Overview
GDMS Management is an enterprise-grade platform designed to provide a unified, centralized management system for a wide range of network and communication devices. It integrates GDMS Networking and GDMS Unified Communications to offer comprehensive oversight and control over network and communication infrastructure.
GDMS Networking is a core component of the GDMS Management platform, focused specifically on managing network devices. It provides a streamlined and centralized approach to handle access points (APs), routers, switches, and GCC devices. It simplifies and enhances network management, ensuring efficient, secure, and high-performance operations across multiple locations through an intuitive interface. GDMS Networking is a cloud-based solution while GWN Manager serves as the on-premise solution for robust network management within a local environment. Both solutions support the GDMS App on iOS® and Android® for mobile network management and monitoring.
PRODUCT OVERVIEW
Features Highlights
GDMS Networking |
|
GWN Manager |
|
Shared |
|
Features Highlights
Specifications
Function |
|
Security and Authentication |
|
Enterprise Features |
|
Supported Devices |
|
Captive Portals |
|
Centralized Management |
|
Reporting and Monitoring |
|
Maintenance |
|
Languages | English, Chinese, Spanish, German, Portuguese, French and more. |
GDMS Networking specifications
GETTING TO KNOW GDMS Networking PLATFORM
GDMS Networking
GDMS Networking is a cloud-based platform used to manage and monitor Grandstream devices (GWN Access Points, GWN Routers, GWN Switches and GCC devices) wherever they are as long as they are connected to the internet. The platform can be accessed using the following link: https://www.gdms.cloud. It provides an easy and intuitive web-based configuration interface as well as an Android® and iOS® App.
Sign up to GDMS Networking
When accessing GDMS Networking for the first time, users are required to sign up. The following screen will be displayed:
- Click “Sign up” to go to the sign-up screen, then enter the required information.
Nickname | Specify a nickname of this account. |
Username | Specify a username for this account. |
Enter the email address. | |
Password | Specify a password for the account Note: 8-16 characters, must be a combination of numbers, letters, and special characters. |
Confirm password | Re-enter the password again. |
User type | Select from the drop-down list the type of user:
|
Company Name | Enter the company name if the type of user is set to Enterprise, Server provider, Channel reseller, System integrator. |
Verification code | Copy the verification from the Captcha. |
GDMS Sign-up Settings
2. Once you create an account, you can access your GDMS Networking page for the first time, and the following page will be displayed:
When the first page opens on GDMS Unified Communications, users can access GDMS Networking by clicking on the “GDMS Networking” option located in the top right corner, as shown below.
The user can access the modules listed in each category to jump quickly to the intended destination. See the example below for the GDMS Networking system.
Region settings
Region settings allow users to enable different regions (data centers). To enable or delete a region, on the top right of the page, click on the location icon → region settings as shown below:
The users’ and devices’ data is stored in the enabled regions. To delete a region, click on “Delete“, and to enable a region, click on “Enabled“.
To start using the enabled region to store users/devices data, make sure it’s selected on the main page, as shown below:

Merge Accounts
The merge accounts feature allows users to merge different accounts with different services and regions into one single base account. On the main page of GDMS Networking, in the top right corner of the page, click on the account name, then select Merge Accounts as shown below:
Click on the “+Accounts to Be Merged” button to add more accounts, then select the base account that will be used for centralized management.

GWN Manager
GWN Manager is an On-premise Grandstream device controller used to manage and monitor network devices, including GWN Access points, GWN Routers, GWN Switches, and GCC devices on your network.

GWN Manager Hardware Requirements
Sofware Requirements | Hardware requirements |
Operation System:
| For up to 200 devices and 2 000 clients:
|
For up to 3 000 devices and 30 000 clients:
| |
For up to 10 000 devices and 200 000 clients:
| |
For up to 30 000 devices and 600 000 clients:
| |
For up to 50 000 devices and 1 000 000 clients:
|
GWN Manager hardware requirements
Installation
To install GWN Manager, please visit the links below:
GWN Manager – Quick Installation Guide
GWN Manager – Deploying a Virtual Machine from an OVA file
First Use
The GWN Manager provides an easy and intuitive Web UI to manage and monitor GWN network devices. It provides users access to all GWN settings, without any additional on-premise infrastructure.
On first use, users need to fill in additional information following the GWN Manager Wizard:
General | Specify the country/region and time zone for the default network. Note: these parameters can be automatically detected by the system. |
User Account | Set up a username, password and email for local login. |
Adopt Device | Select the GWN devices to be adopted by the default network. Note: Access points, Routers available on the same LAN will be detected automatically. |
SSID Configuration | Create an SSID to be used by the default network for the first time. Note: this SSID can be modified later. |
Summary | Review all the previous settings |
GWN Manager setup wizard





Sign up for GWN Manager
Enter the previously configured user credentials to access the GWN Manager GUI:

The following page will be displayed:

Users Settings
To edit the user settings of the currently logged-in account, click on the name of the account from the top right corner → Click on User Settings, and a new page displaying the account details will be displayed, refer to the figure below:
To modify a field, click on “Modify” text, refer to the figures and table below:
Nickname | Modifies the user nickname |
Username | Modifies the username |
Modifies the Email address | |
Password | Changes the password |
Language | Select the web UI language from the drop-down list |
Timezone | Select the timezone from the drop-down list |
Time | Select the time format: 12 hours or 24 hours |
Date Format | Select the date format from the drop-down list |
Appearance | Select the interface theme from the drop-down list: • Follow System • Light • Dark. This setting customizes the platform’s appearance for your account only. |
User Type | Select the user type from the drop-down list |
Company Name | Specifies the company name |
Country | Select the country from the drop-down list |
Multi-Factor Safey Authentication | Toggle ON/OFF the Multi-Factor authentication Note: for more details, visit Multi-Factor Authentication |
User Settings
Theme Appearance
GDMS Networking includes a customizable Appearance setting, allowing each user to personalize the platform interface using Light, Dark, or System Default themes.
This setting enhances visual comfort—especially in low-light environments—and is applied on a per-user basis, without affecting other users in the same organization.
To access the appearance settings:
- Click your account icon in the upper-right corner of the page.
- Select User Settings from the dropdown menu.
- On the User Settings page, locate the Appearance field.
- Click Modify to open the theme selection dropdown.
- Choose one of the available options:
- Follow System (Light): Automatically uses your operating system’s current display theme.
- Light: Standard white background with light color scheme.
- Dark: Dark interface theme designed for low-light or night-time environments.
- Click Save to apply the selected theme.
Feedback
If the users have an issue/bug to report or need help with configurations or general feedback, on the top right corner of the page, click on the account username, then click on “Feedback” to send feedback.
Then, select what type of feedback:
- I have an issue/bug to report and need a solution (forwards the users to Grandstream helpdesk)
- I need help on my configurations (forwarding the users to Grandstream helpdesk)
- Feedback.
- Other.
If Feedback or Other is selected, this page will be shown for users to specify the issue/bug/feedback with attachments (e.g., syslog) and emails for contact.
GETTING STARTED WITH GDMS PLATFORM
The GDMS Platform provides an easy and intuitive Web UI or mobile app (both Android® & iOS® versions) to manage and monitor Grandstream devices (Access points, Routers, Switches, and GCC devices). It provides users access to all device settings, without any additional on-premise infrastructure.
Add a Device to GDMS Networking
To add a device to GDMS Networking, the administrator needs two pieces of information:
- MAC address of the device.
- Password is in the back of the unit.
There are 3 methods to add devices to the cloud:
- Method 1: Adding a New Device Manually
- Method 2: Adding a New Device Using the GWN Application
- Method 3: Transfer APs’ control from Local Master (only for GWN Access points)
Method 1: Add a new device manually
- Locate the MAC address on the MAC tag of the unit, which is on the device or the package.
- Locate the Password.

