel

Name: Enter the name to identify the PoE Schedule entry.

Status: Enable or disable the PoE Schedule entry.

Time RangeSelect the Time Range when the PoE devices work. You can create a Time Range entry by clicking + Create New Time Range Entry from the drop down list of Time Range. For details, refer to Profiles.
Devices ListSelect the PoE switches and PoE ports which the PoE Schedule applies to. Your PoE devices connected to the selected ports of the switches work according to the PoE Schedule.
  1. Click Create. The new PoE Schedule entry is added to the table. You can click ☑ to edit the entry. You can click 🔒 to delete the entry.

NAME ENABLED NEXT EXECUTION DEVICES ACTION tp-link ● Jul 10, 2020 18:00:00 switch Showing 1-1 of 1 records ( 1 > 5 /page Go to page GO + CreateNewPoESchedule

4.10.7 Export Data

Overview

You can export data to monitor or debug your devices.

Configuration

Go to Settings > Services > Export Data. Select the type of data from the export list and click Export.

Export Data Export List: Device List Mode: All Columns Current display columns Format: CSV Export

Export List: Device List: Export the list of managed devices.

Client List: Export the list of all clients that are connected to the networks.

Insight-Rogue AP List: Export the list of the rogue APs scanned before. For detailed information, refer to 8.4.9 Rogue APs.

Log List: Export the list of the logs generated by the controller.

Authorized Client List: Export the list of authorized clients.

Voucher Codes: Export the list of the voucher codes.

Running Log: Export the day-to-day running log of the controller.

Mode All Columns: Export the data list that contains all columns.

Current Display Columns: Export the data list that contains only the displayed columns currently.

Format: The data can be exported to the file in the format of .CSV or .XLSX.

5

Configure the Omada SDN Controller

Controller Settings control the appearance and behavior of the controller and provide methods of data backup, restore and migration:

• 5.1 Manage the Controller • 5.2 Manage Your Controller Remotely via Cloud Access • 5.3 Maintenance • 5.4 Migration • 5.5 Auto Backup

TP-LINK Omada OC200 - Configure the Omada SDN Controller - 1

5.1 Manage the Controller

5.1.1 General Settings

Configuration

Go to Settings > Controller. In General Settings, configure the parameters and click Save.

■ For Omada Hardware Controller

General Settings

Controller Name:OC200_AE20DC
Time Zone:(UTC) Casablanca
Daylight Saving Time:Enable

TP-LINK Omada OC200 - ■ For Omada Hardware Controller - 1

- DST is applicable only when the device supports the feature. To make DST work properly, it is recommended to upgrade your devices to the latest firmware version. - The DST configuration here only takes effect on the controller. To configure the DST for sites, go to the Site Configuration. - With DST configured, the valid duration of Local User will be influenced accordingly.

Time Offset: 60 minutes (1-120) Starts On: Week: Day: Month: Time 1st Sunday January 00:00 Ends On: Week: Day: Month: Time 1st Sunday October 00:00 Primary NTP Server: 0.0.0 Secondary NTP Server: 0.0.0 Reset Button: Network Settings: Static DHCP IP Address: . . . Netmask: . . . Gateway: . . . Primar…

Controller Name: Specify the Controller Name to identify the controller.

Time Zone

Select the Time Zone of the controller according to your region. For controller settings and statistics, time is displayed based on the Time Zone.

Daylight Saving Time

Enable the feature if your country/region implements DST. When it is enabled, the icon DST will appear on the upper right, showing the DST settings and status.

Time Offset: Specify the time added in minutes when Daylight Saving Time starts.

Starts OnSpecify the time when the DST starts. The clock will be set forward by the time offset you specify.
Ends OnSpecify the time when the DST ends. The clock will be set back by the time offset you specify.
Primary NTP Server/Secondary NTP ServerEnter the IP address of the primary and secondary NTP (Network Time Protocol) server. NTP servers assign network time to the controller.

Reset Button: With this feature enabled, the controller can be reset via reset button.

Network Settings: Select one way for the controller to get IP settings.

Static: You need to specify the IP address, Netmask, Gateway, Primary DNS, and Secondary DNS for the controller.

DHCP: The controller gets IP settings from the DHCP server. If the controller fails to get IP settings from the DHCP server, it will use the Fallback IP Address and Fallback Netmask.

■ For Omada Software Controller / Omada Cloud-Based Controller

General Settings Controller Name: TP-LINK 24 Time Zone: (UTC+03:00) Beijing, Chongqing, Hong Kong, Ur Daylight Saving Time: Enable • DST is applicable only when the device supports the feature. To make DST work properly, it is recommended to upgrade your devices to the latest firmware version. • The…

Controller Name: Specify the Controller Name to identify the controller.

Time ZoneSelect the Time Zone of the controller according to your region. For controller settings and statistics, time is displayed based on the Time Zone.

Daylight Saving Time: Enable the feature if your country/region implements DST.

Time Offset: Specify the time added in minutes when Daylight Saving Time starts.

Starts OnSpecify the time when the DST starts. The clock will be set forward by the time offset you specify.
Ends OnSpecify the time when the DST ends.The clock will be set back by the time offset you specify.

5.1.2 Mail Server

Overview

With the Mail Server, the controller can send emails for resetting your password, pushing notifications, and delivering the system logs. The Mail Server feature works with the SMTP (Simple Mail Transfer Protocol) service provided by an email service provider.

Configuration

  1. Log in to your email account and enable the SMTP (Simple Mail Transfer Protocol) Service. For details, refer to the instructions of your email service provider.
  2. Go to Settings > Controller. In Mail Server, enable SMTP Server and configure the parameters. Then click Save.

Mail Server

TP-LINK Omada OC200 - Mail Server - 1

With the Mail Server, the controller can send emails for resetting your password, pushing notifications, and delivering the system logs. For security reasons, we recommend that you configure Mail Server carefully.

SMTP Server:

Enable

SMTP:

TP-LINK Omada OC200 - Mail Server - 2

Port:

465 (1-65535)

SSL:

Enable

Authentication:

Enable

Username:

TP-LINK Omada OC200 - Mail Server - 3

Password:

TP-LINK Omada OC200 - Mail Server - 4

Sender Address:

TP-LINK Omada OC200 - Mail Server - 5

Test SMTP Server:

Send Test Email to

Send

SMTPEnter the URL or IP address of the SMTP server according to the instructions of the email service provider.
Port Configure the port used by the SMTP server according to the instructions of the email service provider.
SSL Enable or disable SSL according to the instructions of the email service provider. SSL (Secure Sockets Layer) is used to create an encrypted link between the controller and the SMTP server.
AuthenticationEnable or disable Authentication according to the instructions of the email service provider. If Authentication is enabled, the SMTP server requires the username and password for authentication.
Username When Authentication is enabled, enter your email address as the username.
PasswordWhen Authentication is enabled, enter the authentication code as the password, which is provided by the email service provider when you enable the SMTP service.
Sender Address(Optional) Specify the sender address of the email. If you leave it blank, the controller uses your email address as the Sender Address.
Test SMTP ServerTest the Mail Server configuration by sending a test email to an email address that you specify.

5.1.3 History Data Retention

Overview

With History Data Retention, you can specify how the controller retains its data.

Configuration

Go to Settings > Controller. In History Data Retention, configure the parameters and click Save.

History Data Retention
Data Retention:6 Months
Collect Clients' History Data:Enable

Data Retention

Select how long the controller retains its data. Any history data beyond the time range is dropped.

Collect Clients' History Data

With Collect Clients' History Data enabled, the history data of the clients are included in that of the controller.

5.1.4 Customer Experience Improvement Program

Configuration

Click the checkbox if you agree to participate in the customer experience improvement program and help improve the quality and performance of TP-Link products by sending statistics and usage information.

Customer Experience Improvement Program

☑ Participate in the customer experience improvement program and help improve the quality and performance of TP-Link products by sending statistics and usage information.

5.1.5 HTTPS Certificate

Overview

If you have assigned a domain name to the controller for login, to eliminate the "untrusted certificate" error message that will appear in the login process, you can import the corresponding SSL certificate and private key here. The certificate and private key are issued by the certificate authority.

Note:

  • HTTPS Certificate configuration is only available for Omada Software Controller and Omada Hardware Controller.
  • You need to restart your controller for the imported SSL certificate to take effect.

Configuration

Go to Settings > Controller. In HTTPS Certificate, import your SSL certificate and configure the parameters. Then click Save.

HTTPS Certificate

TP-LINK Omada OC200 - HTTPS Certificate - 1

If you have assigned a domain name to the Omada Controller for login, to eliminate the "untrusted certificate" error message that will appear in the login process, you can import the corresponding SSL certificate and private key here. The certificate and private key are issued by the certificate authority. Note that you should restart your controller for the imported SSL certificate to take effect.

SSL Certificate:

Import

Keystore Password:

TP-LINK Omada OC200 - HTTPS Certificate - 2

TP-LINK Omada OC200 - HTTPS Certificate - 3

Private Key Password:

TP-LINK Omada OC200 - HTTPS Certificate - 4

TP-LINK Omada OC200 - HTTPS Certificate - 5

Keystore Password

Enter the keystore password if your SSL certificate has the keystore password. Otherwise, leave it blank.

Private Key Password

Enter the private key password if your SSL certificate has the private key password. Otherwise, leave it blank.

5.1.6 Access Config

Overview

With Access Config, you can specify the port used by the controller for management and portal.

! Note:

  • Access Config is only available on Omada Software Controller and Omada Hardware Controller.
  • Once applying the change of HTTPS and HTTP port, restart the controller to make the change effective.
  • For security, the HTTPS and HTTP port for Portal should be different from that for controller management.

Configuration

Go to Settings > Controller. In Access Config, configure the parameters and click Save.

Access Config

Controller Hostname/IP:

192.168.0.163:8043

TP-LINK Omada OC200 - Access Config - 1

HTTPS Port for Controller

8043

(443 or 1024-65535)

Management:

TP-LINK Omada OC200 - Access Config - 2

Once applying the change of HTTPS port, restart the controller to make the change effective. After restart, visit the URL https://Omada Controller Host's IP Address_or_URL:port number to log in to the Omada Controller.

HTTPS Port for Portal:

8843

(1024-65535)

HTTP Port for Portal:

8088

(80 or 1024-65535)

TP-LINK Omada OC200 - Access Config - 3

Once applying the change of HTTPS and HTTP port, restart the controller to make the change effective. For security, the HTTPS and HTTP port for Portal should be different from that for controller management.

Save

Cancel

Controller Hostname/IPEnter the hostname or IP address of the controller which will be used as the Controller URL in the notification email for resetting your controller password. You can keep it default and IP address recognized by the controller will be used as the Controller URL.
HTTPS Port for Controller ManagementSpecify the HTTPS port used by the controller for management. After setting the port, you can visit https://[Omada Controller Host's IP address or URL]:[Port] to log in to the Omada Controller.

HTTPS Port for Portal Specify the HTTPS port used by the controller for Portal.

HTTP Port for Portal Specify the HTTP port used by the controller for Portal.

5.2 Manage Your Controller Remotely via Cloud Access

Overview

With Cloud Access, it's convenient for you to manage your controller from anywhere, as long as you have access to the internet.

Configuration

To manage your controller from anywhere, follow these steps:

  1. Prepare your controller for Cloud Access

■ For Omada Software Controller / Omada Hardware Controller:

① Note:

• Before you start, make sure your Omada Software Controller Host or Omada Hardware Controller has access to the internet. - If you have enabled cloud access and bound your TP-Link ID in the quick setup wizard, skip this step.

1) Go to Settings > Cloud Access. Enable Cloud Access.

Cloud Access Cloud Access: Cloud Access Status: CONNECTED

2) Enter your TP-Link ID and password. Then click Log In and Bind.

Log In and Bind Your TP-Link ID Enter the email address and password of your TP-Link ID. Note that it is not the account that you have used to log in to this controller. TP-Link ID: Email Address No TP-Link ID? Register Now Password: Log In and Bind Cancel

■ For Omada Cloud-Based Controller

Your Omada Cloud-Based Controller is based on the Cloud, so it's naturally accessible through Cloud Service. No additional preparation is needed.

2. Access your controller through Cloud Service

Go to Omada Cloud and login with your TP-Link ID and password. A list of controllers that have been bound with your TP-Link ID will appear. Then click → Launch to manage the controller.

All OC200 Software Controller Add -software controller NAME MAC ADDRESS LOCAL IP STATUS SITES DEVICES CLIENTS ALERTS Som/VERSION FIRMWARE ACTION Omoda Controller_801C5F - 13.0.3.20 Online 2 1 0 37 40,7 - Page Size: 10-<<<1>>

TP-LINK Omada OC200 - Access your controller through Cloud Service - 2

5.3 Maintenance

5.3.1 Controller Status

Go to Settings > Maintenance. In Controller Status, you can view the controller-related information and status.

Controller Status

Controller Name:Omada Controller
MAC Address:F8-BC-12-6D-71-57
System Time:Nov 23, 2020 02:20:44 pm
Uptime:9day(s) 21h 9m 8s
Controller Version:4.3.5
Controller NameDisplays the controller name, which identifies the controller. You can specify the controller name in5.1.1 General Settings.
MAC Address Displays the MAC address of the controller.
System TimeDisplays the system time of the controller. The system time is based on the time zone which you configure in5.1.1 General Settings.
Uptime Displays how long the controller has been working.
Controller Version Displays the software version of the controller.

5.3.2 User Interface

Overview

You can customize the User Interface settings of the controller according to your preferences.

Configuration

Go to Settings > Maintenance. In User Interface, configure the parameters and click Apply.

User Interface Use 24-Hour Time: Statistic/Dashboard Timezone: Site's Fixed Menu: Show Pending Devices: Refresh Button: Refresh Interval: 2 minutes Enable WebSocket Connection: Apply Cancel

Use 24-Hour TimeWith Use 24-Hour Time enabled, time is displayed in a 24-hour format. With Use 24-Hour Time disabled, time is displayed in a 12-hour format.
Statistic/Dashboard TimezoneSelect which Timezone the time of statistics and the dashboard is based on.Site's: Site's Timezone is set in Site Configuration of the corresponding site.Browser's: Browser's Timezone is synchronized with the browser configuration.Controller's: Controller's Timezone is set in General Settings of the controller.UTC: UTC (Coordinated Universal Time) is the common time standard across the world.
Fixed Menu With Fixed Menu enabled, the menu icons are fixed and do not prompt menu texts when your mouse hovers on them.
Show Pending DevicesWith this option enabled, the devices in Pending status will be shown, and you can determine whether to adopt them. With this option disabled, they will not be shown, thus you cannot adopt any new devices.
Refresh ButtonEnable or disable Refresh Button in the upper right corner of the configuration page.
Refresh IntervalSelect how often the controller automatically refreshes the data displayed on the page.
Enable WebSocket ConnectionWith WebSocket Connection enabled, the controller updates in real time some part of its data on the web interface, which is transmitted using the WebSocket service, so that you don't need to refresh them manually.

You can backup the configuration and data of your controller to prevent any loss of important information. If necessary, restore the controller to a previous status using the backup file.

Configuration

Backup

Go to Settings > Maintenance. In Backup & Restore, select the time range in the drop-down menu of Retained Data Backup. Only configuration and data within the time range is backed up. If you select Settings Only, only configuration (no data) is backed up. Click Download Backup Files to download the backup file to your computer.

Backup & Restore Backup Retained Data Backup: Settings Only Download Backup Files Retained Data Backup has been set as Settings Only, no data will be backed up. Note that all configurations and data about licenses will not be backed up, including Auto-Activation, Auto-Renewal and license logs. Resto…

Restore

Go to Settings > Maintenance. In Backup & Restore section, Click Browse and select a backup file from your computer. Click Restore.

Backup & Restore Backup Retained Data Backup: Settings Only Download Backup Files Retained Data Backup has been set as Settings Only, no data will be backed up. Note that all configurations and data about licenses will not be backed up, including Auto-Activation, Auto-Renewal and license logs. Resto…

TP-LINK Omada OC200 - Restore - 2

5.4 Migration

Migration services allow users to migrate the configurations and data to any other controller. Migration services include 5.4.1 Site Migration and 5.4.2 Controller Migration, covering all the needs to migrate both a single site and the whole controller.

Site Migration allows the administrators to export a site from the current controller to any other controller that has the same version. All the configurations and data of the site will be migrated to the target controller.

The process of migrating configurations and data from a site to another controller can be summarized in three steps: Export Site, Migrate Site and Migrate Devices.

Site Migration

Abstract diagram with blue location pins and dashed arrows, no text or symbols present

Site A on Controller A Site A on Controller B

graph LR A["1"] --> B["2"] B --> C["3"]

Export Site Migrate Site Migrate Devices

Export the configurations and data of Site A on Controller A

Import the configurations and data of Site A to Controller B

Migrate the devices on Site A to Controller B

Step 1: Export Site

Export the configurations and data of the site to be migrated as a backup file.

Step 2: Migrate Site

In the target controller, import the backup file of the original site.

Step 3: Migrate Devices

Migrate the devices that are on the original site to the target controller.

Configuration

To migrate a site to another controller, follow these steps below.

Note:

The connection to the internet will be lost for several minutes during the migration. Clients need to connect to the wireless network again after the migration is completed. Please choose the time to start the migration operation carefully.

Export Site, Migrate Site, Migrate Devices

  1. Go to Settings > Migration. On the Site Migration tab, click the start button on the following page.

Site Migration Controller Migration Site Migration Site Migration allows Omada administrators to export a site from the current controller to any other controller that has the same version. All the configurations and data of the site will be migrated to the target controller. Warning: The connection…

  1. Select the site to be imported into the second controller in the Select Site drop-down list. Click Export to download the file of the current site. If you have backed up the file, click Skip.

Site Migration Controller Migration 1 Export Site —— 2 Migrate Site —— 3 Migrate Devices —— 4 Done Select a site and export its configurations and data as a backup file. The file can be imported to any other controller that has the same version. Select Site: Site A Export Skip

Export Site Migrate Site Migrate Center

  1. Start and log in to the target controller, click the top-right corner of the

screen and select ↗ Import Site, and then the following window will pop up. Note that for controller v 4.3.0 and above, only the file from the controller with the same major and minor version number can be imported.

Import Site Site Name: Choose File: Please select a file. Browse i For controller v 4.3.0 and above, only the file from the controller with the same major and minor version number can be imported.

  1. Enter a unique name for the new site. Click Browse to upload the file of the site to be imported and click Import to import the site.
  2. After the file has been imported to the target controller, go back to the previous controller and click Confirm.

Site Migration Controller Migration ✓ Export Site —— 2 Migrate Site —— 3 Migrate Devices —— 4 Done To migrate your site, import the backup file into your target controller. Log into the target controller and go to Site Management to click the Import Site in the Site Management drop-down menu and upl…

Export Site Migrate Site Migrate Devices

  1. Enter the IP address or URL of your target controller into Controller IP/Inform URL input field. In this case, the IP address of the target controller is 10.0.3.23.

Site Migration Controller Migration ✓ Export Site —— ✓ Migrate Site —— 3 Migrate Devices —— 4 Done Select the devices to be migrated and enter the URL or IP address of your target controller. The selected devices will try to discover the target controller. Controller IP/Inform URL: 10.0.3.23

TP-LINK Omada OC200 - Export Site Migrate Site Migrate Devices - 2

Note:

Make sure that you enter the correct IP address or URL of the target controller to establish the communication between Omada managed devices and your target controller. Otherwise Omada managed devices cannot be adopted by the target controller.

  1. Select the devices that are to be migrated by clicking the box next to each device. By default, all the devices are selected. Click Migrate Devices to migrate the selected devices to the target controller.

Site Migration Controller Migration ✓ Export Site —— ✓ Migrate Site —— 3 Migrate Devices —— 4 Done Select the devices to be migrated and enter the URL or IP address of your target controller. The selected devices will try to discover the target controller. Controller IP/Inform URL: 10.0.3.23 Device…

  1. Verify that all the migrated devices are visible and connected on the target controller. When all the migrated devices are in Connected status on the Device page on the target controller, click Forget Devices to finish the migration process.

Site Migration Controller Migration ✓ Export Site ✓ Migrate Site ✓ Migrate Devices 4 Done Migration succeeded! We suggest you forget the successfully migrated devices. Go to the Device page of your target controller and check if the migrated devices are visible and connected. This process may take s…

  1. When the migration process is completed, all the configuration and data are migrated to the target controller. You can delete the previous site if necessary.

5.4.2 Controller Migration

Overview

Controller Migration allows Omada administrators to migrate the configurations and data from the current controller to any other controller that has the same version.

The process of migrating configurations and data from the current controller to another controller can be summarized in three steps: Export Controller, Migrate Controller and Migrate Devices.

Controller Migrationgraph LR A["Controller A"] -->|dashed arrow| B["Controller B"] B -->|dashed arrow| A style A fill:#cce5ff,stroke:#333 style B fill:#cce5ff,stroke:#333

Export Controller Migrate Controller Migrate Devices

Export the configurations and data of Controller A

Import the configurations and data of Controller A to Controller B

Migrate the devices on Controller A to Controller B

Step1: Export Controller

Export the configurations and data of the current controller as a backup file.

Step2: Migrate Controller

In the target controller, import the backup file of the current controller.

Step3: Migrate Devices

Migrate the devices on the current controller to the target controller.

Configuration

To migrate your controller, follow these steps below.

TP-LINK Omada OC200 - Configuration - 1

Note:

The connection to the internet will be lost for several minutes during the migration. Clients need to connect to the wireless network again after the migration is completed. Please choose the time to start the migration operation carefully.

Export Controller Migrate Controller Migrate Devices

  1. Go to Settings > Migration. On the Controller Migration tab, click the start button on the following page.

TP-LINK Omada OC200 - Export Controller Migrate Controller Migrate Devices - 1

Site Migration

TP-LINK Omada OC200 - Export Controller Migrate Controller Migrate Devices - 2

Controller Migration

graph TD A["服务器设备"] --> B["服务器硬件"] B --> A

Controller Migration

Controller Migration allows Omada administrators to migrate your configurations and data from the current controller to any other controller that has the same version.

Warning: The connection to the internet will be lost for several minutes during the migration. Clients need to connect to the wireless network again after the migration is completed. Please choose the time to start the migration operation carefully.

Start

  1. Select the length of time in days that data will be backed up in the Retained Data Backup, and click Export to export the configurations and data of your current controller as a backup file. If you have backed up the file, click Skip.

TP-LINK Omada OC200 - Controller Migration - 1

Export the configurations and data of your current controller as a backup file.

The file can be imported to any other controller that has the same version.

Retained Data Backup:

Settings Only

TP-LINK Omada OC200 - Export the configurations and data of your current controller as a backup file. - 1

TP-LINK Omada OC200 - Export the configurations and data of your current controller as a backup file. - 2

Retained Data Backup has been set to Settings Only, no data will be backed up. Note that all configurations and data about licenses will not be backed up, including Auto-Activation, Auto-Renewal and license logs.

Export

Skip

Export Controller Migrate Controller Migrate Control

  1. Log in to the target controller, go to Settings > Maintenance > Backup & Restore. Click Browse to locate and choose the backup file of the previous controller. Then click Restore to upload the file.

Backup & Restore Backup Retained Data Backup: Settings Only Download Backup Files Retained Data Backup has been set as Settings Only, no data will be backed up. Note that all configurations and data about licenses will not be backed up, including Auto-Activation, Auto-Renewal and license logs. Resto…

  1. After the file has been imported to the target controller, go back to the previous controller and click Confirm.

Site Migration Controller Migration Export Controller —— 2 Migrate Controller —— 3 Migrate Devices —— 4 Done Log into the target controller and go to Maintenance- Backup & Restore and upload the backup file of your controller. Confirm Skip

Export Controller Migrate Controller Migrate Devices

  1. Enter the IP address or URL of your target controller into the Controller IP/Inform URL input field. In this case, the IP address of the target controller is 10.0.3.23.

Site Migration Controller Migration ✓ Export Controller —— ✓ Migrate Controller —— 3 Migrate Devices —— 4 Done Select the devices to be migrated and enter the URL or IP address of your target controller. The selected devices will try to discover the target controller. Controller IP/Inform URL: 10.0.…

Note:

Make sure that you enter the correct IP address or URL of the target controller to establish the communication between Omada managed devices and your target controller. Otherwise, Omada managed devices cannot be adopted by the target controller.

  1. Select the devices that are to be migrated by clicking the box next to each device. By default, all the devices are selected. Click Migrate Devices to migrate the selected devices to the target controller.

Site Migration Controller Migration ✓ Export Controller ✓ Migrate Controller 3 Migrate Devices 4 Done Select the devices to be migrated and enter the URL or IP address of your target controller. The selected devices will try to discover the target controller. Controller IP/Inform URL: 10.0.3.23 Devi…

  1. Verify that all the migrated devices are visible and connected on the target controller. When all the migrated devices are in Connected status on the Device page on the target controller, click Forget Devices to finish the migration process.

Site Migration Controller Migration ✓ Export Controller ✓ Migrate Controller 3 Migrate Devices 4 Done Select the devices to be migrated and enter the URL or IP address of your target controller. The selected devices will try to discover the target controller. Controller IP/Inform URL: 10.0.3.23 Devi…

When the migration process is completed, all the configuration and data are migrated to the target controller. You can uninstall the previous controller if necessary.