3. Navigate to Devices and click on the “Add” button.
4. Select a name for the device, then enter the MAC address and password. The user also has the option to add equipment remarks to easily identify the devices when added to the GDMS Networking or GWN Manager. Also, there is the option to select a device from the Inventory (previously claimed). Please, check the figures below:

If the device is a router, the users will have to option to automatically synchronize router local WAN configurations to GDMS Networking and also assign the SSIDs that are already in the network to the newly added router.
5. Click on the “Add” button, and the device will be added automatically to your GDMS account, and you will be able to monitor/manage it.
Bulk-add devices using CSV file import
Another option for bulk-add devices is to use a CSV file upload.
After clicking on “Add” under the menu Devices, click on the Import Tab and click on the”Add” button to select a CSV file.

Method 2: Add a new device using the GDMS Networking Application
An easy way to add a new device to your GDMS Networking is to use the GDMS Application.
The operation is done by scanning the barcode from the device’s sticker.


Once added, the list of devices will be displayed on the GDMS Networking interface.
Method 3: Transfer from Local Master
In the case where a local master is managing the Access points. Another method to add devices (Access points slaves) to the GDMS is by transferring them to the cloud from the local Master. Follow these steps to achieve this:
- Access the web UI of the local master and go to Access Points.

2. Press button. A new window will display the “Transferable devices” list as shown below.

3. Press button. The web browser will redirect to GDMS Networking login page.
4. Once logged in to the cloud, the configuration page “Select Network” will be displayed:

- Access Point: Shows the MAC address of the passed check device.
- Failed: Shows the MAC address of the authentication that failed or was added.
5. Select Network from the drop-down list to which the AP will be assigned.
6. Press the Save button to confirm.
7. Once added to the cloud, the Master AP web UI will display the following successful notice.

Adopt a Device to GWN Manager
To add devices (router, switch, access point, GCC) to the GWN manager:
- Navigate to GWN Manager Web UI → Devices
- Click on the “Adopt” button.
3. If the GWN Manager connects to the same local subnet as Grandstream devices, it can discover the devices automatically via layer 2 broadcast. GWN devices accept DHCP option 224 encapsulated in option 43 to direct the controller. An example of a DHCP option 43 configuration would be:
224(type)18(length)172.16.1.124:10014(value) translated into Hex as e0123137322e31362e312e3132343a3130303134
4. Select a device by checking the box on its left. Or select all by checking the top box. Then click the “OK” button.
When adopting a GWN router or a switch, the user will be prompted to enter the router/switch’s current administrator password. Please refer to the screenshots below.

When clicking “OK”, the user will be prompted to enter the current password of the administrator account of the device to finish adopting the device.

Adopting devices manually
To manually configure the manager address and port on a GWN device, enable Manager Settings, fill in the Manager Address and Port, and finally click on the “Save” button. For each GWN device (AP, Router, or Switch), please check the steps below:
You can log into the WebUI of a slave AP or an unpaired AP to set the Manager address and port.
For GWN APs, please log in to the GWN AP in slave mode, then navigate to GWN AP Web UI → System → Manager Settings.
For GWN routers, please navigate to GWN Router Web UI → System Settings → Basic Settings page → Manager Server Settings tab.
For GWN switches, please navigate to GWN Switch Web UI → System → Access Control page → Manager Settings tab.
It’s also possible to SSH a slave AP and use the GWN menu to set the Manager address and port (8443).

NETWORKS
The network page provides information regarding all the network groups created under your account. Once the administrator selects one network, all the other configuration pages will change to reflect the information related to the selected network.
Create a new Network
To create a new Network:
- Navigate to GWN Manager Web UI → Organization → Overview → Network Overview Tab, and all the previously created networks will be displayed here.
- Click on the “Create Network” button and enter the network name, country/region, time zone, and Network Administrator, and select a network in case you want to clone a previously created network.
| Organization | Select the organization under which the network will be created. This is used to group and manage networks within a specific organization account. |
| Network Name | Enter the name of the network. The name must contain between 1 and 64 characters and should help identify the network easily. |
| Country/Region | Select the country or region where the network is deployed. This setting may affect regional services, formats, and compliance requirements. |
| Time Zone | Select the time zone for the network. The system uses this setting for logs, schedules, reports, and time-based configurations. |
| Administrator | Displays the administrator account assigned to manage the network. This account will have management permissions for the created network. |
| Clone Network | Allows the user to copy the configuration settings from an existing network. Select a network from the drop-down list to duplicate its settings. |
| Default Network | Enable this option to set the newly created network as the default network within the organization. |
| Tag(s) | Assign tags to the network for easier categorization, filtering, and management. Multiple tags can be added if available. |
| Position | Specify the physical location, branch, or deployment position of the network if required for organizational purposes. |
Add Network Parameters
Move a device to a Network
To move a GWN device to another Network, please navigate to the Devices page, select the desired devices, click on the “More” button, then select “Move“. A pop-up window will appear to choose the destination network to which the selected devices will be moved.
Share a Network
GWN Platforms allow the sharing of a network among the administrators of the organization. To share a network, please navigate to Organization → Overview, then click the configuration icon of the network you wish to share.



DASHBOARD
The Dashboard page provides general information that can be used to monitor GWN devices (The Router with its WAN IP, Switches, and Access Points) and Clients. It also displays the number of Devices online and offline, and as for Clients it displays the number of wired and wireless clients. It also displays an Alerts preview, and the user can click on icon to open the Alerts page with more details.
Click on this icon to get redirected to the Network Topology page.
The user can choose the statistical duration of the data to review for the last 2 hours, 1 day, 1 week, 1 month, 3 months, or 6 months.
- 2 hours and one day: Refresh and record data every 5 minutes.
- 1 week: Refresh and record data every 30 minutes.
- 1, 3, and 6 months: Refresh and record data every 3 hours.

To customize the Dashboard page by adding or removing charts, please click on this icon, and refer to the figure below:

Clients Count | It shows the number of clients connected at a specific period of time. |
Bandwidth Usage | It shows the bandwidth usage over time across all the WAN ports. |
Client Manufacturer | It shows the names of the manufacturers of the network hosts with the percentage of the number of the hosts from each manufacturer. |
Client OS | It shows the operation system that the network hosts are running. |
Client Statistics | Displays the new clients, the returning clients, and the average client time. |
Guest New Session | Displays the number of clients who used Captive Portal authentication. |
Guest Session by Authentication | Displays the number of clients per type of Captive Portal authentication. |
Top Devices | This shows the total bandwidth used by network switches and access points. This includes the bandwidth used by the clients connected to network equipment as well as the bandwidth used by the equipment itself. |
Top Clients | Lists the clients by their total amount of upload and download bandwidth used. |
Top SSIDs | Lists the SSIDs with the most upload and download bandwidth used. |
WAN Speed Test
When a GWN router is added to the GWN Management and the WAN is added under Settings → Internet → WAN, the user can click on the speed test icon as shown below to run the speed test of the selected WAN.

First, select the WAN under Internet, then click on the speed test icon, and then the download test will start.

Once the download test is over, the upload test will start next.

Finally, the speed test result will be shown with download and upload rates.

DEVICES
On this page, users can Add (GDMS Networking) or Adopt (GWN manager), export a list of devices, move to a different network/Device group, reset, delete, configure, reboot, or push configuration.
Also displays all the related information for the GWN devices on the current network. To add/remove columns, click on the “Parameters icon” as shown below:
More information can be viewed from this page:
- Device Model
- Name
- MAC address
- IP address
- Public IP address
- IPv6 address
- Device group
- Firmware
- Uptime
- Number of Clients
- Usage
- Channel: displays GWN APs’ used channels on all bands.
- TX Power: displays transmission power on wireless devices, e.g., GWN APs, in dBm.
- Uplink Speed: Displays the current uplink speed for routers and switches (e.g., 1Gbps, 2.5Gbps), improving real-time link monitoring.
- First Seen: Shows the date and time the device was first connected to GDMS Networking, useful for tracking onboarding history.
- Last Seen: displays the date and time of the device’s most recent connection to GDMS.
For reference, please check the examples below:
Group Management
Group management is a logical group that contains devices either for the same model or different models. This helps make GWN device management even easier. For example, there are pre-set features for switches when added to a group, or when the user wants to apply certain configurations on many devices at the same time, configurations can be applied directly to the device group containing those devices.
GDMS Networking also supports cloning network settings for WAN, VPN, and Device Groups, allowing administrators to quickly duplicate and apply existing configurations across multiple deployments. This helps simplify large-scale network deployments, reduce repetitive configuration tasks, and maintain consistent network settings across different sites and device groups.
To create or edit a Device Group, please navigate to the Web UI → Devices page, then click on the “Group Management” button.
To add a new Device group or add devices to a previously created Device group, click on “+” icon, to delete or modify a Device group, click on the “Edit” or “Delete” icons, respectively.
Switch Pre-Provisioning
The switch Pre-Provisioning feature allows the user to pre-configure port settings and CLI commands for the switches that belong to the same device group. Once the GWN switches are added to the device group, the pre-configurations will take effect.
- Port Settings
In this section, the user can pre-configure the switch ports with a port profile and Trust DHCP Snooping (On or Off).
Click on “+” or “–” icons to add or delete port settings. Please refer to the figure below:
- CLI Command
The user can enter the CLI commands here, separated by “Enter“. Please use English and characters only, and use the “#” key for the comment line.
Push Configuration
The push configuration feature helps to push GDMS Networking or GWN Manager configuration to the local side of added GWN devices, either manually or automatically.
Manual Method
To manually push the GDMS Networking/GWN Manager configuration to the local side of a GWN device, please navigate to Web UI → Devices page, then select a device and click on the “More” button, next click on “Push Configuration“.
A confirmation dialog will pop up to confirm the push configuration, to proceed click on the “OK” button.
Automatic Method
If the user wants to push the GDMS Networking/GWN Manager configuration automatically for the selected GWN device, navigate to Web UI → Devices page, then click on a GWN device or configuration icon, and on the top of the page, toggle ON “Auto Configuration Delivery“, please refer to the figure below:

Export
The user can click on the “Export” button to download a file (Excel file) that contains all the devices on this network with details. Please refer to the figures below:

The exported file contains the following information about all the devices:
- Device Model
- MAC Address
- Name
- IP Address
- Connection IP Address
- IPv6 Address
- Device Group
- Firmware Version
- Running Time
- Clients Count
- Usage
- Channel (For GWN APs & GWN Wireless Routers)
- Tx Power
- Device Remarks
- Serial Number
More
To view more options, please click on the “More” button as shown below:
Reboot: to reboot the GWN device.
Return: Returning a device will transfer it from its current network to the inventory, where it can be reassigned.
Move: to move a device from the current network to another network.
Reset: to reset a device.
Delete: to delete a device.
Operation
Under Operation, the user can find more tools that can help with managing GWN devices.
: Click to configure the GWN device.
: Remove access to the GWN device Web UI.
: Web CLI.
Configure a Device
The configuration page allows the administrator to name, reboot, configure, etc. GWN devices.
Navigate to the Web UI → Devices page, then click on a GWN device entry or click on the configuration icon.
Configure a GWN Access Point
On the Devices page, when the user clicks on a GWN Access point, there are many options on the top of the page dedicated only to GWN Access points:

- Speed Test: is a feature on GWN APs to run a speed test directly from GDMS Networking or GWN manager, making it easier for administrators to check many GWN APs from one single interface. For more details, please refer to the figures below:
To start running the speed test, click on the “Speed Test” button, refer to the figure above.
The first speed test tests download speed.

Once the download speed test is over, the second test is testing upload speed.

Finally, the user will be able to see the final result, including Download/Upload speed and also the Ping response time in ms (Milliseconds). To run the speed test again, click on the “Test Again” button.