TP-LINK Omada OC200 - Note: - 3

5.5 Auto Backup

Overview

With Auto Backup enabled, the controller will be scheduled to back up the configurations and data automatically at the specified time. You can easily restore the configurations and data when needed.

TP-LINK Omada OC200 - Overview - 1

Note:

• For OC200, Auto Backup is available only when it is powered by a PoE device and a storage device is connected to its USB port. - On Omada Cloud-Based Controller, you have no need to configure Auto Backup. It will automatically save your configurations and data on the cloud.

Configuration

To configure Auto Backup, follow these steps:

  1. Go to Settings > Auto Backup. Click ▶ to enable Auto Backup.

Auto Backup

Auto Backup:

TP-LINK Omada OC200 - Auto Backup - 1

  1. Configure the following parameters to specify the rules of Auto Backup. Click Apply.

Auto Backup

Auto Backup:

TP-LINK Omada OC200 - Auto Backup - 1

Occurrence:

Every

Day

TP-LINK Omada OC200 - Auto Backup - 2

03:00

TP-LINK Omada OC200 - Auto Backup - 3

in (UTC-06:00) Central America

TP-LINK Omada OC200 - Auto Backup - 4

Maximum Number of Files:

50

(1-50)

Retained Data Backup:

1 Month

TP-LINK Omada OC200 - Auto Backup - 5

TP-LINK Omada OC200 - Auto Backup - 6

Retained Data Backup has been set as 1 month, data only in recent 1 month will be backed up. Note that all configurations and data about licenses will not be backed up, including Auto-Activation, Auto-Renewal and license logs.

Occurrence

Specify when to perform Auto Backup regularly. Select Every Day, Week, Month, or Year first and then set a time to back up files.

Note the time availability when you choose Every Month. For example, if you choose to automatically backup the data on the 31st of every month, Auto Backup will not take effect when it comes to the month with no 31st, such as February, April, and June.

Maximum Number of Files Specify the maximum number of backup files to save.

Retained Data Backup Select the length of time in days that data will be backed up.

Settings Only: Back up controller settings only.

7 Days/1 Month/2 Months/3 Months/6 Months/1 Year: Back up the data in the recent 7 days/1 month/2 months/3 months/6 months/1 year.

All Time: (Only for Omada Software Controller) Back up all data in the controller.

Saving Path (Only for Omada Hardware Controller) Select a path to save the backup files.

You can view the name, backup time and size of backup files in Backup Files List.

Backup Files List

FILE NAMEBACKUP TIMESIZEACTION
autobackup_30days_20200525_1026.cfg2020-05-2510:26:00 am7.37 KB

To restore, export or delete the backup file, click the icon in the Action column.

TP-LINK Omada OC200 - Occurrence - 1

Restore the configurations and data in the backup file. All current configurations will be replaced after the restoration.

To keep the backup data safe, please wait until the operation is finished. This will take several minutes.

TP-LINK Omada OC200 - Occurrence - 2

Export the backup file. The exported file will be saved in the saving path of your web browser.

TP-LINK Omada OC200 - Occurrence - 3

Delete the backup file.

TP-LINK Omada OC200 - Occurrence - 4

Note:

• To back up data manually and restore the data to the controller, refer to 5.3.3 Backup & Restore to configure Backup&Restore. - The configuration of cloud users can be neither backed up nor restored. To add cloud users, please refer to 9.3 Manage and Create Cloud User Accounts.

TP-LINK Omada OC200 - Note: - 1

Configure and Monitor Omada Managed Devices

This chapter guides you on how to configure and monitor Omada managed devices, including gateways, switches and EAPs. You can configure the devices individually or in batches to modify the configurations of certain devices. The chapter includes the following sections:

• 6.1 Introduction to the Devices Page • 6.2 Configure and Monitor the Gateway • 6.3 Configure and Monitor Switches • 6.4 Configure and Monitor EAPs

TP-LINK Omada OC200 - Configure and Monitor Omada Managed Devices - 1

6.1 Introduction to the Devices Page

Overview

The Devices page displays all TP-Link devices discovered by the controller and their general information. For an easy monitoring of the devices, you can customize the column and filter the devices for a better overview of device information. Also, quick operations and Batch Edit are available for configurations.

Search or select tag. All Gateway/Switches APs. DEVICE NAME, IP ADDRESS, STATUS, MODEL, VERSION, UPTIME, ACTION. CC-32-E5-A4-B1-AC, 192.168.0.1, CONNECTED, TL-ER6120 v3.0, 1.0.0, 4 days 19:38:10. CC-32-E5-69-B5-B0, 192.168.0.136, CONNECTED, T1500G-10MPS v2.0, 2.0.3, 8 days 23:05:41. EA-23-51-06-22-5…

According to the connection status, the devices have the following statuses: Pending, Isolated, Connected, Managed by Others, Heartbeat Missed, and Disconnected. The icons in the Status column are explained as follows:

PENDINGThe device is in Standalone Mode or with factory settings, and has not been adopted by the controller. To adopt the device, click and the controller will use the default username and password to adopt it. When adopting, its status will change from Adopting, Provisioning, Configuring, to Connected eventually.
ISOLATED(For APs in the mesh network) The AP once managed by the controller via a wireless connection now cannot reach the gateway. You can rebuild the mesh network by connecting it to an AP in the Connected status, then the isolated AP will turn into a connected one. For detailed configuration, refer toMesh.
CONNECTEDThe device has been adopted by the controller and you can manage it centrally. A connected device will turn into a pending one after you forget it.
MANAGED BY OTHERSThe device has already been managed by another controller. You can reset the device or provide the username and password to unbind it from another controller and adopt it in the current controller.
HEARTBEAT MISSEDTP-LINK Omada OC200 - Overview - 2A transition status between Connected and Disconnected.Once connected to the controller, the device will send inform packets to the controller in a regular interval to maintain the connection. If the controller does not receive its inform packets in 30 seconds, the device will turn into the Heartbeat Missed status. For a heartbeat-missed device, if the controller receives an inform packet from the device in 5 minutes, its status will become Connected again; otherwise, its status will become Disconnected.The connected device has lost connection with the controller for more than 5 minutes.
[WE77](For APs in the mesh network) When this icon appears with a status icon, it indicates the EAP with mesh function and no wired connection is detected by the controller. You can connect it to an uplink AP through Mesh.
TP-LINK Omada OC200 - Overview - 3When this icon appears with a status icon, it indicates the device in the Connected, Heartbeat Missed, Isolated, or Disconnected status is migrating. For more information about Migration, refer to 5.4 Migration.

Configuration

■ Customize the Column

To customize the columns, click next to Action and check the boxes of the information type.

To change the list order, click the column head and an arrow will appear to indicate the ascending or descending order.

Search or select tag. All Gateway/Switches APs. DEVICE NAME, IP ADDRESS, STATUS, MODEL, VERSION, UPTIME, ACTION. CC-32-E5-A4-B1-AC, 192.168.0.1, CONNECTED, TL-ER6120 v3.0, 1.0.0, 4 days 19:38:10. CC-32-E5-69-B5-B0, 192.168.0.135, CONNECTED, T1500G-10MPS v2.0, 2.0.3, 8 days 23:05:41. EA-23-51-06-22-5…

■ Filter the Devices

Use the search box and tab bar above the table to filter the devices.

To search the devices, enter the text in the search box or select a tag from the drop-down list. For device tags, refer to the general configuration of switches and EAPs.

Search or select tag. Group 1

To filter the devices, a tab bar is above the table to filter the devices by device type.

If you select the APs tab, another tab bar Overview Mesh Performance Config will be available to change the column quickly.

OverviewDisplays the device name, IP address, status, model, firmware version, uptime, channel, and Tx power by default.
MeshDisplays the information of devices in the mesh network, including the device name, IP address, status, model, uplink device, channel, Tx power, and the number of downlink devices, clients and hops by default.
PerformanceDisplays the device name, IP address, status, uptime, channel, Tx power, the number of 2.4 GHz and 5 GHz clients, Rx rate, and Tx rate by default.
ConfigDisplays the device name, status, version, WLAN group, and the radio settings for 2.4 GHz and 5 GHz by default.

■ Quick Operations

Click the icons in the Header or the Action column to quickly adopt, locate, upgrade, or reboot the device.

TP-LINK Omada OC200 - ■ Quick Operations - 1Click to check if there is new firmware for the managed devices.
[X0CC](For pending devices) Click to adopt the device.
[750T](For connected switches and APs) Click this icon and the LEDs of the device will flash to indicate the device's location. The LEDs will keep flashing for 10 minutes, or you can click theicon to stop the flashing.
TP-LINK Omada OC200 - ■ Quick Operations - 2(For connected devices) Click to reboot the device.
[Y2AS]Click to upgrade the device's firmware version. This icon appears when the device has a new firmware version. For Automatic Upgrades, refer to4.2.2 Services.

■ Batch Edit (for Switches and EAPs)

After selecting the Gateway/Switches or APs tab, you can adopt or configure the switches or EAPs in batches. Batch Config is available only for the devices in Connected/Disconnected/Heartbeat Missed/Isolated status, while Batch Adopt is available for the devices in the Pending/Managed By Others status.

Search or select tag. All Gateway/Switches APs. Device NAME, IP ADDRESS, STATUS, MODEL, VERSION, UPTIME, Batch Config, Batch Adopt. TP-Link_Test_Gatev..., 192.168.0.1, CONNECTED, TL-ER7206 v1.0, 1.1.0, 1 days 03:35:44 (1). TP-Link_Test_Swift..., 192.168.0.37, CONNECTED, TL-SG2210MP v1.0, 1.0.0, 10 d…

Click Batch Action, select Batch Adopt, click the checkboxes of devices, and click Done. If the selected devices are all in the Pending status, the controller will adopt them with the default username and password. If not, enter the username and password manually to adopt the devices.

Search or select tag. All Gateway/Switches APs. Overview, Mini, Performance, Config. Device NAME, IP ADDRESS, STATUS, MODEL, VERSION, UPTIME, CLIENTS, DOWN, UP, CHANNEL, ACTION. TP-Link_Text_Eap_4, 112.160.0.104, ADOPT FAILED, SAP235-W8(US) v1.0, 1.02, 16 days 10:42:33, 0, 0 Bytes, 0 Bytes, —, Retry…

Click Batch Action, select Batch Config, click the checkboxes of devices, and click Done. Then the Properties window appears. There are two tabs in the window: Devices and Config.

In Devices, you can click ✗ to remove the device from the current batch configuration.

In Config, all settings are Keep Existing by default. For detailed configurations, refer to the configuration of switches and EAPs.

Search or select tag. All Gateway/Switches APs. Overview, Mesh, Performance, Config. Device NAME, IP ADDRESS, STATUS, MODEL, VERSION, UPTIME, CLIENTS, DOWN, UP, CHANNEL, ACTION. EA-23-51-06-22-52, 10.0.1.70, CONNECTED, EAP225-Outdoor(EU) v1.0, 2.0.0, 1 days 07:54:98, 0, 2.11 GB, 369.62 MB, 11(2.4G),…

>Click to minimize the Properties window to an icon. To reopen the minimized Properties window, click ☐.
Click to maximize the Properties window. You can also use the icon on pages other than the Devices page.
×Click to close the Properties window of the chosen device(s). Note that the unsaved configuration will be lost.
...The number on the lower-right shows the number of devices in the batch configuration.

6.2 Configure and Monitor the Gateway

In the Properties window, you can configure the gateway managed by the controller and monitor the performance and statistics. By default, all configurations are synchronized with the current site.

To open the Properties window, click the entry of a router. A monitor panel and several tabs are listed in the Properties window. Most features to be configured are gathered in the Config tab, such as IP, SNMP, IPTV, and Hardware Offload, while other tabs are mainly used to monitor the devices.

Search or event tag. All Gateway/Switches APs. DEVICE NAME IP ADDRESS STATUS MODEL VERSION UPTIME DOWN. CC-32-E5-A4-B1-AC 192.168.0.1 CONNECTED TL-ER7206+1.0 1.0.0 4 days 18:27:40 - -. CC-32-E5-69-05-60 192.168.0.135 CONNECTED TL-9C2210P +1.0 1.0.3 0 days 21:05:16 949.26 MB 1.00 G. Showing 1-2 of 2…

TP-LINK Omada OC200 - Configure and Monitor the Gateway - 2

Note:

  • You can adopt only one router in one site.
  • The available functions in the window vary due to the model and status of the device.

6.2.1 Configure the Gateway

In the Properties window, click Config and then click the sections to configure the features applied to the router, including general settings, SNMP, IPTV, and advanced functions.

General

In General, you can specify the device name and LED settings of the router.

General. Name: CC-32-E5-A4-B1-AC. LED: Use Site Settings. On. Off. Apply Cancel

Name Specify a name of the device.

LED

Select the way that the device's LEDs work.

Use Site Settings: The device's LED will work following the settings of the site. To view and modify the site settings, refer to 4.2.2 Services.

On/Off: The device's LED will keep on/off.

■ Services

In Services, you can configure SNMP to write down the location and contact detail, and enable IGMP Proxy to detect multicast number group memberships. You can also click Manage to jump to Settings > Services > SNMP, and for detailed configuration of SNMP service, refer to 4.10.2 SNMP.

Services. SNMP. Manage. Location: Contact: IPTV. IGMP Proxy: ✓ Enable. IGMP Version: v2. v3. Apply Cancel

■ Advanced

In Advanced, you can configure Hardware Offload, LLDP (Link Layer Discovery Protocol) and Echo Server to make better use of network resources.

Advanced. Hardware Offload: Enable i. LLDP: Enable. Echo Server: Auto. Custom. Apply Cancel

Hardware OffloadHardware Offload can improve performance and reduce CPU utilization by using the hardware to offload packet processing.Note that this feature cannot take effect if QoS, Bandwidth Control, or Session Limit is enabled. To configure Bandwidth Control and Session Limit for the router, refer to 4.6 Transmission.
LLDP LLDP can help discover devices.
Echo ServerEcho Server is used to test the connectivity and monitor the latency of the network automatically or manually. If you click Custom, enter the IP address or hostname of your custom server.

■ Manage Device

In Manage Device, you can upgrade the device's firmware version manually, move it to another site, synchronize the configurations with the controller, and forget the router.

Manage Device. Custom Upgrade. Please choose the firmware file and upgrade the device. ↑ Browse. Move to Site. Move this device to another site of this controller. Please Select... Move. Force Provision. Click Force Provision to synchronize the configurations of the device with the controller. The d…

Custom UpgradeClick Browse and choose a file from your computer to upgrade the device. When upgrading, the device will be reboot and readopted by the controller. You can also check the box of Upgrade all devices of the same model in the site after the firmware file is uploaded.
Move to SiteSelect a site which the device will be moved to. After moving to another site, device configurations on the prior site will be replaced by that on the new site, and its traffic history will be cleared.
Force ProvisionClick Force Provision to synchronize the configurations of the device with the controller. The device will lose connection temporarily, and be adopted to the controller again to get the configurations from the controller.
ForgetClick Forget and then the device will be removed from the controller. Once forgotten, all configurations and history related to the device will be wiped out.

■ Common Settings

In Common Settings, you can click the path to jump to corresponding modules quickly.

Common Settings. Settings->Wired Networks->Internet. To configure the network of the WAN port, go to the Settings->Wired Networks->Internet page. Settings->Wired Networks->LAN. To view and configure the settings of the network interfaces, go to the Settings->Wired Networks->LAN page. Settings->VPN.…

6.2.2 Monitor the Gateway

One panel and three tabs are provided to monitor the device in the Properties window: Monitor Panel, Details, Networks, and Statistics.

Monitor Panel

The monitor panel displays the router's ports, and it uses colors and icons to indicate different connection status and port types. When the router is pending or disconnected, all ports are disabled.

Disabled. 10/100 Mbps. Disconnected. WAN. 1000 Mbps. LAN

You can hover the cursor over the port icon for more details.

Port1
Status1000 Mbps
Tx Bytes34.70 MB
Rx Bytes59.61 MB

Details

In Details, you can view the basic information of the router and statistics of WAN ports to know the device's running status briefly.

Overview

In Overview, you can view the basic information of the device. The listed information varies due to the device's status.

Overview
MAC Address:Model:
CC-32-E5-A4-B1-ACTL-ER7206 v1.0
Firmware Version:CPU Utilization:
1.0.0 Build 202005091%
Rel.71443
Memory Utilization:LAN IP Address:
12%192.168.0.1
Uptime:
2 days 19:41:14

■ SFP WAN/WAN

In SFP WAN/WAN, you can view the basic information and statistics of the WAN port, such as the IP address, speed, duplex, and upload and download traffic.

SFP WAN. Link Down. WAN. Online | Online ^. IPv4 IPv6. IP Address: Gateway: 192.168.13.107 192.168.13.2. DNS Server: 223.5.5.5 | 0.0.0.0. Status: Online. Disconnect. Duplex: Speed: Full duplex 1000 Mbps. Upload Pkts/Bytes: Download Pkts/Bytes: 557442551 / 76.97 GB 1054026727 / 1305.47 GB. Upload Act…

Networks

In Networks, you can view the network information of the router, including the Network name, IP address, transmitted and received traffics of LAN interfaces in the network, and number of clients.

NetworkIP AddressTx BytesRx BytesClients
LAN192.168.0.1596.1 MB1.0 GB0

Statistics

In Statistics, you can monitor the CPU and memory of the device in last 24 hours via charts. To view statistics of the device in a certain period, click the chart to jump to 8.2 View the Statistics of the Network.

| Time | CPU | Memory | | ---------- | ---- | ------ | | 11:15 am | ~0% | 12% | | 04:40 pm | ~0% | 12% | | 10:05 pm | ~0% | 12% | | 03:30 am | ~0% | 12% | | 11:10 am | ~0% | 12% |

6.3 Configure and Monitor Switches

In the Properties window, you can configure one or some switches connected to the controller and monitor the performance and statistics. Configurations changed in the Properties window will be applied only to the selected switch(es). By default, all configurations are synchronized with the current site.

To open the Properties window, click the entry of a switch, or click Batch Action, and then Batch Config to select switches for batch configuration. A monitor panel and several tabs are listed in the Properties window. Most features to be configured are gathered in the Ports and Config tab, such as the port mirroring, IP address, and Management VLAN, while other tabs are mainly used to monitor the devices.

Search or select tag All Gateway/Switches APs DEVICE NAME IP ADDRESS STATUS MODEL VERSION UPTIME DOWN CC-32-E5-A4-B1-AC 192.168.0.1 CONNECTED TL-ER7206 v1.0 1.0.0 0 days 18.06.22 - CC-32-E5-89-B5-B0 192.168.0.116 CONNECTED TL-SG2210P v1.0 1.0.3 0 days 19.34.02 0 Bytes Showing 1-2 of 2 records < 1 >…

① Note:

  • The available functions in the window vary depending on the model and status of the device. • In Batch Config, you can only configure the selected devices, and the unaltered configurations will keep the current settings.

6.3.1 Configure Switches

In the Properties window, you can view and configure the profiles applied to ports in Ports, and in Config, you can configure the switch features.

Ports

Port and LAG are two tabs designed for physical ports and LAGs (Link Aggregation Groups), respectively. Under the Port tab, all ports are listed, but you can configure physical ports only, including overriding the applied profiles, configuring Port Mirroring, and specifying ports as LAGs. Under the LAG tab, all LAGs are listed, and you can view and modify the configurations of existing LAGs.

Port

In Port, you can view and configure all ports' names and applied profiles.

Port LAG Edit Selected Name Status Profile ACTION 1 Port1 All 2 Port2 All 3 Port3 All 4 Port4 All 5 Port5 All 6 Port6 All 7 Port7 All 8 Port8 All 9 Port9 All 10 Port10 All

Status Displays the port status in different colors.

The port profile is Disabled. To enable it, click to change the profile. ■: The port is enabled, but no device or client is connected to it. : The port is running at 1000 Mbps. ■: The port is running at 10/100 Mbps.

Profile Displays the profile applied to the port.

Action

☑: Click to edit the port name and configure the profile applied to the port.

(For PoE ports) Click to reboot the connected powered devices (PDs).

To configure a single port, click ☑ in the table. To configure ports in batches, click the checkboxes and then click Edit Selected. Then you can configure the port name and profile. By default, all settings are Keep Existing for batch configuration.

Edit Port1 Name: Port1 Profile: All Manage Profiles Profile Overrides Apply Cancel

Name Enter the port name.
ProfileSelect the profile applied to the port from the drop-down list. Click Manage Profiles to jump to view and manage profiles. For details, refer to 4.3 Configure Wired Networks.
Profile OverridesClick the checkbox to override the applied profile. The parameters to be configured vary in Operation modes.

With Profile Overrides enabled, select an operation mode and configure the following parameters to override the applied profile, configure a mirroring port, or configure a LAG.

- Override the Applied Profile

If you select Switching for Operation, configure the following parameters and click Apply to override the applied profile. To discard the modifications, click Remove Overrides and all profile configurations will become the same as the applied profile.

Edit Port1 Name: Port1 Profile: All Manage Profiles ✓ Profile Overrides Operation: ● Switching ○ Mirroring ① ○ Aggregating PoE Mode: ○ Off ● 802.3at/af 802.1X Control: ○ Auto ● Force Authorized ○ Force Unauthorized Link Speed: ○ Auto ● Manual Auto / Auto Port Isolation: □ Enable ① Loopback Control:…

PoE Mode (Only for PoE ports) Select the PoE (Power over Ethernet) mode for the port.
Off: Disable PoE function on the PoE port.
802.3at/af: Enable PoE function on the PoE port.
802.1X ControlSelect 802.1X Control mode for the ports. To configure the 802.1X authentication globally, go to Settings > Authentication > 802.1X.
Auto: The port is unauthorized until the client is authenticated by the authentication server successfully.
Force Authorized: The port remains in the authorized state, sends and receives normal traffic without 802.1X authentication of the client.
Force Unauthorized: The port remains in the unauthorized state, and the client connected to the port cannot authenticate with any means. The switch cannot provide authentication services to the client through the port.
Link Speed Select the speed mode for the port.
Auto: The port negotiates the speed and duplex automatically.
Manual: Specify the speed and duplex from the drop-down list manually.
Port IsolationClick the checkbox to enable Port Isolation. An isolated port cannot communicate directly with any other isolated ports, while the isolated port can send and receive traffic to non-isolated ports.
Loopback ControlChoose the method for loopback control, which helps ensure that you do not create loops when you have redundant paths in the network.
Off: Disable loopback control on the port.
Loopback Detection: Select loopback detection and it helps prevent loops on the port. It is used to detect loops that occur on a specific port. When a loop is detected on a port, the switch will block the corresponding port.
STP: Select STP (Spanning Tree Protocol) to prevent loops in the network. STP helps block specific ports of the switches to build a loop-free topology and detect topology changes and automatically generate a new loop-free topology. To make sure Spanning Tree takes effect on the port, go to the Config tab and enable Spanning Tree on the switch.
LLDP-MED Click the checkbox to enable LLDP-MED (Link Layer Discovery Protocol-Media Endpoint Discovery) for device discovery and auto-configuration of VoIP (Voice over Internet Protocol) devices.
Bandwidth ControlSelect the type of Bandwidth Control functions to control the traffic rate and specify traffic threshold on each port to make good use of network bandwidth.Off: Disable Bandwidth Control for the port.Rate Limit: Select Rate limit to limit the ingress/egress traffic rate on each port. With this function, the network bandwidth can be reasonably distributed and utilized.Storm Control: Select Storm Control to allow the switch to monitor broadcast frames, multicast frames and UL-frames (Unknown unicast frames) in the network. If the transmission rate of the frames exceeds the specified rate, the frames will be automatically discarded to avoid network broadcast storm.
Ingress Rate LimitWith Rate Limit selected, click the checkbox and specify the upper rate limit for receiving packets on the port.
Egress Rate LimitWhen Rate Limit selected, click the checkbox and specify the upper rate limit for sending packets on the port.
Broadcast ThresholdWith Storm Control selected, click the checkbox and specify the upper rate limit for receiving broadcast frames. The broadcast traffic exceeding the limit will be processed according to the Action configurations.
Multicast ThresholdWith Storm Control selected, click the checkbox and specify the upper rate limit for receiving multicast frames. The multicast traffic exceeding the limit will be processed according to the Action configurations.
Unknown Unicast ThresholdWith Storm Control selected, click the checkbox and specify the upper rate limit for receiving unknown unicast frames. The traffic exceeding the limit will be processed according to the Action configurations.
Action When Storm Control selected, select the action that the switch will take when the traffic exceeds its corresponding limit.Drop: With Drop selected, the port will drop the subsequent frames when the traffic exceeds the limit.Shutdown: With Shutdown selected, the port will be shutdown when the traffic exceeds the limit.
Recover TimeWith Shutdown selected as the Action, specify the recover time, and the port will be opened after the specified time.

- Configure a Mirroring Port

If you select Mirroring as Operation, the edited port can be configured as a mirroring port. Specify other ports as the mirrored port, and the switch sends a copy of traffics passing through the mirrored port to the mirroring port. You can use mirroring to analyze network traffic and troubleshoot network problems.

To configure Mirroring, select the mirrored port or LAG, specify the following parameters, and click Apply. To discard the modifications, click Remove Overrides and all profile configurations become the same as the applied profile.

Note that the mirroring ports and the member ports of LAG cannot be selected as mirrored ports.

Profile Overrides Operation: ○ Switching ● Mirroring ① ○ Aggregating Unselected Selected 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 LAG: □ LAG1 PoE Mode: ○ Off ● 802.3at/af Link Speed: ○ Auto ● Manual Auto / Auto Bandwidth Control: ○ Off ● Rate Limit Ingress Rate Limi…

PoE Mode (Only for PoE ports) Select the PoE mode for the port.

Off: Disable PoE on the PoE port.

802.3at/af: Enable PoE on the PoE port.

Link Speed Select the speed mode for the port.

Auto: The port negotiates the speed and duplex automatically.

Manual: Specify the speed and duplex from the drop-down list manually.

Bandwidth ControlBandwidth control optimizes network performance by limiting the bandwidth of specific sources.Off: Disable bandwidth control on the port.Rate Limit: Enable bandwidth control on the port, and you need to specify the ingress and/or egress rate limit.
Ingress Rate LimitWith Rate Limit selected, click the checkbox and specify the upper rate limit for receiving packets on the port. With this function, the network bandwidth can be reasonably distributed and utilized.
Egress Rate LimitWith Rate Limit selected, click the checkbox and specify the upper rate limit for sending packets on the port. With this function, the network bandwidth can be reasonably distributed and utilized.

- Configure a LAG

If you select Aggregating as Operation, you can aggregate multiple physical ports into a logical interface, which can increase link bandwidth and enhance the connection reliability.

TP-LINK Omada OC200 - - Configure a LAG - 1

Configuration Guidelines:

  • Ensure that both ends of the aggregation link work in the same LAG mode. For example, if the local end works in LACP mode, the peer end should also be set as LACP mode.
  • Ensure that devices on both ends of the aggregation link use the same number of physical ports with the same speed, duplex, jumbo and flow control mode.
  • A port cannot be added to more than one LAG at the same time.
  • LACP does not support half-duplex links. • One static LAG supports up to eight member ports. All the member ports share the bandwidth evenly. If an active link fails, the other active links share the bandwidth evenly.
  • One LACP LAG supports multiple member ports, but at most eight of them can work simultaneously, and the other member ports are backups. Using LACP protocol, the switches negotiate parameters and determine the working ports. When a working port fails, the backup port with the highest priority will replace the faulty port and start to forward data.
  • The member port of an LAG follows the configuration of the LAG but not its own. Once removed, the LAG member will be configured as the default All profile and Switching operation.
  • The port enabled with Port Security, Port Mirror, MAC Address Filtering or 802.1X cannot be added to an LAG, and the member port of an LAG cannot be enabled with these functions.

To configure a new LAG, select other ports to be added to the LAG, specify the LAG ID, and choose a LAG type. Click Apply. To discard the modifications, click Remove Overrides and all

profile configurations become the same as the applied profile. For other parameters, configure them under the LAG tab.

Profile Overrides Operation: Switching Mirroring Aggregating Unselected Selected 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 LAG ID: Please Select... (1-8) Static LAG LACP Apply Cancel Remove Overrides

LAG ID Specify the LAG ID of the LAG. Note that the LAG ID should be unique.

The valid value of the LAG ID is determined by the maximum number of LAGs supported by your switch. For example, if your switch supports up to 14 LAGs, the valid value ranges from 1 to 14.

Static LAG Select the LAG type as Static LAG, and the member ports are added to the LAG manually.

LACP Select the LAG type as LACP (Link Aggregation Control Protocol), and the switch use LACP to implement dynamic link aggregation and disaggregation. LACP extends the flexibility of the LAG configurations.

LAG

LAGs (Link Aggregation Groups) are logical interfaces that are aggregated, which can increase link bandwidth and enhance connection reliability. You can view and edit the LAGs under the LAG tab. To configure physical ports as a LAG, refer to Configure a LAG.

Port LAG LAG ID Name Status Ports Profile ACTION 1 LAG1 Port 9,Port 10 All

Status Displays the status in different colors.

The LAG profile is Disable. To enable it, click to change the profile. The port is enabled, but no device or client is connected to it. The LAG ports are running at 1000 Mbps. ■: The LAG ports are running at 10/100 Mbps.

Ports Displays the port number of LAG ports.

Profile Displays the profile applied to the port.

Action

☑: Click to edit the port name and configure the profile applied to the port.

: Click to delete the LAG. Once deleted, the ports will be configured as the default All profile and Switching operation. You can configure the ports under the Port tab.

Click ☐ to configure the LAG name and the applied profile.

Edit LAG1 Name: LAG1 Profile: All Manage Profiles i Configurations of PoE, 802.1x and LLDP-MED in the profile do not take effect on LAG ports. Profile Overrides Apply Cancel

Name Enter the port name.

ProfileSelect the profile applied to the port from the drop-down list. Click Manage Profiles to jump to view and manage profiles. For details, refer to 4.3 Configure Wired Networks.
Profile OverridesClick the checkbox to override the applied profile. The parameters to be configured vary in Operation modes.

With Profile Overrides enabled, you can reselect the LAG members and configure the following parameters.

Profile Overrides Unselected Selected 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 LAG ID: 1 (1-8) Static LAG LACP Link Speed: Auto Manual Port Isolation: Enable Loopback Control: Off Loopback detection Spanning Tree Bandwidth Control: Off Rate Limit Storm Control Apply…

Link Speed Select the speed mode for the port.

Auto: The port negotiates the speed and duplex automatically.

Manual: Specify the speed and duplex from the drop-down list manually.

Port Isolation Click the checkbox to enable Port Isolation. An isolated port cannot communicate directly with any other isolated ports, while the isolated port can send and receive traffic to non-isolated ports.

Loopback ControlChoose the method for loopback control, which helps ensure that you do not create loops when you have redundant paths in the network.Off: Disable loopback control on the port.
Loopback Detection: Select loopback detection and it helps prevent loops on the port. It is used to detect loops that occur on a specific port. When a loop is detected on a port, the switch will block the corresponding port.
STP: Select STP (Spanning Tree Protocol) to prevent loops in the network. STP helps block specific ports of the switches to build a loop-free topology and detect topology changes and automatically generate a new loop-free topology. To make sure Spanning Tree takes effect on the port, go to the Config tab and enable Spanning Tree on the switch.
Bandwidth ControlSelect the type of Bandwidth Control functions to control the traffic rate and traffic threshold on each port to ensure network performance.Off: Disable Bandwidth Control for the port.
Rate Limit: Select Rate limit to limit the ingress/egress traffic rate on each port. With this function, the network bandwidth can be reasonably distributed and utilized.
Storm Control: Select Storm Control to allow the switch to monitor broadcast frames, multicast frames and UL-frames (Unknown unicast frames) in the network. If the transmission rate of the frames exceeds the specified rate, the frames will be automatically discarded to avoid network broadcast storm.
Ingress Rate LimitWith Rate Limit selected, click the checkbox and specify the upper rate limit for receiving packets on the port.
Egress Rate LimitWith Rate Limit selected, click the checkbox and specify the upper rate limit for sending packets on the port.
Broadcast ThresholdWith Storm Control selected, click the checkbox and specify the upper rate limit for receiving broadcast frames. The broadcast traffic exceeding the limit will be processed according to the Action configurations.
Multicast ThresholdWith Storm Control selected, click the checkbox and specify the upper rate limit for receiving multicast frames. The multicast traffic exceeding the limit will be processed according to the Action configurations.
Unknown Unicast ThresholdWith Storm Control selected, click the checkbox and specify the upper rate limit for receiving unknown unicast frames. The traffic exceeding the limit will be processed according to the Action configurations.
Action With Storm Control selected, select the action that the switch will take when the traffic exceeds its corresponding limit.
Drop: With Drop selected, the port will drop the subsequent frames when the traffic exceeds the limit.
Shutdown: With Shutdown selected, the port will be shutdown when the traffic exceeds the limit.

Recover Time

With Shutdown selected as the Action, specify the recover time, and the port will be opened after the specified time.

Config

In Config, click the sections to configure the features applied to the selected switch(es), including the general settings, services, and networks.

■ General

In General, you can specify the device name and LED settings of the switch, and categorize it via device tags.

General Name: CC-32-E5-69-B5-B0 LED: Use Site Settings On Off Device Tags: Please Select... Apply Cancel

Name (Only for configuring a single device) Specify a name of the device.

LED

Select the way that device's LEDs work.

Use Site Settings: The device's LED will work following the settings of the site. To view and modify the site settings, refer to 4.2.2 Services.

On/Off: The device's LED will keep on/off.

Device Tags Select a tag from the drop-down list or create a new tag to categorize the device.

■ VLAN Interface

In VLAN Interface, you can configure Management VLAN and different VLAN interface for the switch. The general information of the existing VLAN interface are displayed in the table.

VLAN Interface Name ▼ VLAN Enable LAN 1 Test A 10 Test B 101 Showing 1-3 of 3 records < 1 > Apply Cancel

To configure a single VLAN interface, hover the mouse on the entry and click to edit the settings.

VLAN Interface > Edit Interface

TP-LINK Omada OC200 - VLAN Interface &gt; Edit Interface - 1

Management VLAN:

TP-LINK Omada OC200 - VLAN Interface &gt; Edit Interface - 2

Enable

TP-LINK Omada OC200 - VLAN Interface &gt; Edit Interface - 3

The controller will fail to manage your devices with wrong Management VLAN configurations. If you are not sure about your network conditions and the potential impact of any configurations, we recommend that you keep the default configurations. Refer to the Configuration Guide before you configure this feature.

IP Address Mode:

TP-LINK Omada OC200 - VLAN Interface &gt; Edit Interface - 4

Static

TP-LINK Omada OC200 - VLAN Interface &gt; Edit Interface - 5

DHCP

Fallback IP Address:

TP-LINK Omada OC200 - VLAN Interface &gt; Edit Interface - 6

Enable

TP-LINK Omada OC200 - VLAN Interface &gt; Edit Interface - 7

Fallback IP Address:

  1. 1

Fallback IP Mask:

255.255.255.0

Fallback Gateway:

(Optional)

DHCP Option12:

(Optional)

DHCP Mode:

TP-LINK Omada OC200 - VLAN Interface &gt; Edit Interface - 8

None

TP-LINK Omada OC200 - VLAN Interface &gt; Edit Interface - 9

DHCP Server

TP-LINK Omada OC200 - VLAN Interface &gt; Edit Interface - 10

DHCP Relay

Apply

Cancel

Management VLANClick the checkbox if you want to use the VLAN interface as Management VLAN. Note that the controller will fail to manage your devices with wrong Management VLAN configurations. If you are not sure about your network conditions and the potential impact of any configurations, we recommend that you keep the default configurations.The management VLAN is a VLAN created to enhance the network security. Without Management VLAN, the configuration commands and data packets are transmitted in the same network. There are risks of unauthorized users accessing the management page and modifying the configurations. A management VLAN can separate the management network from the data network and lower the risks.
IP Address Mode (when Management VLAN disabled)Select a mode for the interface to obtain its IP address, and the VLAN will communicate with other networks including VLANs with the IP address.Static: Assign an IP address to the interface manually, specify the IP Address and Subnet Mask for the interface.When the VLAN interface is set as the Management VLAN, it is optional for you to specify the Default Gateway and Primary/Secondary DNS for the interface.DHCP: Assign an IP address to the interface through a DHCP server.When the VLAN interface is set as the Management VLAN, you can further enable Fallback IP Address, and specify the Fallback IP Address, Fallback IP Mask, and Fallback Gateway (optional). If the VLAN interface fails to get an IP address from the DHCP server, the fallback IP address will be used for the interface.
DHCP Option 12When DHCP is selected as the IP Address Mode, you can specify the hostname of the DHCP client in the field. The DHCP client will use option 12 to tell the DHCP server their hostname.
DHCP Mode Select a mode for the clients in the VLAN to obtain their IP address.None: Do not use DHCP to assign IP addresses.DHCP Server: Assign an IP address to the clients through a DHCP server.When DHCP Server is selected, you can specify the DHCP Range, and the IP addresses in the range can be assigned to the clients in the VLAN. Also, it is optional for you to specify the DHCP Option 138, Primary/Secondary DNS, Default Gateway, and Lease Time. DHCP Option 138 informs the DHCP client of the controller's IP address when the client sends a request to the DHCP server, and specify Option 138 as the controller's IP address here. Lease Time decides how long the client can use the assigned IP address.DHCP Relay: It allows clients in the VLAN to obtain IP addresses from a DHCP server ion different subnet. When DHCP Relay is selected, specify the IP address of the DHCP server in Server Address.

■ Static Route

In Static Route, you can configure entries of static route for the switch. The general information of the existing static route entries are displayed in the table. For an existing static route, click ☑ to edit the settings, and click 🔒 to delete it.

Static Route + Add Destination IP Enabled Next Hop ACTION 192.168.0.3/32 10.0.0.1 Showing 1-1 of 1 records < 1 >

To add a new static route entry, click and configure the parameters.

Static Route > Add New Route Status: Enable Destination IP/Subnet: . . . / Add Subnet Next Hop: . . . . Distance: (1-255) Apply Cancel

Status: Click the checkbox to enable or disable the static route.

Destination IP/SubnetDestination IP/Subnet identifies the network traffic which the Static Route entry controls. Specify the destination of the network traffic in the format of 192.168.0.1/24. You can click + Add Subnet to specify multiple Destination IP/Subnets and click 📄 to delete them.
Next Hop Specify the IP address for your devices to forward the corresponding network traffic.
DistanceSpecify the priority of a static route. It is used to decide the priority among routes to the same destination. Among routes to the same destination, the route with the lowest distance value will be recorded into the routing table.

■ Services

In Services, you can configure Management VLAN, Loopback Control, and SNMP.

Services VLAN Management VLAN: LAN To configure the Management VLAN, please go to VLAN Interface. Note that the controller will fail to manage your devices with wrong Management VLAN configurations. If you are not sure about your network conditions and the potential impact of any configurations, we…

Management VLAN: Displays the name of the current Management VLAN.

To configure the Management VLAN, go to Config > VLAN Interface. Note that the controller will fail to manage your devices with incorrect Management VLAN configurations. If you are unsure about your network conditions and the potential impact of any configurations, we recommend keeping the default settings.

The management VLAN is a VLAN created to enhance network security. Without a Management VLAN, configuration commands and data packets are transmitted on the same network, posing risks of unauthorized users accessing the management page and modifying configurations. A management VLAN separates the management network from the data network, reducing these risks.

Loopback DetectionWhen enabled, the switch checks the network regularly to detect the loopback. Note that Lopback Detection and Spanning Tree are not available at the same time.
Spanning TreeSelect a mode for Spanning tree. This feature is available only when Loopback Detection is disabled. Off: Disable Spanning Tree on the switch. STP: Enable STP (Spanning Tree Protocol) to prevent loops in the network. STP helps to block specific ports of the switches to build a loop-free topology and detect topology changes and automatically generate a new loop-free topology. RSTP: Enable RSTP (Rapid Spanning Tree Protocol) to prevent loops in the network. RSTP provides the same features as STP with faster spanning ree convergence. Priority: When STP/RSTP enabled, specify the priority for the swith in Spanning Tree. In STP/RSTP, the switch with the highest priority will be selected as the root of the spanning tree. The switch with the lower value has the higher priority.
SNMP(Only for configuring a single device) Configure SNMP to write down the location and contact detail. You can also click Manage to jump to Settings > Services > SNMP, and for detailed configuration of SNMP service, refer to 4.10.2 SNMP.

■ IP Settings (Only for configuring a single device)

In IP Settings, select an IP mode and configure the parameters for the device.

If you select DHCP as the mode, ensure there is a DHCP server in the network; the device will then automatically obtain a dynamic IP address from the DHCP server. You can set a fallback IP

address to reserve an IP address for situations where the device fails to obtain a dynamic IP address. Enable Fallback IP and then set the IP address, IP mask, and gateway.

IP Settings Mode: DHCP Static Fallback IP: Enable i Fallback IP Address: 192 . 168 . 0 . 25 Fallback IP Mask: 255 . 255 . 255 . 0 Fallback Gateway: . . . . (Optional) Apply Cancel

If you select Static as the mode, set the IP address, IP mask, gateway, and DNS server for the static address.

IP Settings Mode: DHCP Static IP Address: IP Mask: Gateway: Primary DNS Server: (Optional) Secondary DNS Server: (Optional) Apply Cancel

■ Manage Device

In Manage Device, you can manually upgrade the device's firmware version, move it to another site, synchronize configurations with the controller, and forget the switch.

Manage Device Custom Upgrade Choose the firmware file and upgrade the device. Browse Move to Site Move this device to another site of this controller. Please Select... Move Force Provision Click Force Provision to synchronize the configurations of the device with the controller. The device will disc…

Custom UpgradeClickBrowseand choose a file from your computer to upgrade the device. When upgrading, the device will be reboot and readopted by the controller. You can also check the box ofUpgrade all devices of the same modelin the site after the firmware file is uploaded.
Move to SiteSelect a site which the device will be moved to. After moving to another site, device configurations on the prior site will be replaced by that on the new site, and its traffic history will be cleared.
Force Provision(Only for configuring a single device) Click Force Provision to synchronize the configurations of the device with the controller. The device will lose connection temporarily, and be adopted to the controller again to get the configurations from the controller.
ForgetClick Forget and then the device will be removed from the controller. Once forgotten, all configurations and history related to the device will be wiped out.

6.3.2 Monitor Switches

One panel and four tabs are provided to monitor the device in the Properties window: Monitor Panel, Details, Clients, and Statistics.

Monitor Panel

The monitor panel displays the switch's ports and uses colors and icons to indicate connection status and port type. When the switch is pending or disconnected, all ports are disabled.

| Category | Value | |---|---| | 1 | 2 | | 3 | 4 | | 5 | 6 | | 7 | 8 | | 9 | 10 | Legend: Gray = Disabled, Dark Blue = Disconnected, Green = 1000 Mbps, Orange = 10/100 Mbps, Light Green = Uplink, Black = Mirroring, White = STP Blocking.

PoEA PoE port connected to a powered device (PD).
UplinkAn uplink port connected to WAN.
MirroringA mirroring port that is mirroring another switch port.
STP BlockingA port in the Blocking status in Spanning Tree. It receives and sends BPDU (Bridge Protocol Data Unit) packets to maintain the spanning tree. Other packets are dropped.

You can hover the cursor over the port icon (except disabled ports) for more details. The displayed information varies due to connection status and port type.

Port3
NamePort3
Status1000 Mbps Full Duplex
Tx Bytes343.59 MB
Rx Bytes353.98 MB
ProfileAll
PoE Power4.3 W

Status Displays the negotiation speed of the port.

Tx Bytes Displays the amount of data transmitted as bytes.

Rx Bytes Displays the amount of data received as bytes.

ProfileDisplays the name of profile applied to the port, which defines how the packets in both ingress and egress directions are handled. For detailed configuration, refer to 4.8 Create Profiles.
PoE PowerDisplays the percentage of received packets that have errors and the percentage of packets that were dropped.
Uplink Displays the name of device connected to the uplink port.
Mirroring From Displays the name of port that is mirrored.
LAG ID Displays the name of ports that are aggregated into a logical interface.

Details

In Details, you can view the basic information, traffic information, and radio information of the device to know the device's running status.

Overview

In Overview, you can view the basic information of the device. The listed information will be varied due to the device's model and status.

Overview
S/N:Model:
TL-SG3428XMP v1.0
MAC Address:IP Address:
192.168.0.11
Firmware Version:CPU Utilization:
1.0.2 Build 202101195%
Rel.75169
Memory Utilization:Uptime:
30%5 days 23:14:42
Remaining PoE Power:Fan Status:
97.53% / 374.50WNormal

■ Uplink (Only for the switch connected to an Omada-managed router/switch in Connected status) Click Uplink to view the uplink information, including the uplink port, the uplink device, the negotiation speed, and transmission rate.

Uplink
Port:Uplink Device:
8CC-32-E5-A4-B1-AC
Model:Speed & Duplex:
TL-ER7206 v1.01000 Mbps Full Duplex
Rx Bytes:Tx Bytes:
491.79 MB497.95 MB

Click Downlink to view the downlink information, including the downlink ports, devices name and model as well as negotiation speed.

Downlink Port Model Device-MAC Status 3 EAP660 B0-95-75-E6-48- HD 3C Mbps Full Duplex Showing 1-1 of 1 records < 1 >

Clients

In Clients, you can view the information of clients connected to the switch, including the client name, IP address and the connected port. You can click the client name to open its Properties window.

Name IP Address 7 OC200_72C6FB 192.168.0.132 8 TP-Link-PC 192.168.0.145 Showing 1-2 of 2 records < 1 >

Statistics

In Statistics, you can monitor the CPU and memory of the device over the last 24 hours via charts. To view statistics of the device for a certain period, click the chart to jump to 8.2 View the Statistics of the Network.

| Time | CPU | Memory | | ---------- | ---- | ------ | | 11:15 am | ~0% | 12% | | 04:40 pm | ~0% | 12% | | 10:05 pm | ~0% | 12% | | 03:30 am | ~0% | 12% | | 11:10 am | ~0% | 12% |

TP-LINK Omada OC200 - Statistics - 2

6.4 Configure and Monitor EAPs

In the Properties window, you can configure one or some EAPs connected to the controller and monitor their performance and statistics. Configurations changed in the Properties window will be applied only to the selected AP(s). By default, all configurations are synchronized with the current site.

To open the Properties window, click the entry of an AP, or click Batch Action, and then Batch Config to select APs for batch configuration. A monitor panel and several tabs are listed in the Properties window. Most features to be configured are gathered in the Config tab, such as IP, radios, SSID, and VLAN, while other tabs are mainly used to monitor the device.

CC-32-E5-F7-D0... CONNECTED 1 bi/n mixed 2.4G (54% Utilized) High 48 air/ac mixed 53 (17% Utilized) Good Rx Frames Tx Frames Interference Free Details Clients Mech Config Tools Statistics Overview MHC Address IP Address: CC-32-E5-F7-DD-IC 19.6.2.167 Model Firmware Version: EAP225-Outdoor(EU) v1.0 1.…

TP-LINK Omada OC200 - Configure and Monitor EAPs - 2

Note:

  • The available functions in the window vary due to the model and status of the device. • In Batch Config, you can only configure the selected devices, and the unaltered configurations will keep the current settings.
  • In Batch Config, if some functions, such as the 5 GHz band, are available only on some selected EAPs, the corresponding configurations will not take effect. To configure them successfully, check the model of selected devices first.

6.4.1 Configure EAPs

In the Properties window, click Config and then click the sections to configure the features applied to the selected AP(s), including the general settings, IP settings, Radios, SSIDs, VLAN, SNMP, and advanced functions.

General

In General, you can specify the device name and LED settings of the AP, and categorize it via device tags.

General Name: B0-95-75-E6-48-44 LED: Use Site Settings On Off Device Tags: Please Select... Apply Cancel

Name (Only for configuring a single device) Specify a name of the device.

LED

Select the way that device's LEDs work.

Use Site Settings: The device's LED will work following the settings of the site. To view and modify the site settings, refer to 4.2.2 Services.

On/Off: The device's LED will keep on/off.

Device Tags: Select a tag from the drop-down list or create a new tag to categorize the device.

■ IP Settings (Only for configuring a single device)

In IP Settings, select an IP mode and configure the parameters for the device.

If you select DHCP as the mode, make sure there is a DHCP server in the network and then the device will obtain dynamic IP address from the DHCP server automatically. You can set a fallback IP

address to hold an IP address in reserve for the situation in which the device fails to get a dynamic IP address. Enable Fallback IP and then set the IP address, IP mask and gateway.

IP Settings Mode: DHCP Static Fallback IP: Enable i Fallback IP Address: 192 . 168 . 0 . 254 Fallback IP Mask: 255 . 255 . 255 . 0 Fallback Gateway: . . . . (Optional) Apply Cancel

If you select Static as the mode, set the IP address, IP mask, gateway, and DNS server for the static address.

IP Settings Mode: DHCP Static IP Address: IP Mask: Gateway: Primary DNS Server: (Optional) Secondary DNS Server: (Optional) Apply Cancel

Radios

In Radios, you can control how and what type of radio signals the EAP emits. Select the frequency band 2.4GHz 5GHz and configure the following parameters.