- Locate the device: easily locate the device by clicking on the “Locate the device” button, a white light will flash for 2 minutes, or click on the “Close” button.
- GWN Access Point – Usage
This page shows the usage of the GWN AP (Bandwidth usage and Client Count). The data shown can be filtered from 2 hours up to 1 month.
Clear usage: to clear collected data from the AP (Bandwidth usage and Client Count).
- GWN Access point – Info
On this page, info related to the GWN AP information (firmware, UPtime, etc), RF (Radio Frequency), and Current Client can be found here.
RF Information (BSSID)
The Basic Service Set Identifier (BSSID) is the MAC address of the wireless interface, or precisely the radio antenna (2.4GHz or 5GHz). For example, on the GWN7624 access point, we will have two BSSIDs, one for the 2.4GHz antenna and another for the 5GHz antenna. The two MAC addresses for both antennas will be based on the original device MAC address. In our example, the GWN7624 MAC address is C0:74:AD:XX:XX:40, then the 2.4GHz antenna BSSID is C0:74:AD:XX:XX:41, and for the 5GHz antenna is C0:74:AD:XX:XX:42. Access points include the BSSID in their beacons and probe responses.
Navigate to web UI → Devices → Info, then scroll down to RF Information (BSSID). Refer to the image below.

- GWN Access point – Debug
GWN APs have many debug tools to help diagnose the issues:
- Ping/Traceroute: Ping and traceroute to check the reachability or the trace of an IP/Domain.
- Capture: to capture the traffic of GWN AP or GDMS Networking/Manager (a file will be downloaded to your local machine).
- Core Files: Core Files will be listed here when generated.
- SSH Remote Access: to allow SSH remote access
- Event log: a list of events related to the GWN AP.
- GWN Access Point – Configuration
On this page, the administrator can configure GWN AP-related settings like (name, band steering, VLAN, RF, etc). This configuration is limited to this GWN AP.
- GWN AP L2TPv3
L2TPv3 (Layer 2 Tunneling Protocol version 3) is a versatile protocol widely utilized for tunneling Layer 2 traffic over IP networks. When implemented on GWN Access Points acting as L2TP Access Concentrators (LACs) connecting to a central L2TP Network Server (LNS), it enables seamless and secure communication for wireless clients.
GWN Access Points, known for their reliability and performance, acting as LACs, establish tunnels to the LNS, facilitating the encapsulation and transmission of all wireless clients’ Layer 2 traffic. This architecture proves particularly beneficial in centralized network models where VLANs extend from corporate environments to remote branch sites.
By leveraging L2TPv3, wireless clients associated with GWN Access Points are seamlessly integrated into the corporate network infrastructure. They receive IP addresses dynamically from the DHCP server hosted on the LNS, ensuring efficient network resource allocation and management.
This integration empowers organizations with scalable and secure wireless connectivity solutions, optimized for various deployment scenarios. Whether for small businesses or enterprise environments, the utilization of L2TPv3 on GWN Access Points offers a robust framework for extending network capabilities while maintaining high levels of performance and security.
To add an L2TPv3 tunnel, click on the “Add” button as shown below:
Please refer to the figure and table below:
Name | Set the name of the tunnel. |
L2TPv3 | Enable/Disable the tunnel. |
Protocol | Set the encapsulation type of the tunnel. Valid values for encapsulation are: UDP, IP. |
Remote Server Address | Set the IP address of the remote peer. |
Local Tunnel ID | Set the tunnel id, which is a 32-bit integer value. This uniquely identifies the tunnel. |
Remote Tunnel ID | Set the peer tunnel id, which is a 32-bit integer value assigned to the tunnel by the peer. |
Local Session ID | Set the session id, which is a 32-bit integer value. This uniquely identifies the session being created. The value used must match the peer_session_id value being used at the peer. |
Remote Session ID | Set the peer session id, which is a 32-bit integer value assigned to the session by the peer. The value used must match the session_id value being used at the peer. |
Local Cookie | Set an optional cookie value to be assigned to the session. This is a 4 or 8 byte value, specified as 8 or 16 hex digits, e.g. 014d3636deadbeef. The value must match the peer_cookie value set at the peer. The cookie value is carried in L2TP data packets and is checked for expected value at the peer. Default setting is no cookie used. |
Remote Cookie | Set an optional peer cookie value to be assigned to the session. This is a 4 or 8 byte value, specified as 8 or 16 hex digits, e.g. 014d3636deadbeef. The value must match the cookie value set at the peer. It tells the local system what cookie value to expect to find in received L2TP packets. Default is no cookie used. |
MTU | Set the MTU. Note: Please make sure the MTU values are consistent with the INS values. |
Tunnel VLAN ID | Specify the VLAN ID Note: The tunnel ID must be set in SSID, and make sure that SSID only has the AP(s) who enabled L2TPv3. |
Add L2TPv3
Configure GWN Access Points in Batches
GWN Management platforms allow configuring GWN access points in batches. To do that, please select the access points, click on “More“, then click “Configure” as shown in the figure below.

Edit Configuration File (Access Points)
GDMS Networking allows administrators to directly view and edit an access point’s configuration file in text format. This feature is available for GWN Access Points only and is mainly intended for advanced troubleshooting, support-guided changes, or applying a configuration that is not easily handled through the standard UI.
To access and use the configuration file editor:
- Go to Devices, locate the target access point, then click the Edit Configuration File icon under the Operation column.
- In the Edit Configuration File window, you can edit the configuration directly in the text area. You can also use Export to download the current configuration as a text file, then edit it locally and use Import to upload the updated file back into the editor.
- Click Save to apply the configuration to the access point.
When saving a modified or imported configuration, GDMS Networking displays a confirmation warning that the existing configuration will be overwritten. Check I understand, then click Save to proceed.
After any edit (including importing a file), the editor may show “The initial configuration file has been modified.” This simply indicates the current text differs from what was originally loaded when the window opened.
Notes:
- Configuration files may include sensitive values (such as keys or credentials). Treat exported files as confidential.
- Invalid configuration entries may cause the device to malfunction or go offline, so it is recommended to export a backup before making changes.
- Settings applied through a configuration file may not be overridden later through standard UI configuration pages.
Configure a GWN Router/GCC device
- NAT Traversal
Network Address Translation (NAT) translates private IP addresses to a public IP address, allowing multiple devices to share one public IP address. This poses a challenge for inbound connections from the internet. NAT Traversal facilitates these connections, making devices behind a NAT router accessible from the Internet. This is essential for applications like VoIP, online gaming, and remote management.
When a Grandstream GWN router/GCC device is added to the GDMS Cloud, the NAT Traversal option becomes available. This section will guide you through the configuration process with step-by-step instructions and screenshots.
To configure NAT Traversal, under the Devices page, select a GWN router or GCC device, then click on “NAT Traversal” as shown below:
Click on the “Add” button to create a new NAT Traversal rule.
Specify the Name, Service type, Internal IP address, and the port, then click on the “Save” button to save the rule.
Finally, for the rule to take effect, enable it under status and click on “Sign in” to get redirected.
- GWN Router/GCC device – Usage
Same as the GWN AP usage tab, on this page, the user can find usage related to the GWN Router and GCC devices, like bandwidth usage, Real-time Rate, and even a Link Trace Table for detailed traffic data. Please refer to the figure below:
- GWN Router/GCC Device – Info
All the information related to the GWN router can be found here, including Device information (name, firmware, etc), GWN router ports’ status (active ports), and information about IPv4 and IPv6 (IP address, DNS, etc).
- GWN Router/GCC Device – Debug
The same debug tools found on GWN APs can be found here; please check GWN Access Points.
- GWN Router/GCC Device – Configuration
On the GWN router/GCC device configuration tab, the user can configure device name, and Network Acceleration, enable disable physical ports (WAN/LAN), and add/edit VLAN interfaces. Please refer to the figure below:
VLAN Interface (interface for GWN routers/GCC device)
VLAN Interface, as the name suggests, turns a VLAN into a virtual interface that can be routed using layer 3 routing by giving this interface an IP address. To add a VLAN interface for GWN routers/GCC devices, please click on the”Add” button or configure a previously created one by clicking on the “Configure icon” under operation, refer to the figure below:
Then, select the VLAN from the list or visit the LAN page to create a VLAN (with or without a DHCP Server) first, in case there are no VLANs listed, then specify an IPv4 or IPv6 Address/Prefix for this VLAN interface.