Radios 2.4GHz 5GHz Status: Enable Channel Width: 20 / 40MHz Channel: Auto Tx Power (EIRP): High Note : The EIRP transmit power includes the antenna gain. Apply Cancel

Status If you disable the frequency band, the radio on it will turn off.
Channel WidthSpecify the channel width of the band. Two bands have different available options: 20 MHz, 40 MHz and 20/40 MHz for 2.4 GHz, and 20 MHz, 40 MHz, 80 MHz and 20/40/80 MHz for 5 GHz.Note that the option 20/40 MHz and 20/40/80 MHz channels enable higher data rates but leave fewer available channels for other 2.4 GHz and 5 GHz devices.
ChannelSpecify the operation channel of the EAP to improve wireless performance. If you select Auto for the channel setting, the EAP scans available channels and selects the channel where the least amount of traffic is detected.
Tx PowerSpecify the Tx Power (Transmit Power) in the 4 options: Low, Medium, High and Custom. The actual power of Low, Medium and High are based on the minimum transmit power (Min. Txpower) and maximum transmit power (Max. TxPower), which may vary in different countries and regions.Low: Min. TxPower + (Max. TxPower-Min. TxPower) * 20% (round off the value)Medium: Min. TxPower + (Max. TxPower-Min. TxPower) * 60% (round off the value)High: Max. TxPowerCustom: Specify the value manually.

■ WLANs

In WLANs, you can apply the WLAN group to the EAP and specify a different SSID name and password to override the SSID in the WLAN group. After that, clients can only see the new SSID

and use the new password to access the network. To create or edit WLAN groups, refer to 4.4 Configure Wireless Networks.

WLANs WLAN Group: test Name Band Overrides ACTION tp-link 2.4GHz, 5GHz guest 2.4GHz Showing 1-2 of 2 records < 1 > Apply Cancel

(Only for configuring a single device) To override the SSID, select a WLAN group, click in the entry and then the following page appears.

WLANs>SSID Override SSID Override: ✓ Enable SSID: tp-link Password: ............ Ø VLAN: ✓ Enable VLAN ID: 1 (1-4094) Save Cancel

SSID OverrideEnable or disable SSID Override on the EAP. If SSID Override enabled, specify the new SSID and password to override the current one.
VLANEnable or disable VLAN. If VLAN enabled, enter a VLAN ID to add the new SSID to the VLAN.

■ Services

In Services, you can configure Management VLAN to protect your network and SNMP to write down the location and contact detail.

Services VLAN Management VLAN: Enable LAN The controller will fail to manage your devices with wrong Management VLAN configurations. If you are not sure about your network conditions and the potential impact of any configurations, we recommend that you keep the default configurations. Refer to the C…

Management VLANTo configure Management VLAN, create a network in LAN first, and then select it as the management VLAN on this page. For details, refer to 4.3 Configure Wired Networks.The management VLAN is a VLAN created to enhance the network security. Without Management VLAN, the configuration commands and data packets are transmitted in the same network. There are risks of unauthorized users accessing the management page and modifying the configurations. A management VLAN can separate the management network from the data network and lower the risks.
SNMP(Only for configuring a single device) Configure SNMP to write down the location and contact detail. You can also click Manage to jump to Settings > Services > SNMP, and for detailed configuration of SNMP service, refer to 4.10.2 SNMP.

■ Advanced

In Advanced, configure Load Balance and QoS to make better use of network resources. Load Balance can control the client number associated to the EAP, while QoS can optimize the performance when handling differentiated wireless traffics, including traditional IP data, VoIP (Voice-over Internet Protocol), and other types of audio, video, streaming media.

Select the frequency band and configure the following parameters and features.

Advanced 2.4GHz 5GHz Load Balance Maximum Associated Clients: ✓ Enable 1 (1-511) RSSI Threshold: ✓ Enable 0 (-95-0 dBm) ETH Port Settings ETH1 VLAN: ✓ Enable 1 (1-4094) ETH2 VLAN: □ Enable ETH3 VLAN: □ Enable ETH3 PoE Out: □ Enable QoS Wi-Fi Multimedia (WMM): ✓ Enable No Acknowledgement: □ Enable Un…

Max Associated ClientsEnable this function and specify the maximum number of connected clients. If the connected client reaches the maximum number, the EAP will disconnect those with weaker signals to make room for other clients requesting connections.
RSSI ThresholdEnable this function and enter the threshold of RSSI (Received Signal Strength Indication). If the client's signal strength is weaker than the threshold, the client will lose connection with the EAP.
ETH VLAN/ETH2 VLAN/ETH3 VLAN(Only for Wall Plate AP) Enable this function and add the corresponding AP's LAN port to the VLAN specified here. Then the hosts connected to this EAP can only communicate with the devices in this VLAN.
ETH3 PoE Out(Only for Wall Plate AP with the PoE out port) Enable this function to supply power to the connected device on this port.
Wi-Fi Multimedia (WMM)With WMM enabled, the EAP maintains the priority of audio and video packets for better media performance.
No AcknowledgmentEnable this function to specify that the EAPs will not acknowledge frames with QoS No Ack. Enabling No Acknowledgment can bring more efficient throughput, but it may increase error rates in a noisy Radio Frequency (RF) environment.
Unscheduled Automatic Power Save DeliveryWhen enabled, this function can greatly improve the energy-saving capacity of clients.
OFDMA (Only for AP supporting 802.11 ax) Enable this feature to enable multiple users to transmit data simultaneously, and it will greatly improves speed and efficiency. Note that the benefits of OFDMA can be fully enjoyed only when the clients support OFDMA.

■ Manage Device

In Manage Device, you can upgrade the device's firmware version manually, move it to another site, synchronize the configurations with the controller and forget the AP.

Manage Device Custom Upgrade Choose the firmware file and upgrade the device. ↑ Browse Move to Site Move this device to another site of this controller. Please Select... Move Force Provision Click Force Provision to synchronize the configurations of the device with the controller. The device will di…

Custom UpgradeClick Browse and choose a file from your computer to upgrade the device. When upgrading, the device will be reboot and readopted by the controller. You can also check the box of Upgrade all devices of the same model in the site after the firmware file is uploaded.
Move to SiteSelect a site which the device will be moved to. After moving to another site, device configurations on the prior site will be replaced by that on the new site, and its traffic history will be cleared.
Force Provision(Only for configuring a single device) Click Force Provision to synchronize the configurations of the device with the controller. The device will lose connection temporarily, and be adopted to the controller again to get the configurations from the controller.
Forget this APClick Forget and then the device will be removed from the controller. Once forgotten, all configurations and history related to the device will be wiped out.

6.4.2 Monitor EAPs

One panel and four tabs are provided to monitor the device in the Properties window: Monitor Panel, Details, Clients, Mesh, and Statistics.

Monitor Panel

The monitor panel illustrates the active channel information on each radio band, including the EAP's operation channel, radio mode and channel utilization. Four colors are used to indicate the percentage of Rx Frames (blue), Tx Frames (green), Interference (orange), and Free bandwidth (gray).

| Category | Rx Frames (%) | Tx Frames (%) | Interference (%) | |---|---|---|---| | b/g/n mixed 2.4G | High (52% Utilized) | - | - | | a/n/ac mixed 5G | High (59% Utilized) | - | - |

You can hover the cursor over the channel bar for more details.

Ch.Util.(Busy/Rx/Tx)51% / 32% / 4%
Tx Pkts/Bytes4195 / 847.04 KB
Rx Pkts/Bytes24247 / 6.47 MB
Tx Error/Dropped0.0% / 0.0%
Rx Error/Dropped0.0% / 0.0%

Ch.Util.(Busy/Rx/Tx) Displays channel utilization statistics.

Busy: Displays the sum of Tx, Rx, and also non-WiFi interference, which indicates how busy the channel is.

Rx: Indicates how often the radio is in active receive mode.

Tx: Indicates how often the radio is in active transmit mode.

Tx Pkts/Bytes Displays the amount of data transmitted as packets and bytes.
Rx Pkts/Bytes Displays the amount of data received as packets and bytes.
Tx Error/DroppedDisplays the percentage of transmit packets that have errors and the percentage of packets that were dropped.
Rx Error/DroppedDisplays the percentage of receive packets that have errors and the percentage of packets that were dropped.

Details

In Details, you can view the basic information, traffic information, and radio information of the device to know the device's running status.

Overview

In Overview, you can view the basic information of the device. The listed information varies due to the device's status.

Overview
MAC Address:IP Address:
CC-32-E5-F7-DD-1C10.0.2.167
Model:Firmware Version:
EAP225-Outdoor(EU) v1.01.20.0 Build 20200422 Rel. 70 543
CPU Utilization:Memory Utilization:
2%51%
Uptime:
0 days 00:24:58

■ LAN (Only for devices in the Connected status)

Click LAN to view the traffic information of the LAN port, including the total number of packets, the total size of data, the total number of packets loss, and the total size of error data in the process of receiving and transmitting data.

LAN
Rx Packets:Rx Bytes:
4724936.73 KB
Rx Dropped Packets:Rx Errors:
00
Tx Packets:Tx Bytes:
822647.23 KB
Tx Dropped Packets:Tx Errors:
00

Click Uplink (Wireless) to view the traffic information related to the uplink AP, including the signal strength, transmission rate, ratio of packets number and size, and dynamic downstream rate.

Uplink (Wireless)
Uplink Device:Signal:
CC-32-E5-F7-DD-1C-22 dBm
Tx Rate:Rx Rate:
104Mbps526Mbps
Down Pkts/Bytes:Up Pkts/Bytes:
29 / 9.11 KB18 / 2.50 KB
Activity Speed: i
1.16 KB /s

■ Radios (Only for devices in the Connected status)

Click Radio to view the radio information including the frequency band, the wireless mode, the channel width, the channel, and the transmitting power. You can also view parameters of receiving/transmitting data on each radio band.

Radios 2.4GHz 5GHz Mode: Channel Width: 802.11b/g/n mixed 20/40MHz Channel: Tx Power: 11 / 2462MHz 20 Rx Packets: Rx Bytes: 173177 46.96 MB Rx Dropped Packets: Rx Errors: 0 0 Tx Packets: Tx Bytes: 21465 4.14 MB Tx Dropped Packets: Tx Errors: 0 0

Clients

In Clients, you can view the information of users and guests connecting to the AP, including client name, MAC address and the connected SSID. Users are clients connected to the AP's SSID with Guest Network disabled, while Guests are clients connected to that with Guest Network enabled. You can click the client name to open its Properties window.

All (1) Users (1) Guests (0) Client name or MAC Name MAC SSID admin 28-A0-2B-D8-00-28 admin Showing 1-1 of 1 records < 1 >

Mesh (Only for pending/connected/isolated devices supporting Mesh)

Mesh is used to establish a wireless network or expand a wired network through wireless connection on 5 GHz radio band. In practical application, it can help users to conveniently deploy APs without requiring Ethernet cable. After mesh network establishes, the EAPs can be configured and managed in Omada controller in the same way as wired EAPs. Meanwhile, because of the ability to self-organize and self-configure, mesh also can efficiently reduce the configuration.

Note that only certain EAP models support Mesh, and the EAPs should be in the same site to establish a Mesh network.

To understand how mesh can be used, the following terms used in Omada Controller will be introduced:

Root AP The AP is managed by Omada Controller with a wired data connection that can be configured to relay data to and from mesh APs (downlink AP).
Isolated APWhen the EAP which has been managed by Omada Controller before connects to the network wirelessly and cannot reach the gateway, it goes into the Isolated state.
Mesh APAn isolated AP will become a mesh AP after establishing a wireless connection to the AP with network access.
Uplink AP/Downlink APAmong mesh APs, the AP that offers the wireless connection for other APs is called uplink AP. A Root AP or an intermediate AP can be the uplink AP. And the AP that connects to the uplink AP is called downlink AP. An uplink AP can offer direct wireless connection for 4 downlink APs at most.
Wireless Uplink The action that a downlink AP connects to the uplink AP.
HopsIn a deployment that uses a root AP and more than one level of wireless uplink with intermediate APs, the uplink tiers can be referred to by root, first hop, second hop and so on. The hops should be no more than 3.

A common mesh network is shown below. Only the root AP is connected by an Ethernet cable, while other APs have no wired data connection. Mesh allows the isolated APs to communicate with pre-

configured root AP on the network. Once powered up, factory default or unadopted EAPs can detect the EAP in range and make itself available for adoption in the controller.

graph TD A["Host A (Controller Host) Switch"] --> B["Router (DHCP Server)"] B --> C["Internet"] C --> D["Internet"] B --> E["Root AP Mesh AP"] E --> F["(Hops: 1)"] E --> G["(Hops: 2)"] H["Wireless Uplink"] --> I["Mesh APs (Hops: 2)"]

After all the EAPs are adopted, a mesh network is established. The EAPs connected to the network via wireless connection also can broadcast SSIDs and relay network traffic to and from the network through the uplink AP.

To build a mesh network, follow the steps below:

1) Enable Mesh function. 2) Adopt the Root AP. 3) Set up wireless uplink by adopting APs in Pending(Wireless) or Isolated status.

  1. Go to Settings > Site to make sure Mesh is enabled.

Services LED: ✓ Enable Automatic Upgrades: □ Enable Channel Limit: □ Enable ⓘ Mesh: ✓ Enable ⓘ Auto Failover: ✓ Enable ⓘ Connectivity Detection: Auto (Recommended) ✓ Full-Sector DFS: ✓ Enable ⓘ

  1. Go to Devices to make sure that the Root AP has been adopted by the controller. The status of the Root AP is Connected.

Search or select log Q All Gateway Switches APs DEVICE NAME IP ADDRESS STATUS MODEL VERSION UPTIME ACTION 08-EA-DE-68-E3-11 192.168.0.1 CONNECTED TL-R005 >1.0 1.0.0 24 days 21:57:58 08-32-B-AC-30-F6 192.168.0.133 CONNECTED TL-S02088 <3.0 3.0.0 8 days 04:30:20 EA-33-B1-A8-22-A6 192.168.0.187 CONNECTE…

  1. Install the EAP that will uplink the Root AP wirelessly. Make sure the intended location is within the range of Root AP. The EAPs that are waiting for Wireless Uplink include two cases: factory default EAPs and EAPs that have been managed by the controller before. Go to Devices to adopt an EAP in Pending (Wireless) status or link an isolated AP.

1) For the factory default EAP, after powering on the device, the EAP will be in Pending (Wireless) status with the icon PENDING in the controller. Click to adopt the EAP in Pending (Wireless) status in the Devices list.

Search or select tag Q All Gateway Switches APs DEVICE NAME IP ADDRESS STATUS MODEL VERSION UPTIME ACTION SD-CA-BC-SD-E3-11 192.168.0.1 CONNECTED TL-RMS v1.0 1.0.0 24 days 28:57:58 60-12-B1-10-10-F6 192.168.0.133 CONNECTED TL-SQ2008 v3.0 1.0.0 8 days 04:36:20 EA-23-B1-06-23-E2 - PENDING EAP25-Outdoo…

After adoption begins, the status of Pending (Wireless) EAP will become Adopting (Wireless) and then Connected (Wireless). It should take roughly 2 minutes to show up Connected (Wireless) with the icon CONNECTED within your controller.

2) For the EAP that has been managed by Omada Controller before and cannot reach the gateway, it goes into Isolated status when it is discovered by controller again. Click to connect the Uplink AP in the Devices list.

Search or end: Log Q All Gateway/Switches APs DEVICE NAME IP ADDRESS STATUS MODEL VERSION UP TIME ACTION 03-EA-05-BB-EX-11 192.168.0.1 CONNECTED TL-RB05.v1.0 1.0.0 24 days 21:49:56 ① 03-33-B1-BD-30-F6 192.168.0.133 CONNECTED TL-RB200V v1.0 1.0.0 0 days 04:28:00 ② EA-23-51-06-22-52 192.168.0.7 ISOLAT…

The following page will be shown as below, click Link to connect the Uplink AP.

EA-23-51-06-22... ISOLATED Details Mesh Config Uplinks AP Name Channel Signal ACTION EA-33-51-A8-22-A0 44 -67 dBm Link Showing 1-1 of 1 records < 1 > Rescan

Once mesh network has been established, the EAP can be managed by the controller in the same way as a wired EAP. You can click the EAP's name in the Devices list, and click Mesh to view and configure the mesh parameters of the EAP in the Properties window.

In Mesh, if the selected AP is an uplink AP, this page lists all downlink APs connected to the AP.

Details Clients Mesh Config Tools Statistics This AP is a wired AP currently Downlinks AP Name Signal EA-23-51-06-22-52 -68 dBm Showing 1-1 of 1 records < 1 >

If the selected AP is a downlink AP, this page lists all available uplink APs and their channel, signal strength, hop, and the number of downlink APs. You can click Rescan to search the available uplink APs and refresh the list, and click Link to connect the uplink AP and build up a mesh network.

Uplinks
AP NameChannelSignalHopDownlinkACTION
CC-32-E5-F7-DD-1C36-46 dBm00Link
EA-23-51-06-22-5236-40 dBm00Link
Showing 1-2 of 2 records<1>Rescan

TP-LINK Omada OC200 - Mesh (Only for pending/connected/isolated devices supporting Mesh) - 8

Tips:

  • You can manually select the uplink AP that you want to connect in the uplink AP list. To build a mesh network with better performance, we recommend that you select the uplink AP with the strongest signal, least hop and least downlink AP.
  • You can enable Auto Failover to make the controller automatically select an uplink AP for the isolated AP to establish Wireless Uplink. And the controller will automatically select a new uplink AP for the mesh EAPs when the original uplink fails. For more details about Mesh global configurations, refer to the Mesh feature in 4.2.2 Services.

Tools

In Tools, you can enable RF Scanning to scan the RF (Radio Frequency) environments around the AP, which is useful for spectral analysis in channel selection and planning.

TP-LINK Omada OC200 - Tools - 1

Note:

  • The RF scanning may take several minutes. During the scanning, all clients using this AP will be disconnected, and the AP will be offline. You should select a spare time of network to start scanning. • The APs in the mesh network do not support RF Scanning.

Select the frequency band to view and analyze the scan results.

RF Scanning | Frequency | Channel | Value | | :--- | :--- | :--- | | 2.4GHz | -96 | -48 dBm | | 5GHz | -80 | -64 dBm | | Scan | -96 | -48 dBm | | The color bar reflects channel utilization (Lower is better). | 36 | 52 | | The color bar reflects channel utilization (Lower is better). | 40 | 56 | | Th…

Each colored bar graph displays the information about channel utilization and interference on a channel. The filling area of the bar represents the channel utilization. And the larger filling area means the higher utilization, which indicates the channel is busier in transmitting data. The color shade represents the level of interference. And the legend is displayed at the top.

The 2.4 GHz results are displayed in channel widths of 20 and 40 MHz. The 5 GHz results are displayed in channel widths of 20, 40, and 80 MHz.

The number below the bar graph displays the corresponding channel number for each channel width option. For example, channels 42, 58 and 106 are three of the 80 MHz channels. And the channel outline in blue is in use currently.

20 MHz Channels 1 6 11

You can hover the cursor over a channel option for more details.

| Channel | RF Scanning | |---------|-------------| | Radio | 2.4G (b/g/n mixed) | | Channel Width | 20 MHz | | Frequency Range | 2401-2423 MHz | | Utilization | 37.00% | | Interference | -95 dBm | | Interference Type | -91 dBm | | 2.4GHz | -96 to -48 dBm | | 5GHz | -96 to -48 dBm | | 20 MHz Channel…

Radio Displays the radio that the AP uses.

Channel Width Displays the width of the channel.

Used Channels Displays the channels in use.

Frequency Range Displays the range of frequencies.

Utilization Displays the percentage of the frequency range already in use.

Interference Displays the level of interference.

Interference Type

Displays the type of interference, including MWO (Microwave Oven), CW (Continuous Wave), WLAN (Wi-Fi signals) and FHSS (Frequency Hopping Spread Spectrum).

Statistics

In Statistics, you can monitor the utilization of the device in the last 24 hours via charts, including CPU/Memory Monitor, Channel Utilization, Dropped Packets, and Retried Packets. To view statistics of the device in a certain period, click the chart to jump to 8.2 View the Statistics of the Network.

| Time | CPU | Memory | | ---------- | ---- | ------ | | 11:15 am | ~0% | 12% | | 04:40 pm | ~0% | 12% | | 10:05 pm | ~0% | 12% | | 03:30 am | ~0% | 12% | | 11:10 am | ~0% | 12% |

7

Monitor and Manage the Clients

This chapter guides you on how to monitor and manage the clients through the Clients page using the clients table, the properties window, and the Hotspot Manager system. To view clients that have connected to the network in the past, refer to View the Statistics During the Specified Period with Insight. This chapter includes the following sections:

• 7.1 Manage Wired and Wireless Clients in Clients Page • 7.2 Manage Client Authentication in Hotspot Manager

TP-LINK Omada OC200 - Monitor and Manage the Clients - 1

7.1 Manage Wired and Wireless Clients in Clients Page

7.1.1 Introduction to Clients Page

The Clients page offers a straightforward way to manage and monitor clients. It displays all connected wired and wireless clients in the chosen site and their general information. You can also open the Properties window for detailed information and configurations.

Search Name: IP: MAC or channel All (2) Witness (%) Wind (%) USERNAME IP ADDRESS STATUS SSID/NETWORK AP/PORT ACTIVITY SPEED DOWNLOAD UPLOAD UP TIME ACTION PC 192.168.8.114 AUTHENTICATION/FREE LAN 88-66-77-85-44-10 3 Bytes i.s 0 Bytes 4.32 KB 11th 41m 13s PAD 192.168.8.200 AUTHENTICATION/FREE Test A…

7.1.2 Using the Clients Table to Monitor and Manage the Clients

To quickly monitor and manage the clients, you can customize the columns and filter the clients for a better overview of their information. Also, quick operations and batch configuration are available.

■ Customize the Information Columns

Click next to the Action column and you have three choices: Default Columns, All Columns, and Customize Columns. To customize the information shown in the table, click the checkboxes of information type.

To change the list order, click the column head and the icon 🔊 appears for you to choose the ascending or descending order.

Spanish Name: IP MAC of dclarer Air (S) Wireless (T) Wired (T) USERNAME IP ADDRESS : STATUS $ SID NETWORK APIPORT WIRELESS CONNECTION ACTIVITY SPEED DOWNLOAD UPLOAD UPTIME ACTION PC 162 MA3 114 AUTHENTICATION FREE LAN 88-86-77-05 44:29 192 Bytes /s 0 Bytes 162 KB 12h 40m 18s iPhone 162.160.2.200 AUT…

When this icon appears in the Wireless Connection column, it indicates the client is in the power-saving mode.

■ Filter the Clients

To search specific client(s), use the search box above the table. To filter the clients by their connection type, use the tab bars above the table. For wireless clients, you can further filter them by the frequency band and the type of connected wireless network.

Search Name, IP, MAC or channelFilter clients using the search box based on username, IP address, MAC address or channel.
All (2)Wireless (1)Wired (1)Filter clients based on their connection type.
All (2)2.4 GHz (0)5 GHz (2)(For wireless clients) Filter wireless clients based on the frequency band they are using.
All (2)Users (0)Guests (2)(For wireless clients) Filter wireless clients based on the type of connected wireless network. Guests are clients connected to the guest network, which you can set during the Quick Setup, creating wireless networks, etc.

■ Quick Operations

For quick operations on a single client, click the icons in the Action column. The available icons vary according to the client status and connection type.

Click to block the client in the chosen site. You can view blocked clients in 8.4.1 Known Clients.
(With portal authentication enabled) Click to manually authorize the client that has not passed the portal authentication.
(With portal authentication enabled) Click to unauthorized the client that has passed the portal authentication.
(For wireless clients) Click to reconnect the wireless client to the wireless network.

■ Multiple Select for Batch Configuration

To select multiple clients and add them to the Properties window, click ☑ on the upper-right and then check the boxes. When you finish choosing the clients, click Edit Selected and the chosen client(s) will be added to the Properties window for batch client configuration.

Search Name: IP MAC or channel AB (2) Wireless (1) Wired (1) USERNAME IP ADDRESS STATUS SSD/NETWORK AP/PORT ACTIVITY SPEED DOWNLOAD UPLOAD UPTIME ACTION PC 152.168.5.114 AUTHENTICATION/FREE LAN 88-66-77-99-44-20 152 Bytes / s 3 Bytes 152.63 KB 12h 40m 11s iPhone 152.168.5.200 AUTHENTICATION/FREE Tes…

7.1.3 Using the Properties Window to Monitor and Manage the Clients

In Properties window, you can view more detailed information about the connected client(s) and manage them. To open the Properties window, click the entry of a single client, or click the 📋 icon to select multiple clients for batch configuration. Use the following icons for the Properties window.

Click to select multiple clients and add them to the Properties window for batch monitoring and management.
Click to minimize the Properties window to an icon. To reopen the minimized Properties window, click ☐.
Click to maximize the Properties window. You can also use the icon on pages other than the Clients page.
Click to close the Properties window of the chosen client(s). Note that the unsaved configuration for the client(s) will be lost.
The number on the lower-right shows the number of clients in the batch client configuration.

Monitor and Manage a Single Client

■ Monitor a Single Client

After opening the Properties window of a single client, you can view the basic information, traffic statistics, and connection history under the Details and History tabs.

Under the Details tab, Overview and Statistics displays the basic information and traffic statistics of the client, respectively. The listed information varies due to the client's status and connection type.

PC Details History Config Overview MAC Address: Hostname: F8-BC-12-9B-93-1B SOHO_1-PC IP Address: Uptime: 192.168.0.187 11h 33m 42s Network: Port: LAN 00-0A-EB-45-F7-A5 #1 Statistics

PC Details History Config Overview Statistics Activity Download Speed: Down Pkts/Bytes: 23 B /s -- / 0 Up Pkts/Bytes: 11 / 97.97 KB

Under the History tab, you can view the connection history of the client.

PC Details History Config Date/Time Duration Download Upload May 06, 2020 20:02:22 4h 29m 12s 0 Bytes 0 Bytes May 06, 2020 08:47:59 4h 18m 39s 0 Bytes 0 Bytes May 06, 2020 04:29:20 37m 11s 0 Bytes 0 Bytes Showing 1-3 of 3 records < 1 >

■ Manage a Single Client

In Config, you can configure the following parameters:

PC Details History Config Alias: PC (Optional) Rate Limit: Custom Download Limit: Enable Kbps Upload Limit: Enable Kbps Use Fixed IP Address: Enable Network: LAN IP Address: Apply Cancel

AliasSpecify the client's alias to better identify different clients, and the alias is used as the client's username in the table on the Clients page.
Rate LimitSelect an existing rate limit profile, create a new rate limit profile or customize the rate limit for the client.Custom: Specify the download/upload rate limit based on needs.Note: Rate Limit on this page is only available for the clients connected to the EAPs. To limit the rate of the clients connected to the gateway or switch, go to Bandwidth Control page.
Download/Upload LimitClick the checkbox and specify the rate limit for download/upload for wireless clients using the voucher code(s). The value of the download and upload rate can be set in Kbps or Mbps.

Use Fixed IP Address

Click the checkbox to configure a fixed IP address for the client. With this function enabled, select a network and specify an IP address for the client. To view and configure networks, refer to 4.3 Configure Wired Networks.

Note: An Omada-managed gateway is required for this function. Otherwise, you cannot set a fixed IP address for the client.

Monitor and Manage Multiple Clients

To manage multiple clients at the same time, click ☐, select multiple clients, and click Edit Selected. Then you can configure the following parameters under the Config tab.

Batch Client Configuration Clients Config Rate Limit: Keep Existing IP Settings: Keep Existing Apply Cancel

Rate LimitSelect an existing rate limit profile, create a new rate limit profile or customize the rate limit for the clients.Keeping Existing: The rate limit of the chosen clients remains their current settings.Custom: Specify the download/upload rate limit based on needs.Note: Rate Limit on this page is only available for the clients connected to the EAPs. To limit the rate of the clients connected to the gateway or switch, go to Bandwidth Control page.
Download/Upload LimitClick the checkbox and specify the rate limit for download/upload for wireless clients using the voucher code(s). The value of the download and upload rate can be set in Kbps or Mbps.
IP SettingKeeping Existing: The IP setting of the chosen clients remains their current settings.Use DHCP: The IP addresses of the clients is automatically assigned by the DHCP server, such as the Layer 3 switch and the gateway.Use Fixed IP Address: Select a network and assign fixed IP addresses to the chosen clients manually. To view and configure networks, refer to4.3 Configure Wired Networks. Note that an Omada-managed gateway is required for this function. Otherwise, you cannot set fixed IP addresses for the chosen clients.

You can view their names and IP addresses in the Clients tab and remove client(s) from Batch Client Configuration by clicking ✗ in the Action column.

Batch Client Configuration Clients Config Client Name IP Address Action Phone 192.168.0.142 iPad 192.168.0.143 Showing 1-2 of 2 records < 1 >

7.2 Manage Client Authentication in Hotspot Manager

Hotspot Manager is a portal management system for centrally monitoring and managing the clients authorized by portal authentication. The following four tabs are provided in the system for a easy and direct management.

Authorized Clients View the records of the connected and expired portal clients.

VouchersCreate vouchers for Portal authentication, and view and manage the related information.
Local UsersCreate local user accounts for Portal authentication, view their information, and manage them.
OperatorsCreate operator accounts for Hotspot management, view their information, and manage them.

7.2.1 Authorized Clients

The Authorized Clients tab is used to view and manage the clients authorized by portal system, including the expired clients and the clients within the valid period.

To open the list of Authorized Clients, click Hotspot Manager from the drop-down list of Sites and click Authorized Clients in the pop-up page. You can search certain clients using the search box, view their detailed information in the table, and manage them using the action column.

tp-link omada Sites Default Authorized Clients Vouchers Local Users Operators Search Name, SMO Networks or Authorized By Name MAC ADDRESS $S/D NETWORK AUTHORIZED BY DOWNLOAD UPLOAD START TIME STATUS EXPIRATION TIME ACTION Phone 2 BB-C1-11-15-CF-26 Test A Administrator - admin 0 0 Jan 17, 2020/02 41:…

TP-LINK Omada OC200 - Authorized Clients - 2

TP-LINK Omada OC200 - Authorized Clients - 3

TP-LINK Omada OC200 - Authorized Clients - 4

Click to extend the valid period of the authorized client. You can choose the preset time length or set a customized period based on needs.

Click to disconnect the authorized client(s). When you disconnect an authorized client, the client needs to be re-authenticated for the next connection.

Click to delete the expired client from the list.

7.2.2 Vouchers

The Vouchers tab is used to create vouchers and manage unused voucher codes. With voucher configured and codes created, you can distribute the voucher codes generated by the controller to

clients for them to access the network via portal authentication. For detailed configurations, refer to 4. 9.1 Portal.

Create vouchers

Follow the steps below to create vouchers for authentication:

  1. Click Hotspot Manager from the drop-down list of Sites and click Vouchers in the pop-up page.
  2. Click +Create Vouchers on the lower-left, and the following window pops up. Configure the following parameters and click Save.

TP-LINK Omada OC200 - Create vouchers - 1

tp-link

omada

Authorized Clients

Vouchers

Local Users

Operators

Create Vouchers

Portal:

All

V

Code Length:

6

(6-10)

Amount:

10

(1-500)

Type:

TP-LINK Omada OC200 - Create Vouchers - 1

Limited Usage Counts

TP-LINK Omada OC200 - Create Vouchers - 2

(1-999)

TP-LINK Omada OC200 - Create Vouchers - 3

Duration:

8 Hours

V

TP-LINK Omada OC200 - Create Vouchers - 4

Download Limit, Upload Limit, and Traffic Limit on this page are only available for wireless clients connected to the SSIDs with Portal authentication enabled. To limit the rate of wired clients connected to the switch and gateway, go to the Settings-Transmission-Bandwidth Control page.

Rate Limit:

Custom

V

Download Limit:

TP-LINK Omada OC200 - Create Vouchers - 5

Enable

Kbps

(1-10485760)

Upload Limit:

TP-LINK Omada OC200 - Create Vouchers - 6

Enable

Kbps

(1-10485760)

Traffic Limit:

TP-LINK Omada OC200 - Create Vouchers - 7

Enable

Limit

Every Day

traffic to

MB

(1-10485760)

Description:

TP-LINK Omada OC200 - Create Vouchers - 8

(Option

Save

Cancel

Portal Select the portal for which the vouchers will take effect.

Code Length Specify the length of the code(s) from 6 to 10 digits.

Amount Specify the number of voucher codes you want to create.

Type Select a type to limit the usage counts or the number of authorized users of a voucher code.
Limited Usage Counts: The voucher code can only be used for a limited number of times within its valid period.
Limited Online Users: The voucher code can be used for an unlimited number of times within its valid period, but only a limited number of wireless clients can access the network with this voucher code at the same time.
Duration Select the valid period for the voucher code(s).
Rate LimitSelect an existing rate limit profile, create a new rate limit profile or customize the rate limit for the voucher codes.
Custom: Specify the download/upload rate limit based on needs.
Download/Upload LimitClick the checkbox and specify the rate limit for download/upload for wireless clients using the voucher code(s). The value of the download and upload rate can be set in Kbps or Mbps.
Note: Download/Upload Limit on this page are only available for wireless clients connected to the SSIDs with Portal authentication enabled. To limit the rate of wired clients connected to the switch and gateway, go to the Settings >Transmission >Bandwidth Control.
Traffic LimitClick the checkbox and specify the daily/weekly/monthly/total traffic limit for the voucher, and the value of the traffic limit can be set in MB or GB. Once the limited is reached, the client(s) can no longer access the network using the voucher.
Note: Traffic Limit on this page are only available for wireless clients connected to the SSIDs with Portal authentication enabled. To limit the rate of wired clients connected to the switch and gateway, go to the Settings >Transmission >Bandwidth Control.
Description (optional)Enter notes for the created voucher code(s), and the input description is displayed in the voucher list under the voucher tab.

3. The voucher codes are generated and displayed in the table.

Authorized Clients Vouchers Local Users Operators Search Code or Notes Fosing Language English PORTAL UNTAINED VOCUMS FREE SWITCHED VOCUMS CERIKY CODE Created TIME DOWNLOAD UPLOAD TRAFFIC Notes Duration type PORTAL Action 809312 Feb 01, 2021 05:30:37 22.00 Mbps 6.00 Hours Portal_Default 600710 Feb 0…

The voucher code can be used for an unlimited number of times within its valid period, but only a limited number of wireless clients can access the internet with this voucher code at the same time. The number on the right shows the limited number of users.
The voucher code can only be used for a limited number of times within its valid period. The number on the right shows the limited number of authentication times.
  1. Print the vouchers. Click the print icon to print a single voucher, or select the checkboxes of vouchers and click Print Selected Vouchers to print the selected vouchers. You can also click Print All Unused Vouchers to print all unused vouchers.
307690Valid for 8hLimited Usage Counts One084520Valid for 8hLimited Usage Counts One
924665Valid for 8hLimited Usage Counts One232608Valid for 8hLimited Usage Counts One
701945Valid for 8hLimited Usage Counts One473875Valid for 8hLimited Usage Counts One
141716Valid for 8hLimited Usage Counts One999934Valid for 8hLimited Usage Counts One
825813Valid for 8hLimited Usage Counts One180815Valid for 8hLimited Usage Counts One
  1. Distribute the vouchers to clients, and then they can use the codes to pass authentication. If a voucher code expires, it will be automatically removed from the list.
  2. To delete certain vouchers manually, click the delete icon to delete a single voucher, or click Delete to delete multiple voucher codes at a time.

7.2.3 Local Users

The Local Users tab is used to create user accounts for authentication. With the Local User configured, clients are required to enter the username and password to pass the authentication. You can create multiple accounts and assign them to different users. For detailed configurations, refer to 4.9.1 Portal.

Create Local Users

There are two ways to create local user accounts: create accounts on the page and import from a file. To create local user accounts, follow the steps below.

  1. Click Hotspot Manager from the drop-down list of Sites and click Local Users in the pop-up page.

2. Create Local User accounts through two different ways.

■ Create Local User accounts

Click +Create User on the lower-left, and the following window pops up. Configure the following parameters and click Save.

tp-link | omada Authorized Clients Vouchers Local Users Operators Create User Portal: All Username: Password: Status: Enable Authentication Timeout: Dec 31, 2021 in Asia/Hong_Kong MAC Address Binding Type: No Binding Maximum Users: 1 (1-2048) Name: (Optional) Telephone: (Optional) Download Limit, Up…

Portal Select the portal for which the local users will take effect.

UsernameSpecify the username. The username should be different from the existing ones, and it is not editable once it is created.
Password Specify the password. Local users are required to enter the username and password to pass authentication and access the network.
StatusWhen the status is enabled, it means the user account is valid. You can disabled the user account, and enable it later when needed.
Authentication TimeoutSpecify the authentication timeout for local users. After timeout, the users need to log in again on the authentication page to access the network.
MAC Address Binding TypeThere are three types of MAC binding: No Binding, Static Binding and Dynamic Binding.No Binding: No MAC address is bound to the local user account.Static Binding: Bind a MAC address to this user account manually. Then only the user with the this MAC address can use the username and password to pass the authentication.Dynamic Binding: The MAC address of the first user that passes the authentication will be bound to this account. Then only this user can use the username and password to pass the authentication.
Maximum UsersSpecify the maximum number of users that can use this account to pass the authentication.
Name (optional) Specify a name for identification.
Telephone (optional) Specify a telephone number for identification.
Rate LimitSelect an existing rate limit profile, create a new rate limit profile or customize the rate limit for the local users.Custom: Specify the download/upload rate limit based on needs.
Download/Upload LimitClick the checkbox and specify the rate limit for download/upload for users of the local user account. The value of the download/upload rate can be set in Kbps or Mbps.Note: Download/Upload Limit on this page are only available for wireless clients connected to the SSIDs with Portal authentication enabled. To limit the rate of wired clients connected to the switch and gateway, go to the Settings >Transmission >Bandwidth Control.
Traffic LimitClick the checkbox and specify the daily/weekly/monthly/total traffic limit for the local user account, and the value of the traffic limit can be set in MB or GB. Once the limited is reached, the user(s) can no longer access the network using this account.Note: Traffic Limit on this page are only available for wireless clients connected to the SSIDs with Portal authentication enabled. To limit the rate of wired clients connected to the switch and gateway, go to the Settings >Transmission >Bandwidth Control.

Create Local User accounts from files.

Click Import Users on the upper-right, and the following window pops up. Select a file in the format of CSV or Excel, and click Import. To see required parameters and corresponding explanation, refer to Create Local User accounts. Note that the imported file will override the current user data.

Import Users Portal: All Choose File: Please select a file. Browse Only CSV, XLS and XLSX file types are supported. The imported file will override the current user data. Import Cancel

Portal: Select the portal to which the local users will be imported.

  1. The local user account(s) will be created and displayed in the module. You can view the information of the created local users, search certain accounts through the name, and use icons for management.

tp-link omada Sites: Default Authorized Clients Vouchers Local Users Operators Search Name Q USERNAME ENABLED EXPIRATION TIME MAXIMUM USERS DOWNLOAD UPLOAD TRAFFIC ACTION User 1 Dec 31, 2009 11:59:18 pm 1 10240.00 Kbps 10240.00 Kbps 100.00 KB User 2 Dec 31, 2009 11:59:18 pm 2 User 3 Dec 31, 2009 11:…

Import UsersClick to add local user(s) from files in the format of CVS or Excel. It is recommended when you need to create local users in batches. Select the portals based on needs, and the local users will be imported to the chosen portal.Note that the imported file will override the current user data.
Export UsersClick to export the local user(s) to files in the format of CVS or Excel. Select the portals based on needs, and the local users of the chosen portal will be exported.
Click to edit the parameters for the local user.
Click to delete the local user.

7.2.4 Operators

The Operators tab is used to manage and create operator accounts that can only be used to remotely log in to the Hotspot Manager system and manage vouchers and local users for specified sites. The operators have no privileges to create operator accounts, which offers convenience and ensures security for client authentication.

Create Operators

To create operator accounts, follow the steps below.

  1. Click Hotspot Manager from the drop-down list of Sites and click Operators in the pop-up page.
  2. Click + Create Operator on the lower-left, and the following window pops up.

tp-link | omada Authorized Clients Vouchers Local Users Operators Create Operator Username: Password: Description: Site Privileges: (Please Select... Save Cancel

  1. Specify the username, password and description (optional) for the operator account. Then select sites from the drop-down list of Site Privileges. Click Save.
  2. The operator accounts are created and displayed in the table. You can view the information of the created operator accounts on the page, search certain accounts through the name and notes, and use icons for management.

tp-link omada Authorized Clients Vouchers Local Users Operators Search Name or Index USERNAME PASSWORD NOTES ACTION Operator 1 ******** €5 for default site ✓ B Operator 2 ******** $3 for site 2 ✓ B Showing 1-2 of 2 records ( 1 ) 10 page Go To page: GO + Create Operator

TP-LINK Omada OC200 - Create Operators - 3

Click to edit the parameters for the operator account.

TP-LINK Omada OC200 - Create Operators - 4

Click to delete the operator account.

  1. Then you can use an operator account to log in to the Hotspot Manager system:

■ For software controller

Visit the URL https://Omada Controller Host's IP Address:8043/hotspot/login (for example: https://192.168.0.174:8043/hotspot/login), and use the operator account to enter the hotspot manager system.

■ For hardware controller

Visit the URL https://Omada Controller Host's IP Address:443/hotspot/login (for example: https://192.168.0.174:443/hotspot/login), and use the operator account to enter the hotspot manager system.

■ For cloud-based controller

Visit the URL https://URL of the controller/hotspot/login, and use the operator account to enter the hotspot manager system.

8

Monitor the Network

This chapter guides you on how to monitor the network devices, clients, and their statistics. Through visual and real-time presentations, Omada SDN Controller keeps you informed about the accurate status of the managed network. This chapter includes the following sections:

• 8.1 View the Status of Network with Dashboard • 8.2 View the Statistics of the Network • 8.3 Monitor the Network with Map • 8.4 View the Statistics During Specified Period with Insight • 8.5 View and Manage Logs

8.1 View the Status of Network with Dashboard

8.1.1 Page Layout of Dashboard

Dashboard is designed for a quick real-time monitor of the site network. An overview of network topology is at the top of Dashboard, and the below is a tab bar followed with customized widgets.

| Client | Clients | Frequency (%) | | --- | --- | --- | | FBBC-10-6D-71.57 | 489.48 MB | 14.52 | | none_7_Pro_5G-Bata6@M45 | 70.81 MB | 10.71 | | HUAWEI_Maiw_20_Pro-id | 4.91 MB | 5.61 | | Clor | 3.40 MB | 3.4 GHE |

Topology Overview

Topology Overview on the top shows the status of ISP Load and numbers of devices, clients and guests. ISP Load has four statuses: Unknown, Good, Medium, Poor.

graph LR A["10 Mbps<br>Internet Capacity"] --> B["0%<br>Gateway"] B --> C["1<br>Switches"] C --> D["6<br>EAPs"] D --> E["8<br>Clients"] E --> F["0<br>Guests"]

You can hover the cursor over the gateway, switch, AP, client or guest icons to check their status. For detailed information, click the icon here to jump to the Devices or Clients section.

1 Switches Total Switches 1 Connected 1 Wired Clients 2 Total Ports 8 Available Ports 6 Power Consumption 0

Tab Bar

You can customize the widgets displayed on the tab for Dashboard page. Three tabs are created by default and cannot be deleted.

NetworkClients+Mar 16, 2021 - Mar 17, 2021
NetworkDisplays Alerts, Wi-Fi Traffic Distribution, Wi-Fi Summary and Traffic Activities by default.
ClientsDisplays Most Active Clients, Clients Freq Distribution, and Client Activities by default.

In the tab bar, you can take the following action to edit the tabs and customize the widget to be displayed.

Click the icon to edit the tabs. For the default tabs, you can reset them to the default settings. For a created tab, you can edit its name or delete it.
+Click the icon and enter the name in the pop-up window to create a new tab.
Nov 22, 2020 - Nov 23, 2020Click the date to display a calendar. Click a specific date twice in the calendar for the widgets to display its statistics. To display the statistic of a time range, click the start date and end date in the calendar.
Click a tab and then click the widget in the pop-up page to add it to this tab or remove it.

8.1.2 Explanation of Widgets

The widgets are divided into two categories: Network, Client. You can click the 📄 icon to add or remove the widgets.

| Period | IBP Load (kW) | Alerts | |--------|---------------|--------| | Sep-15 | 18M | 3M | | Oct-15 | 16M | 4M | | Nov-15 | 17M | 5M | | Dec-15 | 19M | 6M | | Jan-16 | 20M | 7M | | Feb-16 | 18M | 6M | | Mar-16 | 17M | 5M | | Apr-16 | 19M | 6M | | May-16 | 21M | 7M | | Jun-16 | 20M | 6M | | Jul-16…

NetworkAlerts, ISP Load, VPNs, Most Active EAPs, Most Active Switches,Wi-Fi Traffic Distribution, Wi-Fi Summary, Switching Summary, Traffic Distribution, Client Distribution, Traffic Activities, Retried Rate/Dropped Rate, Top Devices Usage, PoE Utilization, Top Interference
ClientMost Active Clients, Longest Client Uptime, Clients Freq Distribution, Client Activities, Clients Association Activities, Association Failures, Clients SSID Distribution, Clients with on Boarding Times, Clients with RSSI

Network

Widgets in Network use lists and charts to illustrate the traffic status of wired and wireless networks in the site, including traffic statistics, the most active devices, VPN connection, distribution, PoE utilization, and interference.

Alerts

The Alerts widget displays the total number of unarchived alerts happened in the site and details of the latest five. To view all the alerts and archive them, click See All to jump to Log > Alerts. To

specify events appeared in Alerts, go to Log > Notifications and configure the events as the Alert level. For details, refer to 8.5 View and Manage Logs.

Alerts See All > 11 Alerts • 2020-05-28 09:35:03 am CC-32-E5-A4-B1-AC detected Ping of Death attack and dropped 2 packets. • 2020-05-28 07:33:17 am CC-32-E5-A4-B1-AC detected Ping of Death attack and dropped 16 packets. • 2020-05-27 07:25:20 pm CC-32-E5-A4-B1-AC detected Ping of Death attack and dro…

■ ISP Load

ISP Load use a line chart to display the throughput and latency of gateway's WAN port within the time range. Click the tab on the right to view the statistics of each WAN port and move the cursor on the line chart to view specific values of throughput and latency. For detailed statistics of certain gateway's WAN port within a time range, refer to 8.2 View the Statistics of the Network.

| Time | Throughput (Mbps) | Latency (msec) | |------|-------------------|----------------| | 0 | ~0 | ~100 | | 1 | ~0 | ~100 | | 2 | ~0 | ~100 | | 3 | ~0 | ~100 | | 4 | ~0 | ~100 | | 5 | ~0 | ~100 | | 6 | ~0 | ~100 | | 7 | ~0 | ~100 | | 8 | ~0 | ~100 | | 9 | ~0 | ~100 | | 10 | ~0 | ~100 | | 11 | ~0…

To test the current download and unload speed and the latency of WAN port, click Test Speed on the widget to display the speed test result.

■ VPNs

VPNs displays the information of PPTP and L2TP VPN server and PPTP and L2TP VPN client, including VPN name, status, VPN tunnels, average Tx data and average Rx data. Click the tab to display the statistics of the VPN server and VPN client.

VPNs VPN Server VPN Client Name Status Tunnels Average Tx Data Average Rx Data I2tp_server ● 1 409.65 MB 395.62 MB pptp_server ● 1 198.37 MB 297.34 MB < 1 > Go To page: GO

VPNs VPN Server VPN Client Name Status Tunnels Average Tx Data Average Rx Data I2tp_client ● --- 410.01 MB 395.16 MB pptp_client ● --- 200.58 MB 296.34 MB < 1 > Go To page: GO

Name Displays the name of VPN server or VPN client.
Status Displays the connection status of VPN server or VPN client.
Tunnels Displays the number of VPN tunnels for the VPN server.
Average Tx Data(For VPN Server) Displays the traffic of all tunnels transmitted to the VPN server.(For VPN Client) Displays the amount of traffic transmitted to the VPN client.
Average Rx Data(For VPN Server) Displays the traffic of all tunnels received from the VPN server.(For VPN Client) Displays the amount of traffic received from the VPN client.

■ Most Active EAPs/Most Active Switches

These two widgets can display, respectively, 15 most active EAPs and switches in the site based on the total number of traffic within the time range. Only the devices that have been adopted by the controller will be displayed.

To view all the devices discovered by the controller, click See All to jump to the Devices section. You can also click the traffic number in the widget to open the device's Properties window for further

configurations and monitoring. For details, refer to 6 Configure and Monitor Omada Managed Devices.

Most Active EAPs | Category | Value | | :--- | :--- | | EA-23-51-06-22-52 | 2.14 GB > | | 1C-3B-F3-A8-99-5C | 1.08 GB > | | 00-00-FF-FF-0E-80 | 48.12 MB > | | EA-33-51-A8-22-A0 | 552.96 KB > |

■ Wi-Fi Traffic Distribution

The Wi-Fi Traffic Distribution widget displays channel distribution of all connected EAPs in the site. Good, Fair, and Poor are used to describe channel status which indicates channel interference from low to high. You can hover your cursor over the band to view the number of EAPs and clients on the channel.

TP-LINK Omada OC200 - ■ Wi-Fi Traffic Distribution - 1

■ Wi-Fi Summary

The Wi-Fi Summary widget summarizes the real-time status of wireless networks in the site, including the number of connected EAPs and clients, the channel utilization, and the total number of traffic within the time range.

| Category | Value | | -------------------- | --------- | | EAPs Online | 5 | | Clients | 8 | | Channel Utilization | 57.00% | | Traffic | 18.25 GB |

■ Switching Summary

The Switching Summary widget summarizes the real-time status of switches in the site, including the number of connected switches and clients, the port utilization, and the total amount of traffic within the time range.

| Category | Value | | ------------------ | --------- | | Switches Online | 1 | | Clients | 2 | | Port Utilization | 25.00% | | Traffic | 11.37 GB |

■ Traffic Distribution

The Traffic Distribution widget uses a pie chart to display the traffic distribution on EAPs and switches in the site within the time range. Click the tab to display the statistic of EAPs or switches, and click the slice to view the total number of traffic, its proportion, and the device name.