- GWN Router/GCC Device – FXS Configuration (GWN7062ET Only)
The FXS Configuration section allows administrators to configure and manage the FXS ports of supported GWN devices for analog telephony services. Through this section, users can configure SIP account registration settings, SIP server and network communication parameters, voice codec behavior, ring tone settings, and advanced call handling features. These configurations help ensure proper interoperability with SIP platforms, analog phones, PBX systems, and VoIP service providers.
All configuration settings can be applied individually for each available FXS port, allowing administrators to customize telephony behavior and SIP account settings independently per connected analog device or telephone line.
Account Settings: The Account Settings section is used to configure the basic SIP account information associated with the selected FXS port. Administrators can enable or disable the port and configure parameters such as the SIP User ID, authentication ID, authentication password, and display name. These settings are required for registering the FXS port with a SIP server or IP PBX system.
SIP Settings: The SIP Settings section is used to configure SIP server communication and network-related SIP parameters. Administrators can define the primary and failover SIP servers, outbound proxy settings, NAT traversal methods, SIP transport protocols (UDP/TCP/TLS), local SIP ports, and SIP keep-alive mechanisms. These settings help ensure stable SIP registration and reliable communication between the FXS device and the VoIP infrastructure.
Voice Codec Settings: The Voice Codec Settings section allows administrators to configure RTP and audio processing behavior for voice calls. Settings include jitter buffer type and length, RTP port configuration, SRTP encryption mode, preferred DTMF method, and regional SLIC impedance settings. These parameters help optimize audio quality, call stability, compatibility, and voice security depending on the deployment environment and SIP provider requirements.
Ring Tones: The Ring Tones section is used to customize telephony tone behavior for the selected FXS port. Administrators can configure dial tone, ringback tone, busy tone, reorder tone, and prompt tone language settings. These configurations help adapt the telephony experience to different regional standards and user preferences.
Call Features: The Call Features section provides advanced telephony and call handling configurations for the selected FXS port. Features include anonymous calling, anonymous call rejection, call waiting, hook flash support, DND reminder ring, visual message waiting indication (MWI), call forwarding options, emergency call handling, and audio gain adjustments for transmit and receive paths. These settings allow administrators to customize user calling behavior and enhance telephony functionality for analog devices connected to the FXS port.
Configure a GWN Switch (Layer 2+ / Layer 3)
- GWN Switch – Usage
As for the GWN Switches usage tab, traffic statistics or PoE Ports power usage can be found here. The user can click on the”Clear Traffic” button to clear all the traffic or click on the”Clear” icon under operation to clear traffic only for a specific port.
- GWN Switch – Info
Relevant GWN switch information or PoE power supply information can be found here.
- GWN Switch – Port
The Port tab under each GWN switch device in GDMS Networking provides a centralized interface to monitor and configure individual Ethernet ports. This includes port status, traffic rates, VLAN tagging, link aggregation, speed controls, authentication methods, and security settings.
This page allows administrators to fine-tune port behavior to meet both performance and security needs in enterprise networks.
Port List and Status View:
At the top of the Port tab, users can see a graphical representation of all switch ports. Each port block displays real-time link status, port number, and traffic activity.
- Visual Layout (Top Panel)
The port layout gives a graphical overview of each port’s current connection and status. Ports are color-coded by link speed:
- 10Gbps – Cyan
- 2.5Gbps – Blue
- 1000Mbps – Green
- ≤100Mbps – Yellow
- Disconnected – Gray
- Errdisable – Red
- Disabled – Light Gray
Icons can appear over ports to indicate special configuration:
- ⚡ PoE (Power over Ethernet)
- ↔ Aggregation (LAG)
- 👁 Mirror (monitoring enabled)
- ⬆ Uplink (indicates uplink port)
This layout helps network admins visualize the topology and quickly locate key connections or issues.
Clicking on a port opens a detailed configuration panel for that individual port.
After selecting a port, the panel expands to include key settings grouped into the following areas:
- Basic Info: Port name, enable status, link profile
- General Settings: VLANs, duplex mode, flow control
- Security Settings: MAC or 802.1X authentication, isolation, guest VLAN
The top section of the port settings includes:
- Port Number & Name: Displays the port number. You can assign a custom name for easier identification (up to 64 characters).
- Port Enable: Toggle to enable or disable the port.
- Link Aggregation: Assign this port to a Link Aggregation Group (LAG).
- Link Aggregation Type: Choose between Static or LACP (Link Aggregation Control Protocol).
- LACP Protocol Priority: Set the priority for this port in the LAG group. Lower values indicate higher priority (range: 1–65535).
- LACP Packet Timeout Period: Choose between Slow (30s timeout) or Fast (1s timeout) modes.
- Port Profile / LAG Port Profile:
- When LAG is not enabled, this setting appears as Port Profile.
- When the port is assigned to a LAG group, it becomes a LAG Port Profile.
- In both cases, this setting applies a predefined profile to the port or virtual LAG interface.
Note: The profile is only effective if the Port Profile Override is disabled.
- Trust DHCP Snooping: Enable to allow DHCP responses from trusted sources on this port.
To configure or manage port profiles, go to:
Settings → Profile → Port Profile
Port Configuration – Port Profile Override:
If Port Profile Override is enabled, the predefined port profile (or LAG port profile) will be ignored, and custom settings can be applied directly to the selected port. This is useful when specific port behavior is required outside of the standard profile applied to other ports.
The override settings are grouped into two sections: General and Security.
General Settings:
- Native VLAN: Selects the untagged VLAN for the port.
- Allowed VLAN: Lists the tagged VLANs allowed on the port.
- Voice VLAN: Enables a dedicated VLAN for voice traffic (requires Voice VLAN to be enabled globally).
- Rate: Sets the interface speed (Auto or manual selection).
- Duplex Mode: Choose between Auto-negotiation, Full-duplex, or Half-duplex.
- Flow Control: Enables or disables Ethernet flow control.
- Enable Port STP: Enables Spanning Tree Protocol for the port.
- Incoming/Outbound Speed Limit: Allows rate limiting in both directions.
- LLDP-MED: Enables LLDP-MED protocol for enhanced device discovery and voice services.
- Network Policy TLV: Allows setting network policy TLVs (Voice VLAN must be enabled first).
Security Settings:
- Storm Control: Enables protection against broadcast, multicast, or unknown unicast storms.
- Port Isolation: Isolates traffic from this port to others.
- Port Security: Allows MAC address-based security.
- User Authentication Mode: Selects between None, MAC-based, or 802.1X-based authentication.
- Authentication Type: Configure MAC Authentication and/or 802.1X with method (e.g., RADIUS).
- Guest VLAN: Assigns a fallback VLAN for unauthenticated clients (requires global Voice VLAN).
- Port Control: Defines behavior (e.g., Auto, Force-Authorized, Force-Unauthorized).
- Re-authentication: Enables periodic re-authentication for connected clients.
- GWN Switch – Debug
Debugging tools like ping/traceroute are also available for GWN switches, as well as SSH Remote Access.
- GWN Switch – Configuration
On this tab, under devices (only for GWN switches), the user can configure GWN switch-related configurations like switch name, RADIUS Authentication, and VLAN interfaces.
Device Password: Set the device’s SSH remote login password other than APs, which is also the device’s web login password.