Traffic Distribution | Category | Value (MB) | Percentage (%) | |---|---|---| | EAPs | 1734.8 | 9.28 | | Switches | | | | 00-31-92-A4-4E-5A | | | | 00-31-92-A4-4E-5A | | | | E4-C3-2A-5... | | | | EAP520_yyL... | | | | 00-31-92-A... | | |

■ Client Distribution

The Client Distribution widget uses a sunburst chart to display the real-time distribution of connected clients in the site. The chart has up to three levels. The inner circle is divided by the

device category the clients connected to, the middle is by the device name, and the outer is by the frequency band. You can hover the cursor over the slice to view specific values.

Clients Distribution| Category | Value | |---|---| | Swatches | 1 | | 00-32-E5-69-B5-B0 | 1 | | B0-95-75-E6-48-C2 | 2 | The chart displays the relative proportions of each category within a single segment. The labels 'EAPs' and 'B0-B5-B6-B8-C2' are also present but not explicitly labeled in the image. There is no expli…

■ Traffic Activities

The Traffic Activities widget displays the Tx and Rx data of EAPs and switches within the time range. Only activities of the devices in the connected status currently will be counted.

Click the tab to display the statistic of EAPs or switches, and move the cursor on the line chart to view specific values of traffic. For detailed statistics of certain devices within a time range, refer to 8.2 View the Statistics of the Network.

| Date | Tx Data | Rx Data | | ---------- | ------- | ------- | | 2020-05-28 01:10 am | 2.94MB | 24.31MB |

■ Retried Rate/Dropped Rate

The Retried Rate/Dropped Rate widget displays the rate of retried and dropped packets of the connected EAPs within the time range. Select an AP from the list and click the tab to display the chart of retried rate or dropped rate. You can move the cursor on the point to view specific values.

| Date | Dropped Rate | | ---------- | ------------ | | 2020-05-28 03:40 am | 37.29 | | Dropped Times | 1896 |

Retried Rate Displays the percentage of packets that needed to be re-sent because they were corrupted upon arriving at the proper destination. Dropped Rate Displays the percentage of packets that were dropped before reaching their intended destination.

■ Top Devices Usage

The Top Devices Usage widget displays the CPU utilization and memory utilization of devices within the time range. Click the tab to select the CPU or memory for display. Click the traffic number in the widget to open the device's Properties window for further configurations and monitoring. For details, refer to 6 Configure and Monitor Omada Managed Devices.

Top Devices Usage | Device | CPU (%) | Memory (%) | | :--- | :--- | :--- | | EAP620_yytest_lab | 16.00 | > | | 00-31-92-A4-4E-D4 | 14.00 | > | | E4-C3-2A-57-97-76 | 6.00 | > | | E4-C3-2A-57-71-AC | 6.00 | > | | 84-D8-1B-B3-A8-76 | 5.00 | > |

■ PoE Utilization

The PoE Utilization widgets describes the PoE utilization of a switch. Select a switch from the switch list to display the ports connected to PoE devices. You can hover the cursor over a certain port to

view specific values. The bar below displays the current power capacity provided by PoE and its proportion of the PoE budget.

PoE Utilization | Port Number | Power Capacity (W) | | :--- | :--- | | 1 | 0 W | | 2 | 500 W | | 3 | 500 W | | 4 | 500 W | | 5 | 500 W | | 6 | 500 W | | 7 | 500 W | | 8 | 500 W | | 9 | 500 W | | 10 | 500 W | | 11 | 500 W | | 12 | 500 W | | 13 | 500 W | | 14 | 500 W | | 15 | 500 W | | 16 | 500 W | |…

■ Top Interference

The Top Interference widget displays the environment interference of wireless products. Click the tab to select the 2.4 GHz band or 5 GHz band. Click the traffic number in the widget to open the device's Properties window for further configurations and monitoring. For details, refer to 6 Configure and Monitor Omada Managed Devices.

Top Interference | Interference | Value (%) | | :--- | :--- | | EAP620_yytest_lab | 53.00 | | EAP620_yytest_office | 48.00 | | 00-31-92-A4-4E-5A | 47.00 | | 00-31-92-A4-4E-D4 | 45.00 | | 84-D8-1B-B3-A8-76 | 10.00 |

Client

Widgets in Clients use lists and charts to illustrate the traffic status of wired and wireless clients in the site, including the most active clients, activity statistics and distribution.

■ Most Active Clients

The Most Active Clients widget can display 15 most active clients. Only the clients in the connected status currently will be displayed.

To view all the clients connected to the network, click See All to jump to the Clients section. You can also click the traffic number in the widget to open the client's Properties window for further configurations and monitoring. For details, refer to 7.1 Manage Wired and Wireless Clients in Clients Page.

Most Active Clients See All > MEIZU-16T 70.23 MB > yangweiiedeiMac 4.32 MB > Honor_9-a0048737cb90... 1.38 MB >

■ Longest Client Uptime

The Longest Client Uptime widget can display up to 15 clients sorted by the uptime. Only the clients in the connected status currently will be displayed. You can also click the uptime in the widget to open the client's Properties window for further configurations and monitoring. For details, refer to 7.1 Manage Wired and Wireless Clients in Clients Page.

Longest Client Uptime yangweiiedeiMac 3h 27m 15s> MEIZU-16T 2h 16m 54s> Honor_9-a0048737cb9... 35m 17s>

■ Clients Freq Distribution

The Clients Freq Distribution widget uses a donut chart to display the distribution of wireless clients connected to the 5 GHz band and 2.4 GHz band in the site. The chart has two levels. The inner circle shows the total number of wireless clients, and the outer displays the proportion of clients that

connect to the two bands. You can hover the cursor over the slice to view the number of clients in 2.4 GHz or 5 GHz band.

Clients Freq Distribution| Category | Percentage (%) | | :--- | :--- | | 5 GHz | 71.43 | | 2.4 GHz | 28.57 | 7 TOTAL

■ Clients Association Activities

The Clients Association Activities widget displays how the number of client connected to EAPs changes over time and the duration during which the clients communicate with the EAPs. In the stacked chart, you can easily compare the total number of clients and analyze the variation of each time period.

The total value of a column shows the total number of clients connected to EAPs in this time period, and the segments in four colors represent the client number of different durations in specific time.

| Time Period | 0-1s | 1-3s | 3-12s | >12s | | --------------------- | ---- | ---- | ----- | ---- | | 2021-03-15 04:05 pm | 13 | 0 | 0 | 0 | | 2021-03-15 07:10 pm | 12 | 0 | 0 | 0 | | 2021-03-15 09:45 pm | 6 | 0 | 0 | 0 | | 2021-03-16 02:09 am | 6 | 0 | 0 | 0 | | 2021-03-16 05:08 am | 0 | 0 | 0 | 0…

■ Client Activities

The Client Activities widget displays how the number of connected clients changes over time within the selected time range. In the stacked chart, you can easily compare the total number of clients and analyze the variation for each time period.

The total value of a column shows the total number of connected clients in that time period, and the segments in three colors show the change in client count compared with the previous time period.

Blue represents newly connected clients, orange represents clients that were already connected in the previous period, and gray represents newly disconnected clients.

| Date | New | Existing | Disconnected | | ---------- | --- | -------- | ------------ | | 2020-06-02 12:05 am | 1 | 1 | 0 | | 2020-06-02 01:10 am | 4 | 3 | 1 | | 2020-06-02 02:35 am | 5 | 4 | 1 | | 2020-06-02 03:30 am | 3 | 2 | 1 | | 2020-06-02 04:25 am | 7 | 3 | 1 | | 2020-06-02 05:30 am | 3 | 2 |…

■ Association Failures

The Association Failures widget lists three failure types and the number of times clients failed to connect to the EAPs' networks in the site. A bar next to the count shows the proportion of the three failure reasons using shades of gray, from dark to light. Click a reason in the list to view the distribution of failures across EAPs.

Association Failures3 Type Count • Association Timeout 0 • Blocked by Access Control ⓘ 0 • WPA Authentication Timeout/Failure 3

B0-95-75-E6-47-E2

Association Timeout: The connection failed because of a session timeout.

Blocked by Access ControlThe connection failed because the client has been blocked. For details about blocked clients, refer to 8.4.1 Known Clients.
WPA Authentication Timeout/FailureThe connection failed because the client did not pass the authentication due to authentication timeout or wrong password.

■ Clients SSID Distribution

The SSID Distribution widget uses a sunburst chart to display the distribution of wireless clients connected to the different SSIDs in the site. The chart has two levels. The inner circle is divided by the SSID that the clients connected to, and the outer circle is divided by the frequency band. You can hover

the cursor over a slice to view the number of clients connected to the SSID in the 2.4 GHz or 5 GHz band. Click a specific SSID to further display the statistics of its band frequency distribution.

Clients SSID Distribution| Category | Value | |---|---| | 5GHz | 5 | | 145Hz | 145 | | 2.4GHz | 2.4 | | EAP62D | EAP62D | | PE WIFI | PE WIFI |

■ Clients with on Boarding Times

The Clients with on Boarding Times widget describes the time wireless clients take when connecting to a certain SSID. The donut chart on the left shows the proportion of clients that take less than 10 seconds to connect to the devices. The line graph on the right displays the number of clients according to the different times that clients take to connect to the SSIDs.

Clients with onboarding times < 10s

≥ 10s Threshold

| Time (seconds) | Percentage (%) | | :--- | :--- | | 0 | 100.00 | | 1 | 100.00 |

| Category | Value | |---|---| | < 2 | 180 | | 2-4 | 0 | | 4-6 | 0 | | 6-8 | 0 | | 8-10 | 0 | | ≥ 10 | 0 | | Failure | 0 |

■ Clients with RSSI

The Clients with RSSI widget describes the RSSI (Received Signal Strength Indication) that wireless clients experience in the environment. RSSI is a negative value measuring the power level being received after any possible loss at the antenna and cable level. The higher the RSSI value, the stronger the signal. The donut chart on the left shows the proportion of clients whose RSSI value

is bigger than -72 dBm. The line graph on the right displays the number of clients according to the different range values of RSSI.

Clients with RSSI > -72 dBm| Category | Value (%) | |---|---| | RSSI (dBm) | 71.43 |

□≤72dBm Threshold

| Range | Frequency | |---|---| | ≤ -72 | 1.9 | | -71 to -65 | 0 | | -65 to -55 | 0 | | -55 to -45 | 2.9 | | ≥ -45 | 1.9 |

8.2 View the Statistics of the Network

Statistics provides a visual representation of device data in Omada SDN Controller. You can easily monitor the network traffic and performance under the following tabs, Performance, Switch Statistics, and Speed Test Statistics.

8.2.1 Performance

In Performance, you can view the device performance in a specified period by graphs, such as user counts, CPU and memory usage, and transmitted and received packets. The graphs vary due to the device type and status.

Tab Bar

The tabs and calendar on the top are used to specify the displayed statistics, and the legends on the right account for elements in the graphs.

B0-95-75-E6-47-E2 Jul 01, 2020 - Jul 02, 2020 Hourly WAN WAN/LAN1 WAN/LAN2 WAN/LAN3 LAN1 B0-95-75-E6-47-E2 > click to select a device from the drop-down list to view its statistics. The tabs vary due to the type of the selected device. Click the date to display a calendar. Click a specific date twic…

Statistical Graphs

Statistical graphs vary according to the type of devices. The chart below shows the statistical graphs which correspond to the gateway, switch, and AP.

Gateway User Counts, Usage, Traffic, Packets

Switch User counts, Usage

AP User Counts, Usage, Traffic, Packets, Dropped, Errors, Retries

■ User Counts

The User Counts graph displays the number of users connected to the devices during the selected time range. Hover the cursor over the line to display the specific values.

| Date | User Counts | | ---------- | ----------- | | Jul 06, 2020 | 1 |

■ Usage

The Usage graph uses the orange line and yellow line to display the percentage of CPU usage and used memory during the selected time range, respectively. Hover the cursor over the lines to display the specific values.

| Date | CPU | Memory | | ---------- | ----- | ------ | | Jul 06, 2020 18:15 | 5.20% | 36.20% |

Traffic

The Traffic graph uses the dark blue line and light blue line to display the bytes of data transmitted and received during the selected time range, respectively. Hover the cursor over the lines to display the specific values.

| Date | Received (MBytes) | Transmitted (Kbps) | | ---------- | ----------------- | ------------------ | | Jul 06, 2020 | 905.88 | 178.77 |

■ Packets

The Packets graph uses the dark blue line and light blue line to display the number of packets transmitted and received during the selected time range, respectively. Hover the cursor over the lines to display the specific values.

| Date | Packets | | ---------- | ------- | | Jul 06, 2020 | 137003 |

■ Dropped

The Dropped graph uses the dark blue line and light blue line to display the number of dropped Tx packets and Rx packets during the selected time range, respectively. Hover the cursor over the lines to display the specific values.

| Date | Tx Dropped Pits | Rx Dropped Pits | | ---------- | ---------------- | ---------------- | | Jul 02, 2020 | 392 | 114 |

Errors

The Errors graph uses the dark blue line and light blue line to display the number of error packets sent to AP and received by AP during the selected time range, respectively. Hover the cursor over the line to display the specific values.

| Date | Tx Errors | & Errors | | ---------- | --------- | --------- | | Jun 24, 2020 | 648 | 316 |

Retries

The Retries graph uses the dark blue line and light blue line to display the number of times that the data packets are transmitted again and received again during the selected period, respectively. Hover the cursor over the lines to display the specific values.

| Date | Tx Retriebs | Rx Retriebs | | ---------- | ----------- | ----------- | | Jul 01, 00:15 | 0 | 0 | | Jul 01, 04:15 | 0 | 0 | | Jul 01, 08:15 | 0 | 0 | | Jul 01, 13:15 | 4,376 | 874 | | Jul 01, 16:15 | 0 | 0 | | Jul 01, 20:15 | 0 | 0 | | Jul 02, 00:15 | 4,376 | 0 | | Jul 02, 04:15 | 0 | 0 | |…

8.2.2 Switch Statistics

In Switch Statistics, you can view the current status of ports and their traffic statistics of the selected switch in the specified time range via a monitor panel and graphs.

Tab Bar

The tabs and calendar on the top are used to specify the displayed statistics, and the legends on the right account for elements in the graphs.

switchClick to select a switch from the drop-down list to view its statistics.
Jul 06, 2020 - Jul 07, 2020Click the date to display a calendar. Click a specific date twice in the calendar for the widgets to display its statistics. To display the statistic of a time range, click the start date and end date in the calendar, or directly select the time range on the right.The available time range is restricted by the time interval. Before selecting a long time range, select Hourly or Daily as the time interval.
HourlySelect 5 minutes, Hourly, or Daily to specify the time interval of the data. When selecting a long time range, a longer time interval is recommended for a better view.
Sort: NaturalSelect Natural, Transmitted, Received, or All to specify the graph order of ports.Natural: Displays the line graphs in ascending order of the port number.Transmitted: Displays the line graphs in descending order based on the traffic volume of transmitted packets.Received: Displays the line graphs in descending order based on the traffic volume of received packets.All: Displays the line graphs in descending order based on the total traffic volume of transmitted and received packets.
bpsBytesPacketsSelect bps, Bytes or Packets to specify the data type and measuring unit. bps: Displays the traffic rate in bps. Bytes: Displays the traffic statistics in Bytes. Packets: Displays the total number of packets.
If you select Packet, click the tab to specify which type of packet statistics to be displayed. All: Displays statistics of all packets, including broadcast and multicast packets. Broadcast: Displays statistics of broadcast packets only. Multicast: Displays statistics of multicast packets only.

Monitor Panel

The monitor panel below the tab bar displays the current status of the ports on the selected switch.

| Category | Value | |---|---| | 1 | 2 | | 2 | 1 | | 3 | 4 | | 5 | 6 | | 7 | 8 | | 9 | 10 | Legend: Light gray = Disabled; Black = Disconnected; Green = 1000 Mbps; Orange = 10/100 Mbps; Light green = Uplink; White = Mirroring; Black = STP Blocking.

DisabledThe port profile is Disable. To enable it, refer to 6.3 Configure and Monitor Switches.
Disconnected The port is enabled but connects to no devices or clients.
1000 Mbps The port is running at 1000 Mbps.
10/100 Mbps The port is running at 10/100 Mbps.
PoEA PoE port connected to a powered device (PD).
UplinkAn uplink port connected to WAN.
MirroringA mirroring port that is mirroring another switch port.
STP BlockingA port in the Blocking status in Spanning Tree. It receives and sends BPDU (Bridge Protocal Data Unit) packets to maintain the spanning tree. Other packets are dropped.

Statistical Graphs

Statistical graphs below the monitor panel display the traffic statistics of active ports.

You can specify the data type and measuring unit by clicking the tab. The dark blue and light blue are used to indicate the transmitted and received statistics, respectively. Hover the cursor over the lines to display the specific values. To view and configure the device connected to the port, click the device name beside the port number.

| Time | Transmitted (bps) | Received (Bytes/s) | | ---------------- | ----------------- | ------------------ | | Jun 30, 00:15 | ~5555 | ~1111 | | Jun 30, 14:15 | ~5555 | ~1111 | | Jul 01, 04:15 | ~3333 | ~1111 | | Jul 01, 18:15 | ~3333 | ~1111 | | Jul 02, 08:15 | ~3333 | ~1111 | | Jul 02, 23:15 |…

8.2.3 Speed Test Statistics

Speed Test Statistics displays the results of the periodic speed test running on WAN ports, including the network latency and speed. To enable the speed test, go to Settings > Sites, enable Periodic Speed Test in Service, and specify the test interval. For details, refer to 4.2.2 Services.

Tab Bar

The tab and calendar on the top are used to specify the displayed statistics, and the legends on the right account for elements in the graphs.

TP-LINK Omada OC200 - Tab Bar - 1

Click the date to display a calendar. Click a specific date twice in the calendar for the widgets to display its statistics. To display the statistic of a time range, click the start date and end date in the calendar, or directly select the time range on the right.

TP-LINK Omada OC200 - Tab Bar - 2

Select the port you want to view the latency and speed.

Statistical Graphs

Statistical graphs below the tab bar display the network latency and speed of the WAN port.

Latency

The Latency graph displays the time that it takes for a packet to travel from the gateway to the service provider's gateway.

| Date | Latency (ms/sec) | | ---------- | ---------------- | | Jul 05, 2020 | 7 | | Jul 05, 2020 | 16 | | Jul 05, 2020 | 7 | | Jul 05, 2020 | 7 |

Speed

The Speed graph uses the blue line and green line to display the upload and download speed of the WAN port, respectively.

| Date | Download | Upload | | ---------- | -------- | ------ | | Jul 04, 2020 | 89 Mbps | 33 Mbps |

8.3 Monitor the Network with Map

In the Map section, you can look over the topology and device provisioning of network in Topology, and customizes a visual representation of your network in Map.

8.3.1 Topology

Go to Map > Topology, and you can view the topology generated by the controller automatically. You can click the icon of devices to open the Properties window. For detailed configuration and monitoring in the Properties window, refer to 6 Configure and Monitor Omada Managed Devices.

graph TD A["Internet Connected"] --> B["TL-ER7206 WAN 1"] B --> C["TL-SG2210MP"] B --> D["TL-SG2428P"] B --> E["TL-SG2428P"] C --> F["EAP660 HD\n6 Ingl. 40 (ac)"] D --> G["EAP620 HD\n6 Ingl. 40 (ac)"] E --> H["OC200"] E --> I["Client Group"] E --> J["EAP225\n6 Ingl. 40 (ac)"]

For a better overview of the network topology, you can control the display of branches, the size of the diagram, and the link labels.

graph TD A["Internet Connected"] --> B["1000 FDX"] B --> C["TL-ER7206 WAN 1"] C --> D["TL-SG2210MP"] C --> E["TL-SG2428P"] C --> F["TL-SG2428P"] D --> G["EAP660 HD 6 (ng), 40 (ac)"] E --> H["EAP620 HD 6 (ng), 40 (ac)"] F --> I["OC200"] F --> J["Client Group"] F --> K["EAP225 6 (ng), 40 (ac)"] D -->…

■ Display of Branches

The default view shows the all devices connected by solid and dotted lines. Click the icon of the client group to view clients connected to the same device. Click the nods + to unfold or ⓣ to fold the branches.

■ Diagram Size

Click the icons at the right corner to adjust the size of the topology and view the legends.

Click to fit the topology to the web page.
Click to zoom in the topology.
Click to zoom out the topology.
Click to view the meaning of lines in the topology. Solid and dotted lines are used to indicate wired and wireless connections, respectively, and four colors are used to indicate the link speed.

Click Link Labels at the left corner, and labels will appear to display the link status. Information on the labels varies due to the link connections.

TP-LINK Omada OC200 - Link Labels - 1(For the WAN port of router connected to the internet) Displays the port name, link speed and duplex type.
TP-LINK Omada OC200 - Link Labels - 2(For simple wired connections) Displays the link speed, duplex type, and connected port number. Note that only the switch's port number can be displayed in the label.
TP-LINK Omada OC200 - Link Labels - 3(For Link Aggregation) Displays the LAG speed, duplex type, LAG ID, and the port number of LAG members.
TP-LINK Omada OC200 - Link Labels - 4(For wireless connections between APs) Displays the RSSI (displayed in percentage and dBm) and the negotiation rate of uplink and downlink.
TP-LINK Omada OC200 - Link Labels - 5(For wireless connections between APs and clients) Displays the wireless channel of AP, connected SSID, and its signal strength.

8.3.2 Map

Go to Map >Map, and a default map is shown as below with the unplaced devices listed on the left. You can upload your local map images and drag in the devices to customize a visual representation of your network.

Topology Map Map: Default Show Device Name Devices CC-32-E5-A4-B1-AC CC-32-E5-69-B5-B0 B0-95-75-E6-48-C2 D8-47-32-1B-88-E6

■ Customize Map

Click the following icons to add, edit, and select the map. After selecting a map, click and drag in the devices from the Devices list to place it on the map according to the actual locations.

Click to add a map. In the pop-up window, enter the description and upload an image in the .jpg, .jpeg, .gif, .png, .bmp, .tiff format.
Click to edit maps in the pop-up window.Clickto edit the description of the map.Clickto delete the map.
Click to show the name of the devices on the map.
Map: TP-LinkClick to select a map from the drop-down list to place the devices.

Hover your cursor over the device icon to view the basic information of it, including the device name, MAC address, IP address and connected clients.

Name:CC-32-E5-69-B5-B0
MAC Address:CC-32-E5-69-B5-B0
IP Address:192.168.0.135
Users:3
Guests:0

You can click the device icon to reveal additional action icons:

Indicates that the device is unlocked and you can click it to lock the device in the current location. When unlocked, you can move the device on the map and click the action icons around it.
Indicates that the device is locked on the map and you can only click the icon to unlock the device.
Displays the device's Properties window. For detailed configuration and monitor in the Properties window, refer to6 Configure and Monitor Omada Managed Devices.
Click to remove the selected device back into the Device list.
(Only for connected switches and APs) Click to flash the LED of the device on the map. Then the LED will flash for 10 minutes or until the cancel button is clicked again.
Click to stop the LED from flashing.

■ Diagram Size

Click the icons at the right corner to adjust the size of the topology and view the legends.

TP-LINK Omada OC200 - ■ Diagram Size - 1

Click to fit the map to the web page.

TP-LINK Omada OC200 - ■ Diagram Size - 2

Click to zoom in the map.

TP-LINK Omada OC200 - ■ Diagram Size - 3

Click to zoom out the map.

8.4 View the Statistics During Specified Period with Insight

In the Insight page, you can monitor the site history of connected clients, portal authorizations, and rogue APs. For better monitoring, you can specify the time period and classify the clients and APs.

8.4.1 Known Clients

In Known Clients, a table lists all clients that have connected to the network before in the site.

In the table, you can view the client's basic information, role, and connection statistics, including download and upload traffic, connection duration, and the last time it connected to the network.

Search Name or MAC Address. Start date - End date. All Wireless Wired All Users Guests All Rate Limited Blocked. Columns: NAME, MAC ADDRESS, USER/GUEST, DOWNLOAD, UPLOAD, DURATION, LAST SEEN, ACTION. Rows: 00-BE-3B-A5-CC-0F, 00-BE-3B-A5-CC-0F, User, 0 Bytes, 0 Bytes, 7m 25s, Jun 06, 2020. 04-D3-B5-2…

A search bar, a time selector, and three tabs are above the table for searching and filtering.

Search Name or MAC Address: Enter the client name or MAC address to search the clients. Start date - End date: Filter the clients based on Last Seen. Click the selector to open the calendar. Click a specific date twice in the calendar to display the records on the day. To display the records of a ti…

All Wireless Wired

All Users Guests

All Rate Limited Blocked

Click the tabs to filter the clients listed in the table. The three tabs can take effect simultaneously.

All/Wireless/Wired: Click All to display both wireless and wired clients. Click Wireless or Wired to display wireless or wired clients only.

All/Users/Guests: Click All to display both users and guests. Click Users or Guests to display users or guests only. Guests are users connected to the wireless guest network. To configure the guest network, refer to 4.4 Configure Wireless Networks.

All/Rate Limited/Blocked: Click All to display both rate-limited and blocked clients. Click Rate Limited or Blocked to display rate-limited or blocked clients only. To configure Rate Limit, refer to 4.8.3 Rate Limit. To block clients, click the 🔒 icon in the table.