VLAN Interface (interface for GWN switches)
Hosts in different VLANs cannot communicate directly and need to be forwarded through routers or layer 3 switching protocols.
A VLAN interface is a virtual interface in Layer 3 mode and is mainly used to implement Layer 3 communication between VLANs; it does not exist on the device as a physical entity. Each VLAN corresponds to an interface by configuring an IP address for it; it can be used as the gateway address of each port in the VLAN so that packets between different VLANs can be forwarded to each other on Layer 3 routing through the VLAN interfaces. GWN switches support IPv4 interfaces as well as IPv6.
To add a VLAN Interface for GWN switches, click on the “Add” button or click on the“Configure icon” to edit previously added one. Refer to the figure below:

- If DHCP is selected: hosts will obtain IP addresses automatically from whatever DHCP pool is configured for example a router.
- If Static IP is selected: for hosts to obtain IP addresses, the user must configure a VLAN with DHCP Server, and create or edit VLAN first LAN.

Configure a GWN Switch (Layer 2 lite)
This section explains how to configure GWN Layer 2 Lite switches, such as the GWN7711P, using the GDMS Networking platform. Layer 2 Lite switches have a simpler interface compared to Layer 2+/Layer 3 switches, and not all features are available depending on the specific model. The following pages reflect the actual layout and tabs of the Web UI for easier orientation.
- Layer 2 Lite Switch – Usage – Traffic Statistics
The “Traffic Statistics” view under the Usage tab allows users to monitor packet flow in real-time for each port on the switch. It displays key metrics such as:
- InPackets / OutPackets
- InErrPackets / OutErrPackets
A statistical interval drop-down is available to refresh data every few seconds, and you can filter to show specific ports. Use the “Clear Traffic” button to reset statistics either for all ports or individually using the eraser icon in the Operation column.
- Layer 2 Lite Switch – Usage – PoE Ports
This page appears only if the switch model supports PoE. It displays detailed power usage for each PoE-enabled port, including:
- Current (mA)
- Current Power (mW)
- Power-Off Schedule
- Temperature (°C)
- Power Supply Mode (Auto, Force, Close)
At the top, a banner appears prompting users to match the total configured input power to the actual power supply. Failing to do so may result in unstable power delivery to connected devices. The “Set up now” link will lead users directly to the Configuration tab to adjust power input values.

To configure PoE behavior per port, click the gear icon on the right. This opens advanced settings, allowing users to define the following:
- Port-specific Power Supply Standard (802.3af/at, 24V DC, 48V DC)
- Custom Power Limit (in Watts)
- Power Supply Mode (Auto / Force / Close)
- Power Priority (Highest, Second Highest, Lowest)
This lets the user fine-tune how power is allocated to each port, especially in cases where power is limited and needs to be prioritized.
- Layer 2 Lite Switch – Info
The Info tab provides a quick summary of system data, including:
- Device Name
- Model
- System Uptime
- PoE Power Supply Information (Total capacity, reserved, consumption)
This tab is read-only and reflects current operating conditions. It also includes chip-level power status, such as working condition and voltage delivery.
This is especially useful when troubleshooting PoE issues or confirming if the system is receiving and supplying adequate power.

If the switch is configured in a stack, the user can switch the view between the switches in the same stack.

- Layer 2 Lite Switch – Port
The Port tab shows a visual representation of the switch’s physical ports. Each port’s color indicates its current link speed or state:
- Green: Connected (speed color-coded)
- Grey: Disconnected or Disabled
- Orange/Red: Error-disabled
It also displays PoE and LAG status icons per port. These indicators vary by model and capabilities – some support 10Gbps or 2.5Gbps, depending on the hardware.
Clicking on a port opens the configuration window. Here, users can:
- Enable or disable the port
- Assign it to a Link Aggregation Group (LAG)
- Choose Aggregation Type (Static or LACP)
- Set LACP priority and timeout behavior
- Apply a Port Profile
If LAG is enabled, the user configures a LAG Profile. If LAG is disabled, the user can assign a standard Port Profile. These profiles are preconfigured templates stored in the system to simplify port configuration across multiple devices or ports. Check Port Profile for more info.
If “Port Profile Override” is toggled on, the system ignores the assigned Port Profile and allows direct manual configuration of port behavior.
Port Profile configuration allows users to set advanced parameters such as LLDP-MED, Voice VLAN, rate control, and more. These profiles can be created once and applied across supported switch models, including Layer 2, Layer 2 lite, and Layer 3 switches.
If the switch is stacked, the user can toggle the view between all the stacked switches in the same page.