You can also take actions to block or forget the client. For detailed monitoring and management, click the entry in the table to open the Properties window of the client. For more details, refer to 7.1.2 Using the Clients Table to Monitor and Manage the Clients.

(For unblocked clients) Click to block the client in the site. Once blocked, the client is banned from connecting to the network in the site.
(For blocked clients) Click to unblock the client in the site.
Click to forget the client. Once forget, all statistics and history of the client in the site are dropped.

8.4.2 Past Connections

In Past Connections, a table displays information about previous client connection sessions.

In the table, you can view the client's name, MAC address, association time and duration, download and upload traffic, IP address, and the network/port it connected to.

Known Clients Past Connections Past Portal Authorizations Rogue APs. Search Name, SSIO, or MAC Address Q Start date - End date Association Success (37) Association Failure (0) All (37) Users (37) Guests (0). Columns: NAME, MAC ADDRESS, USER/GUEST, ASSOCIATION TIME, ASSOCIATED, DOWNLOAD, UPLOAD, DURA…

A search bar and a time selector are above the table for searching and filtering.

Search Name, SSID, or MAC Address: Enter the client name, SSID or MAC address to search the clients. Start date - End date: Filter the clients based on Start Time. Click the selector to open the calendar. Click a specific date twice in the calendar to display client connection sessions on the day. T…

8.4.3 Past Portal Authorizations

In Past Portal Authorization, a table lists all clients that passed the portal authorization before.

In the table, you can view the client's name, MAC address, authorization credential, uplink and downlink traffics, authorization time and duration, IP address, and the network/port it connected to. For detailed monitoring and management, refer to 7.2 Manage Client Authentication in Hotspot Manager.

Search Name or MAC Address Start date - End date NAME MAC ADDRESS AUTHORIZED BY START TIME DOWNLOAD UPLOAD DURATION IP ADDRESS AP/PORT DESKTOP-G2N0C3C F8-63-3F-A8-F7-96 Local User - tplink May 29, 2020 02:28:55 pm 2.1 MB 449.2 KB 1m 25s 192.168.0.27 EAP225(Hotel) DESKTOP-G2N0C3C F8-63-3F-A8-F7-96 Lo…

A search bar and a time selector are above the table for searching and filtering.

Search Name or MAC Address

Start date - End date

Enter the client name or MAC address to search the clients.

Filter the clients based on Start Time.

Click the selector to open the calendar. Click a specific date twice in the calendar to display the clients authorized on the day. To display the clients authorized during a time range, click the start date and end date in the calendar.

8.4.4 Switch Status

In Switch Status, a table displays information about the status of the switches managed by the controller. In the table, you can view the ports, PoE status, mode, and traffic activity of the switches.

Search Switch or Name Overview POE Counters All Connected Disconnected PORT SWITCH NAME POE MODE PROFILE LINK STATUS STP TX SUM RX SUM TX THROUGHPUT RX THROUGHPUT ACTION 15 E4-C3-3A-57-71-AC Port15 0.5W switching All 1000M Full Forwarding 6.75 GB 1.12 GB 876 bps 336 bps 16 E4-C3-3A-57-71-AC Port16 -…

A search bar and two tabs are above the table for searching and filtering. You can also click the icons in the Action column for quick operation.

Search Switch or NameEnter the switch or name to search.
Overview PoE CountersAll Connected DisconnectedClick the tabs to filter the switch ports listed in the table. The two tabs can take effect simultaneously.Overview/PoE/Counters: Click Overview to display the general status of each port. Click PoE to display the PoE configurations and status of each port. Click Counters to display TX and RX rates for each port.All/Connected/Disconnected: Filter the ports by their link status. Click All to display information of all ports. Click Connected or Disconnected to display all connected or disconnected ports.
Click to edit the configurations of the port.
(Only for the PoE port that is connected to a PD) Click the button and the port will stop to supply power to the connected PD momentarily in order to reboot the PD.

The listed information when you select Overview on the first tab is explained as follows.

Port: Displays the port number and status of the port.

10/100 Mbps: The port is running at 10/100 Mbps.

1000 Mbps: The port is running at 1000 Mbps.

2.5 Gbps: The port is running at 2.5 Gbps.

10 Gbps: The port is running at 10 Gbps.

Disabled: The port is disabled.

Disconnected: The port is enabled but not connected to any devices or clients.

PoE: The PoE port is connected to a powered device (PD).

Uplink: The port is an uplink port connected to the WAN.

Mirroring: The port is a mirroring port that mirrors another switch port.

STP Blocking: The port is in the Blocking state in Spanning Tree. It receives and sends BPDU (Bridge Protocol Data Unit) packets to maintain the spanning tree. Other packets are dropped.

Switch: Displays the MAC address or the alias of the switch.

Name: Displays the name of the port.

PoE: Displays the PoE status of the port.

--: PoE is disabled.

W: Display the power output of the port in watts.

Mode: Display the operation mode of the port.

Switching: The default mode.

Mirroring: The network traffic of this port will receive the mirrored traffic from its mirrored port.

Aggregating: The port is a part of an aggregate link.

Profile: Display the switch port profile that takes effect on the port.

Link Status: Display the connection speed and duplex mode of the port.

STP: Display the Spanning Tree Protocol (STP) mode.

TX Sum: Display the amount of transmitted data.

RX Sum: Display the amount of received data.

TX Throughput: Display the transmit throughput rate.

RX Throughput: Display the receive throughput rate.

The listed information when you select PoE on the first tab is explained as follows.

Port: Display the port number and status of the port.

10/100 Mbps: The port is running at 10/100 Mbps.

1000 Mbps: The port is running at 1000 Mbps.

2.5 Gbps: The port is running at 2.5 Gbps.

10 Gbps: The port is running at 10 Gbps.

Disabled: The port is disabled.

Disconnected: The port is enabled but connects to no devices or clients.

PoE: The PoE port is connected to a powered device (PD).

Uplink: The port is an uplink port connected to WAN.

Mirroring: The port is a mirroring port that is mirroring another switch port.

STP Blocking: The port is in the Blocking status in Spanning Tree. It receives and sends BPDU (Bridge Protocol Data Unit) packets to maintain the spanning tree. Other packets are dropped.

Switch: Displays the MAC address or the alias of the switch.

Name: Displays the name of the port.

PoE: Displays the PoE status of the port.

--: PoE is disabled.

_W: Displays the power output of the port in watts.

PD Class: Displays the power requirement of the PD connected to the PoE port.

Power: Displays the power output of the port in watts.

Voltage: Displays the voltage output in volts.

Current: Displays the current output in amperes.

The following information is displayed when you select Counters on the first tab.

Port: Displays the port number and status of the port.

10/100 Mbps: The port is running at 10/100 Mbps.

1000 Mbps: The port is running at 1000 Mbps.

2.5 Gbps: The port is running at 2.5 Gbps.

10 Gbps: The port is running at 10 Gbps.

Disabled: The port is disabled.

Disconnected: The port is enabled but not connected to any devices or clients.

PoE: The PoE port is connected to a powered device (PD).

Uplink: The port is an uplink port connected to the WAN.

Mirroring: The port is a mirroring port that mirrors another switch port.

STP Blocking: The port is in the Blocking state in Spanning Tree. It receives and sends BPDU (Bridge Protocol Data Unit) packets to maintain the spanning tree. Other packets are dropped.

Switch: Displays the MAC address or the alias of the switch.

TX Bytes: Displays the number of transmitted bytes.

TX Frames: Displays the number of transmitted frames.

TX Multicast: Displays the number of transmitted multicast packets.

TX Broadcast: Displays the number of transmitted broadcast packets.

TX Errors: Displays the number of transmitted error packets.

RX Bytes: Displays the number of received bytes.

RX Frames: Displays the number of received frames.

RX Multicast: Displays the number of received multicast packets.

RX Broadcast: Displays the number of received broadcast packets.

RX Errors: Displays the number of received error packets.

8.4.5 Port Forwarding Status

In Port Forwarding Status, a table displays information about the port forwarding entries used by the gateway managed by the controller.

User Defined UPHP NAME INTERFACE SOURCE IP SOURCE PORT DESTINATION IP DESTINATION PORT PROTOCOL PACKETS BYTES ACTION Lib 172.31.53.2624 8043 192.168.0.16 8043 TCP&UDP 0 0 Bytes TexA 0.0.0.06 443 192.168.0.22 443 UDP 0 0 Bytes TextB 10.0.0.16/24 8080 192.168.0.16 8080 TCP 0 0 Bytes Showing 1-3 of 3 r…

A tab is above the table for filtering. You can also click the icons in the Action column for quick operations.

TP-LINK Omada OC200 - Port Forwarding Status - 2

Click the tab to filter the port forwarding entries listed in the table.

User-defined/UPnP: Click User Defined to display the port forwarding entries created by the user. Click UPnP to display the UPnP port forwarding entries.

TP-LINK Omada OC200 - Port Forwarding Status - 3

Click to edit the configurations of the port forwarding entry.

The listed information is explained as follows.

Name: Display the name of the port forwarding entry.

Interface: Display the WANs used by the port forwarding entry.

Source IP (Only for user-defined entries): Display the source IP address.

A specific IP address/Mask: The specified source IP address.

0.0.0.0/0: All IP addresses are set as the source IP address.

Source Port: The traffic through the source port, also known as internal port, will be forwarded to the LAN.

Destination IP: Display the destination IP address, and it will receive the forwarded port traffic.

Destination Port: Display the destination port, also known as internal port, that will receive the forwarded traffic.

Protocol: Display the protocol that will be forwarded.

Packets: Display the number of transferred packets.

Bytes: Display the number of transferred bytes.

Lease Duration

(Only for UPnP port forwarding) Display the uptime of the port forwarding entry.

8.4.6 VPN Status

In VPN Status, a table displays the existing VPN tunnels and corresponding information.

IPsec SAVPN Tunnel
NAMESPIDIRECTIONTUNNEL IDDATA FLOWPROTOCOLAH AUTHENTI CATIONESP AUTHENTI CATIONESP ENCRYPTI ONACTION
|psec_tunne3331307731in100.64.111.102100.64.111.103192.168.0 101/32192.168.1 101/32ESP--SHA1AES-256
|psec_tunne3258204075out100.64.111.102100.64.111.103192.168.0 101/32192.168.1 101/32ESP--SHA1AES-256
--3397724945in172.16.100.102172.16.100.103172.16.100.102/32[udp/12f]172.16.100.103/32[udp/12f]ESP--SHA13DES
--3326915047out172.16.100.102172.16.100.103172.16.100.102/32[udp/12f]172.16.100.103/32[udp/12f]ESP--SHA13DES
Showing 1-4 of 4 records<1>25 /pageGo To page:GO

A tab is above the table for filtering. You can also click the icons for quick operation.

IPsec SAVPN TunnelClick the tab to filter the routing information listed in the table.IPsec SA/VPN Tunnel: Click to display. When you select VPN Tunnel, you can further choose Server or Client.
(Only for VPN Tunnel) Filter the entries.
(Only for IPsec SA) Click to configure the entry.
(Only for VPN Tunnel) Click to terminate the VPN tunnel.
(Only for VPN Tunnel) Click to choose more listed information to be displayed in the table.

The listed information of IPsec SA table is explained as follows.

Name: Display the name of the IPsec SA entry.

SPI: Display the Security Parameter Index of SA.

Direction: Display the direction of the SA process.

Tunnel ID

Display the local and remote IP address/name. The arrow indicates the traffic direction.

Data Flow: Display local and remote subnet. The arrow indicates the direction.

Protocol: Display the authentication and encryption protocol of the entry.

AH Authentication: Display checksum algorithms of the entry.

ESP Authentication: Display the algorithms for ESP authentication.

ESP Encryption: Display the algorithms for ESP encryption.

IPsec SAVPN TunnelServerClient
USERINTERFACETYPELOCAL IPREMOTE LOCAL IPDNSUPTIMEACTION
f2tpSFP WANLZTP Server (Network Ext...172.31.237.1192.168.102.28.8.8.80d 0h 5m
pptpWAN/LAN1PPTP Server (Network Ext...172.31.94.2192.168.103.48.6.8.80d 0h 2m
Showing 1-2 of 2 records< 1 >25 /page Go To page: GO

The listed information of VPN Tunnel (Server) table is explained as follows (some information listed below is hidden by default). You can further filter the entries based on their type.

User: Displays the username of the remote user.

Interface: Displays the interface that the traffic goes through.

Type: Displays the connection type.

Local IP: Displays the local IP address of the VPN tunnel.

Remote Local IP: Displays the IP address of the remote user of the VPN tunnel.

DNS: Displays the DNS address of the VPN tunnel.

Download Pkts: Displays the amount of data downloaded as packets.

Download Bytes: Displays the amount of data downloaded as bytes.

Upload Pkts: Displays the amount of data uploaded as packets.

Display the amount of data uploaded as bytes.

Upload Bytes: Displays the amount of data uploaded as bytes.

Display the amount of data uploaded as bytes.

Uptime: Displays the time duration that the VPN tunnel has been active.

IPsec SA VPN Tunnel Server Client INTERFACE TYPE REMOTE LOCAL IP DNS UPTIME ACTION SFP WAN L2TP Client 172.31.237.1 8.8.8.8 Dd Oh 9m WAN/LAN1 PPTP Client 172.31.94.2 8.8.8.8 Dd Oh 6m WAN/LAN2 OpenVPN Client 192.168.104.5 8.8.8.8 Showing 1-3 of 3 records < 1 > 25/page Go To page: GO

The listed information of VPN Tunnel (Client) table is explained as follows (some information listed below is hidden by default). You can further filter the entries based on their type.

User: Displays the username of the remote user.

Interface: Displays the interface that the traffic goes through.

Type: Displays the connection type.

Remote Local IP: Displays the IP address of the remote user of the VPN tunnel.

DNS: Displays the DNS address of the VPN tunnel.

Download Pkts: Displays the amount of data downloaded as packets.

Download Bytes: Displays the amount of data downloaded as bytes.

Upload Pkts: Displays the amount of data uploaded as packets.

Upload Bytes: Displays the amount of data uploaded as bytes.

Uptime: Displays the time duration that the VPN tunnel has been active.

8.4.7 Routing Table

Routing Table displays information of routing entries that have taken effect.

Gateway Switch ID DESTINATION IP/SUBNETS NEXT HOP INTERFACE METRIC 1 0.0.0.0 10.0.0.1 WAN1 0 2 10.0.0/22 0.0.0.0 WAN1 0 3 10.0.0.1 0.0.0.0 WAN1 0 4 127.0.0/8 0.0.0.0 Io 0 5 10.10.10.0/24 0.0.0.0 LAN329457056 0 6 192.168.0.0/24 0.0.0.0 LAN1 0 Showing 1-6 of 6 records < 1 > 25 /page Go To page: GO

Gateway Switch NAME DESTINATION IP/SUBNETS NEXT HOP DISTANCE ACTION E1-C3-2A-S7-71-AC 0.0.0.00 192.168.0.1 254 E1-C3-2A-S7-/1-AC 192.168.0.0/24 192.168.0.11 0 Showing 1-2 of 2 records < 1 > 25 page Go To page: GO

A tab is above the table for filtering. You can also click the icons in the Action column for quick operation.

TP-LINK Omada OC200 - Routing Table - 3

Click the tab to filter the routing information listed in the table.

Gateway/Switch: Click to display the routing information of the gateway or the switch.

TP-LINK Omada OC200 - Routing Table - 4

(Only for switch) Click to configure the static routes.

The listed information is explained as follows.

Destination IP/Subnets: Display the destination IP addresses of the routing entry.

Next Hop: Display the IP address of the next hop.

Interface (Only for Gateway): Display the interface that the traffic of the entry goes through.

Metric (Only for Gateway): Display the number of hops before reaching the destination. Generally, if there are a few routing entries with the same destination, the routing with the lowest metric will be used.

Distance (Only for Switch): Display the administrative distance of the routing entry. It is used to decide the priority among routes to the same destination. Among routes to the same destination, the route with the lowest distance value will be used.

8.4.8 Dynamic DNS

In Dynamic DNS, a table displays information about the uses of the dynamic DNS services. You can click ☐ in the Action column to edit the entry.

Knows Clients Past Connections Past Portal Authorizations Switch Status Port Forwarding Status VPN Status Routing Table Dynamic OH3 Rigue APs SERVICE INTERFACE STATUS USERNAME DOMAIN NAME P LAST UPDATED ACTION DynONS WAN connecting AA www.ies1.com 10.0-3.53 Mar 16, 2021 12:34:40 pm NO IP WAN -- AA w…

Service: Display the name of the DDNS service.

Interface: Display the WANs used by the DDNS entry.

Status: Display the status of the latest DDNS update.

Username: Display the username of the DDNS account.

Domain Name: Display domain name registered with the DDNS service.

IP: Display the IP address of the domain name.

Last Updated: Displays the time when the IP address of the domain name was last updated.

8.4.9 Rogue APs

A rogue AP is an access point that has been installed on a secure network without explicit authorization from a system administrator. In Rogue APs, you can scan for rogue APs and view the rogue APs that were scanned before.

NAME/SSIDBSSIDCHANNELSECURITYBEACONLOCATIONSIGNALLAST SEEN
ChinaNet-gcvZ48-A7-4E-83-8B-C811 (11ng)WPA-Personal100Nearest B0-95-75-E6-48-C2100% (-14dBm)May 27, 2020 02.01:20 pm
yangxinxin200-0A-EB-13-7A-FF9 (11ng)WPA-Personal100Nearest B0-95-75-E6-48-C2100% (-15dBm)May 27, 2020 02.01:20 pm
mmmmmmmmmm54-A7-03-57-C4-E56 (11ng)WPA-Personal100Nearest B0-95-75-E6-48-C2100% (-34dBm)May 27, 2020 02.01:20 pm
Xiaomi_14CDEC-41-18-E6-14-CE1 (11ng)WPA-Personal100Nearest B0-95-75-E6-48-C2100% (-43dBm)May 27, 2020 02.01:20 pm
nxclly8C-AB-8E-99-76-B013 (11ng)WPA-Personal100Nearest B0-95-75-E6-48-C2100% (-50dBm)May 27, 2020 02.01:20 pm
midea_e2_20873C-2C-94-20-C9-526 (11ng)WPA-Personal100Nearest B0-95-75-E6-48-C298% (-51dBm)May 27, 2020 02.01:20 pm
ChinaNet-eGaN80-41-26-05-15-6410 (11ng)WPA-Personal100Nearest B0-95-75-E6-48-C283% (-57dBm)May 27, 2020 02.01:20 pm
ChinaNet-y7FkDC-A3-33-B0-C2-121 (11ng)WPA-Personal100Nearest B0-95-75-E6-48-C280% (-56dBm)May 27, 2020 02.01:20 pm
ChinaNet-azsL94-BF-80-88-33-C07 (11ng)WPA-Personal100Nearest B0-95-75-E6-48-C220% (-82dBm)May 27, 2020 02.01:20 pm
Search Name or MAC AddressEnter the client name or MAC address to search the clients.
Start date - End dateFilter the rogue APs based on Last Seen.Click the selector to open the calendar. Click a specific date twice in the calendar to display the rogue APs scanned on the day. To display the scanned AP during a time range, click the start date and end date in the calendar.
All 2.4G 5GClick the tab to filter the rogue APs listed in the table based on the frequency band.
ScanClick to scan rogue APs. It may take several minutes, and the wireless service may be influenced during scanning.
BSSID A string with a similar form as MAC address to recognize access points.
Channel Displays the operation channel and standard of the rogue AP.
Security Displays the security strategy of the rogue AP.
Beacon Displays the beacon interval of the rogue AP.
Beacons are transmitted periodically by the EAP to announce the presence of a wireless network for the clients, and the interval means how often the AP send a beacon to clients.
LocationDisplays the managed AP nearest to the rogue AP. You can click the nearest AP to open its Properties window.

Signal: Displays the signal strength in percentage and dBm.

Last Seen: Displays the last time that the rogue AP was scanned by the controller.

8.5 View and Manage Logs

The controller uses logs to record the activities of the system, devices, users, and administrators, which provides powerful support for monitoring operations and diagnosing anomalies. In the Logs page, you can conveniently monitor the logs in 8.5.1 Alerts and 8.5.2 Events, and configure their notification levels in 8.5.3 Notifications.

All logs can be classified from the following four aspects.

■ Occurred Hierarchies

Two categories in occurred hierarchies are Controller and Site, which indicate the log activities that happened, respectively, at the controller level and in a certain site. Only Master Administrators can view the logs that happened at the controller level.

- Notifications

Two categories in notifications are Event and Alert, and you can classify the logs into them by yourself.

■ Severities

Three levels in severities are Error, Warning, and Info, whose influences are ranked from high to low.

- Contents

Four types in contents are Operation, System, Device, and Client, which indicate the log contents relating to.

8.5.1 Alerts

Alerts are the logs that need to be noticed and archived specially. You can configure the logs as Alerts in Notifications, and all the logs configured as Alerts are listed under the Alerts tab for you to search, filter, and archive.

Alerts Events Notifications 32 Unarchived Alerts. Type, level or content. Unarchived Archived All Errors Warnings Info All Operation System Device Client. CONTENT TIME ARCHIVE ALL. EA-23-51-06-22-52 was isolated Nov 17, 2020 02:40:33 pm. [Failed] Failed to readopt EA-23-51-06-22-52 automatically. No…

Click to change the view mode for a better overview.
Displays the logs in a table.
//: Displays the logs in a day/week/month. To change the time, click or .To jump back to the current one, click Today/This Week/This Month.
Enter the content types, severity levels, or key words to search the logs.
Click the tabs to filter the logs listed in the table. The two tabs can take effect simultaneously.
Unarchived/Archived: Click the tab to filter the unarchived and archived logs. You can click and Archive All to archive a single log and all, respectively.
All/Errors/Warnings: Click All to display logs in both Error, Warning, and Info levels. Click Errors or Warnings to display logs in Error or Warning levels only.
ContentDisplays the log types and detailed message. You can click the device name, client name to open its Properties window for detailed information.

Time: Displays when the activity happened.

Archive All: Click to archive all unarchived logs.

TP-LINK Omada OC200 - Alerts - 2

TP-LINK Omada OC200 - Alerts - 3

Click to archive the log entry.

Click to delete all archived alerts. Once deleted, the archived alerts cannot be recovered. The unarchived alerts cannot be deleted.

8.5.2 Events

Events are the logs that can be viewed but have no notifications. You can configure the logs as Events in Notifications, and all the logs configured as Events are listed under the Events tab for you to search and filter.

Alerts Events Notifications. 32 Unarchived Alerts. Type, level or content All Errors Warnings Info All Operation System Device Client. CONTENT TIME. A8-57-00-00-00-07 is connected to 00-EA-DE-5B-E3-11 on LAN network. Nov 23, 2020 09:25 19 am. A8-57-00-00-00-07 was disconnected from network "LAN" on…

TP-LINK Omada OC200 - Events - 2

TP-LINK Omada OC200 - Events - 3

TP-LINK Omada OC200 - Events - 4

TP-LINK Omada OC200 - Events - 5

Click to change the view mode.

TP-LINK Omada OC200 - Events - 6

Displays the logs in a table.

TP-LINK Omada OC200 - Events - 7

17: Displays the logs in a day/week/month. To change the time, click . To jump back to the current one, click Today/This Week/This Month.

Type, level or content

TP-LINK Omada OC200 - Events - 8

Enter the content types, severity levels, or key words to search the logs.

TP-LINK Omada OC200 - Events - 9

TP-LINK Omada OC200 - Events - 10

TP-LINK Omada OC200 - Events - 11

Click to delete all Events logs.

Click the tabs to filter the logs listed in the table. The two tabs can take effect simultaneously.

All/Errors/Warnings/Info: Click All to display logs in both Error and Warning levels. Click Errors, Warnings or Info to display logs in the corresponding level only.

All/Operation/System/Device/Client: Click All to display all types of logs. Click Operation or System or Device or Client to display the corresponding type of logs only.

Content: Displays the log types and detailed message. You can click the device name or client name to open its Properties window for detailed information.

Time: Displays when the activity happened.

8.5.3 Notifications

In Notifications, you can find all kinds of activity logs classified by the content and specify their notification categories as Event and Alert for the current site. Also, you can enable Email for the logs. With proper configurations, the controller will send emails to the administrators when it records the logs.

Alerts Events Notifications Reset to Default Operation System Device Client Advanced Features Enabled ✓ Event □ Alert □ Email Management VLAN Changed ✓ Event □ Alert □ Email Voucher Created ✓ Event □ Alert □ Email Voucher Deleted ✓ Event □ Alert □ Email Rolling Upgrade Triggered ✓ Event □ Alert □ Em…

To specify the logs as Alert/Event, click the corresponding checkboxes of logs and click Apply. The following icons and tab are provided as auxiliaries.

Reset to DefaultClick to reset all notification configurations in the current site to the default.
OperationSystemDeviceClientClick the tabs to display the configurations of corresponding log types.
□ Event □ AlertEnable the checkboxes to specify the activity logs as Events/Alerts, and then the recorded logs will be displayed under the Events/Alerts tab. If both of them are disabled, the controller will not record the activity logs.
□ EmailEnable the checkboxes to specify the activity logs as alert logs. With proper settings in Site and Admin, the controller can send emails to notify the administrators and viewers of the site's alert logs once generated.
This icon appears when the configuration of a log is changed but has not been applied. Click it to reset the configuration of the log to the default.

The Email checkboxes are used to enable Alert Emails for the logs. To make sure the administrators and viewers can receive alert emails of the site, follow the following steps:

1) Enable Mail Server 2) Enable Alert Emails in Site 3) Enable Alert Emails in Admin 4) Enable Alert Emails in Logs

Enable Mail Server Enable Alert Emails in Site Enable Alert Emails in Admin

Go to Settings > Controller. In the Mail Server section, enable SMTP Server and configure the parameters. Then click Save.

Mail Server

With the Mail Server, the controller can send emails for resetting your password, pushing notifications, and delivering the system logs. For security reasons, we recommend that you configure Mail Server carefully.

SMTP Server:

Enable

SMTP:

example.url

Port:

25

(1-65535)

SSL:

Enable

Authentication:

Enable

Sender Address:

example@sender.address

(Optional)

Test SMTP Server:

Send Test Email to

example@tp-link.com

Send

SMTPEnter the URL or IP address of the SMTP server according to the instructions of the email service provider.
PortConfigure the port used by the SMTP server according to the instructions of the email service provider.
SSLEnable or disable SSL according to the instructions of the email service provider. SSL (Secure Sockets Layer) is used to create an encrypted link between the controller and the SMTP server.
AuthenticationEnable or disable Authentication according to the instructions of the email service provider. If Authentication is enabled, the SMTP server requires the username and password for authentication.
Username Enter the username for your email account if Authentication is enabled.
Password Enter the password for your email account if Authentication is enabled.
Sender Address (Optional) Specify the sender address of the email.
Test SMTP ServerTest the Mail Server configuration by sending a test email to an email address that you specify.

Enable Mail Server Enable Alert Emails in Site Enable Alert Emails in Admin

  1. Go to Settings > Site and enable Alert Emails in the Services section.

Services LED: ✓ Enable Automatic Upgrades: □ Enable Channel Limit: □ Enable i Mesh: ✓ Enable i Auto Failover: □ Enable i Connectivity Detection: Auto (Recommended) ✓ Full-Sector DFS: ✓ Enable i Periodic Speed Test: ✓ Enable Speed Test History Speed Test Interval: 20 hours (10-999) Alert Emails: ✓ En…

  1. (Optional) On the same page, enable Send similar alerts within seconds in one email and specify the time interval. When enabled, the similar alerts generated in each time period are collected and sent to administrators and viewers in one email.

Alert Emails: Enable alert emails ⓘ Send similar alerts within 60 seconds in one email. ⓘ

  1. Click Apply.

Go to Admin and configure Alert Emails for the administrators and viewers to receive the emails. Click + Add New Admin Account to create an account or click ☑ to edit an account. Enter the email address in Email and enable Alert Emails. Click Create or Apply.

Edit Account

Username:

Administrator

Change Password:

Enable

Role:

Administrator

Site Privileges:

All (Including all new-created sites)

Device Permissions:

○ Sites

√ Adopt Devices

√ Manage Devices (Move to Site, Restart, Upgrade and Forget)

Email:

example@tp-link.com

Alert Emails:

Enable i

Save

Cancel

Enable Alert Emails in Site Enable Alert Emails in Admin Enable Alert Emails in Logs

Go to Logs and click Notifications. Click a tab of content types and enable Email for the activity logs that the controller emails administrators. Click Save.

Alerts Events Notifications Reset to Default Operation System Device Client Reboot Schedule Executed Event Alert Email Reboot Schedule Execution Failed Event Alert Email PoE Schedule Executed Event Alert Email PoE Schedule Execution Failed Event Alert Email Logs Mailed Automatically Event Alert Emai…

⑨

Manage Administrator Accounts of Omada SDN Controller

This chapter gives an introduction to different user levels of administrator accounts and guides you on how to create and manage them in the Admin page. The chapter includes the following sections:

• 9.1 Introduction to User Accounts • 9.2 Manage and Create Local User Accounts • 9.3 Manage and Create Cloud User Accounts

9.1 Introduction to User Accounts

Omada SDN Controller offers three levels of access available for users: master administrator, administrator, and viewer. Because the controller can be accessed both locally and via cloud access, users can be further grouped into local users and cloud users. Multi-level administrative account presents a hierarchy of permissions for different levels of access to the controller as required. This approach ensures security and gives convenience for management.

■ Master Administrator

There is only one master administrator who has access to all features. The account who first launches the controller will be the master administrator and cannot be changed and deleted.

■ Administrator

Administrators can create and delete viewers in the Admin page, but they can be created and deleted only by master administrator. In the Settings page, administrators have no permission to some modules, including cloud access, migration, auto-backup, etc.

■ Viewer

Viewers can only view the status and settings of the network, and they cannot change the settings. The entrance to Admin page is hidden for viewers, and they can be created or deleted by the master administrator and administrator.

9.2 Manage and Create Local User Accounts

By default, Omada SDN Controller automatically sets up a local user with the role called master administrator as the primary administrator. The username and password of the master administrator are the same as that of the controller account by default. The master administrator cannot be deleted, and it can create, edit, and delete other levels of user accounts.

9.2.1 Edit the Master Administrator Account

To view basic information and edit the master administrator account, follow these steps:

  1. Go to Admin, click in the Action column. Enter the password and click Confirm (by default, the password of the master administrator is the same as the controller account).

Edit Account Enter your current password to make any changes to your account. Password: Confirm Cancel

  1. Basic information including role and device permissions is shown. You can change the password and enable alert emails by checking the box. Click Save.

Basic Information

Role:

Master Administrator

Device Permissions:

√ Allow Devices Adoption √ Allow Devices Manage (Move to Site, Restart, Upgrade and Forget)

Edit Account

Username:

tplink123456

Change Password:

TP-LINK Omada OC200 - Edit Account - 1

Enable

New Password:

TP-LINK Omada OC200 - Edit Account - 2

Confirm Password:

TP-LINK Omada OC200 - Edit Account - 3

Email:

Alert Emails:

TP-LINK Omada OC200 - Edit Account - 4

Enable

TP-LINK Omada OC200 - Edit Account - 5

Save

Cancel

9.2.2 Create and Manage Administrator and Viewer

To create and manage local user accounts, follow these steps:

  1. Click + Add New Admin Account.

USERNAME admin@tp-link.com admin ROLE Master Cloud Administrator master Administrator EMAIL admin@tp-link.com Showing 1-2 of 2 records < 1 > 10 /page Go To page: GO + Add New Admin Account

  1. Select Local User for the administrator type in the pop-out window. Specify the parameters and click Create.

Add New Admin Account Administrator Type: Local User Cloud User Cloud Access Required Username: Password: Role: Administrator Site Privileges: All (Including all new-created sites) Sites Please Select... Device Permissions: Adopt Devices Manage Devices (Move to Site, Restart, Upgrade and Forget) Ema…

Username: Specify the username. The username should be different from the existing ones.

Password: Specify the password.

Role: Select a role for the created user account.

Administrator: This role has permissions to adopt and/or manage devices of the sites chosen in the site privileges, edit itself, create/edit/delete viewer accounts in its privileged sites. However, it cannot delete itself or edit/delete master administrator and other administrator accounts.

Viewer: This role can view the information of the sites chosen in the site privileges. It can only edit itself.

Site Privileges Assign the site permissions to the created local user.
All: The created user has device permissions in all sites, including all new-created sites.
Sites: The created user has device permission in the sites that are selected. Select the sites by checking the box before them.
Device Permissions (when creating a local administrator)Grant following permission to the created user in the role of administrator by checking the box(es).
Adopt Devices: the created administrator account can view the devices in status of pending in the privileged sites, and the administrator account has permissions to adopt the devices.
Device Manage: the created administrator account can manage the devices in the privileged sites.
Email (optional) Enter an email address for receiving alert emails.
Alert EmailsCheck the box if you want the created user to receive emails about alerts of the privileged sites. For detailed configurations, refer to 4.2.2 Services.

To edit and delete the accounts, click the icons in the Action Column.

To edit the parameters for the user.
Master administrator can edit all user accounts, Administrator can edit itself and viewer accounts of its privileged sites, and viewer can only edit itself.
To delete the account.
Master administrator can delete all user accounts apart from itself, administrator can delete viewer accounts of its privileged sites, and viewer cannot delete any accounts.

9.3 Manage and Create Cloud User Accounts

For cloud-based controller, the cloud access is enabled by default, and the controller automatically sets up the cloud master administrator. Software and hardware controller automatically sets up the cloud master administrator if you have enabled cloud access and bound the controller account with a TP-Link ID in the quick setup. The username and password are the same as those of the TP-Link ID. The cloud master administrator cannot be deleted, and it can create, edit, and delete other levels of user accounts.

9.3.1 Set Up the Cloud Master Administrator

For software and hardware controller, if you have not enabled the cloud access and bound the controller with a TP-Link ID in quick setup, to set up the cloud master administrator, follow these steps:

  1. Go to Settings > Cloud Access to enable Cloud Access and bind your TP-Link ID.

Cloud Access Cloud Access: i Cloud Access Status: DISCONNECTED Owner Owner ID: admin@tp-link.com Unbind TP-Link ID Omada Cloud Service: https://omada.tplinkcloud.com

  1. In Admin, a cloud master administrator with the same username as the TP-Link ID will be automatically created. The Cloud Master Administrator cannot be deleted. You can log in with the cloud master administrator when the cloud access is enabled.

9.3.2 Create and Manage Cloud Administrator and Cloud Viewer

To create and manage cloud user account, follow these steps:

1. Click + Add New Admin Account.

USERNAME admin@tp-link.com admin ROLE Master Cloud Administrator master Administrator EMAIL admin@tp-link.com Showing 1-2 of 2 records < 1 > 10 /page Go To page: GO + Add New Admin Account

2. Select Cloud User for the administrator type in the pop-out window. Specify the parameters and click Invite.

Add New Admin Account Administrator Type: Local User Cloud User Cloud Access Required TP-Link ID: Role: Administrator Site Privileges: All (Including all new-created sites) Sites Please Select... Device Permissions: Adopt Devices Manage Devices (Move to Site, Restart, Upgrade and Forget) Alert Email…

TP-Link IDEnter an email address of the created cloud user, and then an invitation email will be sent to the email address.If the email address has already been registered as a TP-Link ID, it will become a valid cloud user after accepting the invitation.If the email address has not been registered, it will receive an invitation email for registration. After finishing registration, it will automatically becomes a valid cloud user.
Role Select a role for the created cloud user.Administrator: This role has permissions to adopt and/or manage devices of the sites chosen in the site privileges, edit itself, create/edit/delete viewer accounts in its privileged sites. However, it cannot delete itself or edit/delete master administrator and other administrator accounts.Viewer: This role can view the information of the sites chosen in the site privileges. It can only edit itself.
Site Privileges Assign the site permission to the created cloud user.All: The created user has permission in all sites, including all new-created sites.Sites: The created user has permission in the sites that are selected. Select the sites by checking the box before them.
Device Permissions (when creating a cloud administrator)Grant following permission to the created user in the role of cloud administrator by checking the box(es).Adopt Devices: The created administrator account can view the devices in status of pending in the privileged sites, and the administrator account has permission to adopt the devices.Device Manage: The created administrator account has privileges to manage the devices in the privileged sites.
Alert EmailsCheck the box if you want the created user to receive emails about alerts of the privileged sites. For detailed configurations, refer to 4.2.2 Services.

To edit and delete the accounts, click icons in the Action Column.

To edit the parameters for the user.
Cloud master administrator can edit all user accounts, administrator can edit itself and viewer accounts of its privileged sites, viewer can only edit itself.
To delete the account.
Cloud master administrator can delete all user accounts apart from master administrator and itself, administrator can delete viewer accounts of its privileged sites, viewer cannot delete any accounts.

Appendix 1: Omada APP

Omada app is a mobile application designed for Omada products. It allows you to conveniently monitor and manage your network. The Omada app can be used for Standalone and Controller mode. This appendix introduces how to use Omada app to manage your network. It includes the following sections:

• Install Omada App on the Mobile Device - Manage Your Network in Standalone Mode - Manage Your Network in Controller Mode

1 Install Omada App on the Mobile Device

Omada app runs on iOS and Android devices, such as smart phones and tablets. Launch the Apple App Store (iOS) or Google Play store (Android) and search "TP-Link Omada" or simply scan the QR code to download and install the app.

Scan for Omada App Download Omada AppTP-LINK Omada OC200 - Install Omada App on the Mobile Device - 1

2 Manage Your Network in Standalone Mode

For a relatively small-scale network which has a few EAPs (usually less than three) and only basic functions are required, standalone mode is recommended. You can use a mobile device to configure each EAP individually for basic functionality without configuring an Omada SDN Controller. Note that the EAP which is managed by Omada SDN Controller is inaccessible in standalone mode.

Refer to the topology below, make sure that the following requirements have been met:

  • An Ethernet connection from your Omada EAP to the LAN with a DHCP server.
  • The supported firmware version of the EAP. To check the firmware versions of the supported EAPs, please refer to www.tp-link.com/omada_compatibility_list.
  • A compatible iOS or Android device with Omada app.

graph LR A["Internet"] --> B["Router"] B --> C["EAP"] B --> D["EAP"] C --> E["Omada App"] D --> E

Follow the steps below to manage your network via Omada app in standalone mode. The following page is exampled with the iOS version of the app. The Android version is similar.

  1. Connect your mobile device to the EAP by using the default SSID (format: TP-Link 2.4GHz/5GHz_XXXXXX) printed on the label.

MDC104 XIX MACD-06-09-06-06-02-00 SIC:TP-14:1.2454X.XIX SIC:TP-14:1.3254X.XIX

  1. Launch the Omada app, tap Standalone APs and wait for the EAP device to be discovered. Pull down to refresh if your devices do not appear.

No SIM 3:57 PM Standalone APs Current WLAN: TP-Link_2.4GHz_062252 EAP225-Outdoor-E... EAP225-Outdoor EA-23-51-06-22-52 192.168.0.101 Can't find your device?

TP-LINK Omada OC200 - Manage Your Network in Standalone Mode - 4

Note:

All the EAP devices in the same subnet will be discovered by Omada app and shown on the page. You can tap the discovered EAP device to configure directly.

  1. Tap on the EAP device appearing on the page. Set a new username and password for your login account of the EAP.

Setup Set a new username and password for the EAP. Username admin Password

4. Edit the default SSID and password to keep your wireless network secure. Tap Next.

No SIM 3:58 PM Wireless Settings Next 2.4GHz Network SSID TP-Link_2.4GHz_062252 Password Password should contain at least 8 characters. 5GHz Network Copy 2.4GHz Network SSID TP-Link_5GHz_062253 Password Password should contain at least 8 characters.

TP-LINK Omada OC200 - Edit the default SSID and password to keep your wireless network secure. Tap Next. - 2

Note:

The settings will take effect after several minutes. For operation system differences, the wireless network connection will be different. When the default SSID of the EAP device is changed, normally mobile device join the new wireless network automatically. For the unsupported operation system, you should manually connect to the new SSID.

  1. You can view the name of the EAP device and other information including wireless parameters and clients. You can tap ☐ to change the settings of radio, SSID and device account.

No SIM 3:59 PM EAP225-Outdoor-EA-23-... EAP225-Outdoor Overview IP Address 192.168.0.101 MAC Address EA-23-51-06-22-52 Firmware Version 1.3.0 Build 20180614 Rel. 50359 Hardware Version 1.0 LED Wireless Radio >

TP-LINK Omada OC200 - Note: - 2

Note:

  • The Omada app is designed to help you quickly configure some basic settings. For advanced configuration, you can use controller mode. And when your EAP is managed by the controller, you cannot use standalone mode.
  • In standalone mode, only one user is allowed to log in to the management page of the EAP at the same time. Thus, the management web page of the EAP cannot be logged in to when using the Omada app and vice versa. Also, only one user can log in to the EAP via the Omada app.

3 Manage Your Network in Controller Mode

For a large-scale network which has routers, switches, and mass EAPs, advanced functions are required, and controller mode is recommended. Controller mode allows you to configure and manage the devices and network in a straightforward and efficient way.

The Omada app offers a convenient way to access the Omada SDN Controller and adopt devices. With Local Access and Cloud Access functions on the Omada app, you can manage the devices both locally and remotely while the controller is running.

3.1 Locally Manage Your Devices Using the Omada App

The Local Access function on the Omada app is designed for accessing the hardware/software controller which is in the same subnet as your mobile devices. Refer to the topology below, and make sure that the following requirements have been met:

  • An Ethernet connection from your Omada EAP to the LAN with a DHCP server.
  • The version of the Omada SDN Controller is 4.1.5 or above.
  • A compatible iOS or Android device with the Omada app (iOS: 3.0.28 and above, Android: 3.0.10 and above).

graph TD A["Internet"] --> B["Router"] B --> C["Switch"] C --> D["Omada Software Controller"] C --> E["Omada Hardware Controller"] C --> F["EAP EAP"] C --> G["EAP"] D --> H["Mobile Device Installed with Omada App"] E --> H F --> H G --> H

Follow the steps below to manage your network via the Omada app in controller mode locally. The following page is exemplified with the iOS version of the app. The Android version is similar.

  1. Connect your mobile device to the EAP by using the default SSID (format: TP-Link 2.4GHz/5GHz_XXXXXX) printed on the label. Note that the EAP should be in the same subnet as the controller.

MacLAN-001 mac-00 MAC-3D-08-00-08-00-00 SSG.TP-Lim, 2.4GHz, XXX SSG.TP-LINK,5GHz, XXX

  1. Launch the Omada app, go to Local Access, tap the + button on the upper-right corner to add the Omada controller. Normally, the Omada app will discover the controller which is in the same subnet. If the controller cannot be found, you can add the controller by entering the IP address and port of the controller host in the manual column.

No SIM 4:02 PM Add Controller Auto Manual Omada Controller_2EE6B0 192.168.0.100 v3.0.2

  1. Tap the Omada Controller, the controller login page will show. Enter the username and password of the controller, then tap Log In to launch the controller.

China Mobile 4G 14:38 @ 47% Login Log in with your TP-Link ID. Email administrator@tp-link.com.cn Password Log In Forgot Password? No TP-Link ID? Sign Up

  1. On the Devices screen, tap the Device that is pending for adoption. You can use the functions at the bottom to navigate various screens of the Omada Controller, including wireless statistics, client information, and basic settings.

No SIM 4:06 PM Devices Search All Wireless Wired 40-3F-8C-CE-05-50 TL-R605 192.168.0.1 Pending 84-D8-1B-B3-A8-76 EAP225-Outdoor 192.168.0.193 Pending E4-C3-2A-57-71-AC TL-SG3428XMP 192.168.0.11 Connected E4-C3-2A-57-97-76 EAP245 192.168.0.122 Connected Dashboard Devices Clients Settings

3.2 Remotely Manage Your Devices Using the Omada App

The Cloud Access function on the Omada app is designed for accessing the hardware/software/cloud-based controller via Omada Cloud Service. Thus, you can configure your controller and manage EAPs at any time, from anywhere.

Hardware/Software Controller

Refer to the topology for hardware/software controller below, and make sure that the following requirements have been met:

  • Both your hardware controller/controller host and mobile device have internet access.
  • The version of the Omada Controller is 4.1.5 or above.
  • A compatible iOS or Android device with Omada app (iOS: 3.0.28 and above, Android: 3.0.10 and above).
  • Cloud Access is enabled on the controller. The controller has been bound with a TP-Link ID.

graph TD A["Mobile Device Installed with Omada App"] --> B["Internet"] B --> C["Router"] C --> D["Switch"] D --> E["Omada Software Controller"] D --> F["Omada Hardware Controller"] D --> G["EAP EAP"] D --> H["EAP"] E --> I["Mobile Device"] F --> J["Omada"] G --> K["Hardware Controller"] H --> L["Cli…

Follow the steps below to manage your network via Omada app in controller mode remotely. The following page is exampled with the iOS version of the app. The Android version is similar.

  1. Launch the Omada app, go to Cloud Access, and tap Go to Log In to log in to Omada Cloud with your TP-Link ID.

Login Log in with your TP-Link ID. Email administrator@tp-link.com.cn Password Log In Forgot Password? No TP-Link ID? Sign Up

  1. All the controllers which are bound with your TP-Link ID will appear on the page.
  2. If you want to add a hardware controller, tap + on the upper right, scan its QR code, and follow the instructions to add a hardware controller.
  3. If you want to add devices to an existing hardware/software controller, tap the controller to launch it.

Controller - Cloud Access administrator@tp-link.com.cn OC200_36154_BghH 192.168.179.200 v4.2.8 OC200_36154_PfgH 192.168.2.200 v4.2.8 OC300_C97CE9 192.168.88.211 v4.2.4 TP-LINK 24 192.168.0.152 v4.2.8 Omada Controller_59A519 OFFLINE v3.2.7 Rudden CC Cloud Access Local Access Standalone APs Account

  1. On the Devices screen, tap the device that is pending adoption. You can use the functions at the bottom to navigate various screens of the Omada Controller, including wireless statistics, client information, and basic settings.

No SIM 4:06 PM Devices Search All Wireless Wired 40-3F-8C-CE-05-50 TL-R605 192.168.0.1 Pending 84-D8-1B-B3-A8-76 EAP225-Outdoor 192.168.0.193 Pending E4-C3-2A-57-71-AC TL-SG3428XMP 192.168.0.11 Connected E4-C3-2A-57-97-76 EAP245 192.168.0.122 Connected Dashboard Devices Clients Settings

Cloud-Based Controller

Refer to the topology for cloud-based controller below, and make sure that the following requirements have been met:

  • Your mobile device has internet access.
  • A compatible iOS or Android device with the Omada app.
  • The supported firmware version of the router/switch/EAP.

graph TD A["Mobile Device Installed with Omada App"] --> B["Internet"] C["Omada Cloud-Based Controller"] --> B B --> D["Router"] D --> E["Switch"] E --> F["EAP EAP EAP"] E --> G["Client"] E --> H["Mobile Device"] style A fill:#f9f,stroke:#333 style C fill:#ccf,stroke:#333 style D fill:#cfc,stroke:#3…

Follow the steps below to manage your network via the Omada app in controller mode remotely. The following page is an example using the iOS version of the app. The Android version is similar.

  1. Launch the Omada app, go to Cloud Access, and tap Go to Log In to log in to Omada Cloud with your TP-Link ID.

Login Log in with your TP-Link ID. Email administrator@tp-link.com.cn Password Log In Forgot Password? No TP-Link ID? Sign Up

  1. All online controllers bound to your TP-Link ID will appear on the page. Tap the cloud-based controller to launch and configure it.

Controller - Cloud Access administrator@tp-link.com.cn Cloud-Based Controller https://7B069503725FF430B... v4.2.21 OC200_36154_PfgH 192.168.2.200 v4.2.8 OC300_C97CE9 192.168.88.211 v4.2.4 TP-LINK 24 192.168.0.152 v4.2.8 Omada Controller_59A519 OFFLINE v3.2.7 Rudden CC Cloud Access Local Access Stand…

  1. On the Devices screen, tap the + in the upper right to add devices to your cloud-based controller. You can scan the barcode of the device's serial number or enter the serial number manually.

No SIM 4:06 PM Devices Search All Wireless Wired No devices found in current site and this LAN. Dashboard Devices Clients Settings

TP-LINK Omada OC200 - Cloud-Based Controller - 5

Note:

To successfully add a device to your cloud-based controller, make sure the following requirements are met:

  • Your device is powered on and connected to the internet.
  • If the device has been managed by another controller, please forget it on the previous controller and reset it to factory defaults.
  • On the Devices screen, the newly added device will appear. To manage and configure devices on the cloud-based controller, you need to activate them by assigning available licenses. Tap the device to load the page for device details.

No SIM 4:06 PM + - Devices Search All Wireless Wired 00-00-FF-FF-0F-4B EAP225-Wall 192.168.137.197 Unactivated Dashboard Devices Clients Settings

  1. Tap Activate and follow the instructions to assign licenses to the devices.

No SIM 4:06 PM 00-00-FF-FF-0F-4B EAP225-Wall Unactivated Details IP Address 192.168.137.197 MAC Address 00-00-FF-FF-0F-4B Firmware Version 1.20.0 Build 20200422 Rel. 70504 Model EAP225-Wall(EU) v2.0 CPU Utilization 0% Memory Utilization 48% License License Status • Unbound Actions Activate Move to S…

  1. After binding with licenses, the devices can be managed and configured. You can use the functions at the bottom to navigate various screens of the Omada Controller including the wireless statistics, clients information and basic settings.

No SIM 4:06 PM + : Devices Search All Wireless Wired 00-00-FF-FF-0F-4B EAP225-Wall 192.168.137.197 Connected Dashboard Devices Clients Settings

Table of contents Click a title to access it
Manual assistant
Powered by Anthropic
Waiting for your message
Product information

Brand : TP-LINK

Model : Omada OC200

Category : Controller