- Layer 2 Lite Switch – Debug
The Debug tab gives access to diagnostic tools, currently limited to Ping functionality. The tool allows the user to test network reachability for IPv4 addresses or domain names.
Enter the destination IP or domain, select the protocol type, and click “Run.” The results will show round-trip time, packet loss, and other network diagnostic info.
This is useful for confirming whether a device has connectivity to upstream devices or the internet.
- Layer 2 Lite Switch – Configuration
The Configuration tab allows users to customize device identity, location, and network behavior. Available fields include:
- Device Name
- Remarks
- Device Password (cloud-set password overrides local device password)
- Latitude and Longitude (can be manually entered or auto-filled if device is mapped)
- Total Power Input (W)
The Total Power Input value is critical for PoE stability. It should match the physical power supply connected to the switch. An incorrect setting may lead to ports not supplying power properly.
The lower section also includes IP Settings, where users can:
- Set static or dynamic IP addressing
- Enable Static DNS
- Specify Preferred and Alternate DNS Servers
This section ensures the device can reliably connect to the network and resolve domain names.

CLIENTS
From the clients page, the administrator can monitor and manage all the clients connected to the network/GWN devices. A list of all connected clients with their related information, such as connection type, IP Address, total bandwidth usage, associated devices (GWN AP, router, or switch), and more, will be displayed.
GDMS Networking allows administrators to customize the client information displayed for detected clients, including details such as Hostname, Connection status, SSID, BSSID, VLAN ID, IP Address, IPv6 Address, 802.1X Identity, Wi-Fi Band, total traffic usage, upload and download statistics, RSSI, link rate, associated devices, station mode, guest status, connection time, operating system, manufacturer, first seen timestamp, and last seen timestamp.
GDMS Networking also supports client batch configuration, allowing administrators to select and manage multiple clients simultaneously for more efficient client management and configuration operations across the network.
In addition, GDMS Networking supports client offline alarms and bandwidth usage alerts, allowing administrators to receive notifications when a client disconnects unexpectedly or when a client exceeds a specified bandwidth usage threshold. This helps administrators quickly detect abnormal behavior, monitor network usage, and improve overall network management and troubleshooting efficiency.
For more information about a client or related configuration settings, please click on the client entry or click on the configuration icon. Please refer to the figure below:
GDMS Networking also supports Client Type Identification and Classification, allowing administrators to distinguish connected clients based on their device category, such as PCs, tablets, smartphones, cameras, printers, TVs, and other device types.
The users also have the option to set an icon for the client from the predefined icons or add a new custom one, as shown below:
To add a custom icon, click on “Add New Type” as shown above, then upload the icon image and specify a name for it.
To make it easier to find specific clients, you can use the Client Type filter at the top of the Clients page to narrow down the list.
This filter allows you to display:
- Wired Clients to show only clients connected by Ethernet.
- Wireless Clients to show only clients connected through Wi-Fi.
- All SSIDs or a specific SSID to list wireless clients connected to that SSID.
- Blocked Client to show clients that are currently blocked.
- Locked Client to show clients that are locked to a specific access point.
The Clients page also supports filtering by Device Group. Use the All Device Groups drop-down list to show clients associated with devices in a specific device group, or keep All Device Groups selected to display clients from all groups. Click here to know more about Device Groups.
In the same way, users can filter clients by wired and wireless connections; they can also filter by time (calendar). Many options are available:
- Now Online: displays currently connected clients.
- By day: displays connected clients from a past day selected from the calendar.
- Last 1 day: displays connected clients of the last day.
- Last 7 Days: displays connected clients of the last 7 days.
- Last 30 days: displays connected clients of the last 30 days.
- Until Now: displays all connected clients until the current moment.
A lock icon is displayed next to the Access Point under the Associated Devices column to indicate that the connected client is locked to that specific AP. For more details, check Configure a Client.
Configure a Client
The Client Configuration tab allows users to customize settings for individual clients connected to the network. This includes blocking specific wireless clients, applying bandwidth restrictions, setting DHCP static IP assignments, and binding clients to specific Access Points (APs) with optional failover.
When a wireless client is selected, additional options are available:
- Client Blocking allows the administrator to block a wireless client from the network. This is applied via the Global Blocklist, which supports up to 1000 MAC entries. You can also specify whether the block is permanent (Always) or temporary.
- Lock to the Access Point allows binding the client to a specific AP. If enabled, the client will always connect to the assigned AP. An optional Failover Access Point can be set to provide redundancy in case the primary AP becomes unavailable.
- The View All APs with Lock Devices option provides a centralized list of all APs with locked clients, simplifying the process of tracking and managing client bindings.
When viewing locked client devices under View All APs with Lock Devices, users can quickly unbind a client from its associated Access Point by clicking the Unbind icon in the Operation column.
Field | Description |
Hostname | The name assigned to the client device. |
Client Blocking | Option to block the client device from accessing the network. Notes: Client Blocking and Lock to the Access Point can’t be enabled at the same time. Only applicable to wireless clients. Click on View Global Blocklist to view the Global Blocklist or add new one. |
Block Duration | Determines if the block is always or temporary. • Always: Will always block the client; • Temporarily: Blocks the client for a set period of time. Once the set duration is reached, the block automatically cancels. |
Duration | Specifies the duration for the temporary block (in days, hours, and minutes). |
Bandwidth Rules | Defines bandwidth rules applied to the client, select from the list or click on “Add New Bandwidth rule” to add a new one. Note: The bandwidth rule does not take effect on wired clients. |
DHCP Static IP address binding | Enables binding the client to a specific IP address within the network. |
VLAN | Specifies the VLAN to which the client is assigned. |
IP Address | The static IP address assigned to the client. |
Lock to the Access Point | Option to lock the client to a specific access point. Note: Client Blocking and Lock to the Access Point can’t be enabled at the same time. View All APs with Lock Devices: opens a list view of all access points with locked clients and their assigned failover APs. |
Access Point | Choose the primary AP the client will stay connected to. |
Failover for Lock to Access Point | Optional backup AP. If the primary AP fails, the client will connect to this failover AP. |
Client Configuration
Client usage
The Usage tab provides per-client bandwidth statistics and real-time rate monitoring. This is useful for reviewing network activity or diagnosing traffic-related issues per device.
Navigation: Clients → [Select a Client] → Usage Tab
- Real-Time View & Short-Term Usage
When Collect client historical data is disabled, the chart provides usage history over short timeframes only:
- Selectable ranges: 2 hours or 1 day
- Real-time Rate Graph: Continuously updates to reflect current bandwidth activity in Mbps
- Bandwidth Usage Graph: Displays total upload/download during the selected timeframe
- SSID Filter: View usage for a specific SSID or across all SSIDs
- Graph Tooltips: Hover over any point on the graph to view the upload/download at that time
- Enabling Historical Usage Tracking
If Collect client historical data is enabled, longer timeframes become available:
- Additional ranges: 1 week and 1 month
- Enables deeper usage analysis and bandwidth trend comparison over time
- A warning is displayed that enabling this will increase data storage usage
Client info
On this page, info about the current client will be displayed, showing the client’s Hostname, Client Status, IP Address, Current rate, etc.
Click on “Show more information” to get more info about the client.
GUESTS
Online Status
This page displays information about the clients connected via the Captive portal, including the MAC address, Hostname, Authentication Type, the device they are connected to, Certification state, SSID, as well as the RSSI and Data usage.
The administrator can also export a .csv file containing all the guest information (Client MAC address, Authentication Form when choosing Custom Field, Last Visit…etc) by clicking on the “Export” button, and selecting the export time period for all users who connected to the captive portal during that period.
Voucher
The Voucher system in GDMS Networking allows admins to generate one-time or multi-use access codes for guests to join Wi-Fi securely—ideal for hotels, events, cafés, campuses, or any scenario where temporary access is needed.
Voucher Groups can be generated manually or based on a Voucher Group Template, allowing you to quickly reuse common settings like device quota, duration, or bandwidth limits.
- Accessing the Voucher Page:
To begin voucher configuration:
- Navigate to
Guests → Voucher - This will bring up the voucher management screen
- Adding a New Voucher Group:
To add vouchers manually:
- Click Add Voucher Group
- Fill in the configuration form with the required parameters
| Name | Specifies the label or name for the voucher group. This helps administrators identify and manage the generated batch of vouchers. |
| Voucher Group Template | Enables the use of a predefined voucher template configuration. When enabled, the voucher settings will automatically reference the selected template data. |
| Quantity | Defines the number of vouchers to generate within this voucher group. |
| Voucher ID Length | Specifies the length of the generated voucher ID. The supported range is between 6 and 10 characters. |
| Voucher ID Format | Defines the format of the voucher ID by selecting whether the generated IDs contain numbers, letters, or a combination of both. |
| Device Quota | Specifies the maximum number of client devices allowed to use a single voucher simultaneously. |
| Duration | Defines how long the voucher grants network access once activated. The duration can be configured in days, hours, and minutes. |
| Maximum Upload Rate (Kbps) | Configures an optional maximum upload bandwidth limit for voucher users in Kbps. |
| Maximum Download Rate (Kbps) | Configures an optional maximum download bandwidth limit for voucher users in Kbps. |
| Byte Limit (MB) | Defines an optional traffic usage limit for the voucher. The byte limit can be applied either per voucher or per device. |
| Validity Time | Specifies the number of days the voucher group remains valid after being created. |
| Notes | Allows administrators to add internal reference notes or comments related to the voucher group configuration. |
Using Voucher Group Templates
You can toggle Voucher Group Template ON to auto-fill the voucher fields with a predefined configuration.
Templates help ensure consistency and save time when deploying large batches across different networks.
Once the template is created , it is shown as below:

By clicking the highlighted icon, the system will generate a new voucher list from the created voucher and use it as a template.
Important:
When the toggle is enabled, all relevant fields will auto-fill from the selected template. If disabled, you may edit all fields manually.
- Voucher Branding Options
To customize the printed/exported vouchers, click Voucher Settings on the voucher page.
You can upload a logo and define a slogan that will appear on the printed voucher layout.
- Managing Vouchers
After creating a voucher group, you’ll see it listed in the table. From the Operations column, you can:
- Download the voucher set as CSV
- Print vouchers for distribution
- Delete the batch if needed
Using the Voucher (Guest Access)
Once generated, vouchers are applied by assigning them to SSIDs configured with a Splash Page.
The Splash Page must be set to use Voucher login mode. When a guest connects, they’ll be prompted to enter a valid voucher code.
👉 For full setup of the Splash Page and guest portal options, see: Splash Page Configuration Guide
NETWORK TOPOLOGY
Network Topology shows an overview of the whole network, starting from the GWN Router or GCC Convergence device (Internet access), including GWN Switches and Access Points, as well as Clients. The administrator/monitor can have an overview of the network at a glance. By clicking on a GWN device or a Client, more information can be displayed.
Features overview:
- Display network layout.
- Visualize gateway, switch, access point, and connected client device information.
- The topology map can be zoomed in and out, and nodes are retractable; topology supports vertical/horizontal orientation.
- Support Mesh AP and also the option to highlight Mesh AP.
- VLAN information filtering.
Notes:
- Click on
to collapse that part of the network.
- Dashed lines mean wireless connection, while solid lines mean wired connection.
To backup the current topology or share it, on the top right corner of the page, click on the “Export” button, and a PNG image will be downloaded.
It’s also possible to change the topology orientation (vertically or horizontally), click on the orientation icon as shown below,
MAP & FLOOR PLANS
Map
With the Map feature, the administrators can link GWN devices or buildings to certain places on the Map, either manually on the Map or automatically using the device IP address, which will help to geolocate GWN devices or to link them to a different location (ex, company branch).
To place GWN Devices/Building on the Map, please navigate to Web UI → Map & Floor Plans (under Map tab). Please refer to the figure below:
Select “Building” or “Devices” and under “Unplaced” select the device/building, then click on the “Map” icon to manually place the GWN device on the map, or click on “Place on map” to be placed based on the IP address.


To remove the GWN device/building from the Map, please select the device/building and then click on “Remove from map“.

Floor Plans
The Floor Plans feature provides a convenient way to plan and deploy devices within a building to achieve optimal wireless coverage. Using the RF heat map preview, users can easily predict the best locations to deploy GWN devices, including both physical and virtual GWN access points, wireless routers, and wireless bridge devices.
For large deployments with multiple walls, glass partitions, and wide coverage areas, this feature helps deployment teams accurately determine the ideal placement of GWN devices to ensure reliable Wi-Fi coverage and an improved wireless experience for users.
Please navigate to Web UI → Map & Floor Plans → Floor Plans. Refer to the figure below.

Uploading a Floor Plan
- Click the “+” icon on the left side of the page to upload a floor plan image.
- After uploading the image, optionally add walls and dividers to simulate the building structure more accurately.
- Click the “+” button to create a custom wall or divider and configure custom attenuation values for both 2.4 GHz and 5 GHz signals.
- The system also supports AI Wall Detection, which can automatically identify walls and estimate wall types directly from the uploaded floor plan image to simplify and accelerate deployment planning.
After the AI placement process is completed, GDMS Networking will prompt the user to provide feedback regarding the generated deployment layout and device placement recommendations. This feedback mechanism helps improve future AI placement accuracy and overall deployment recommendations.
The walls and dividers available are:
| Wall / Divider Type | 2.4 GHz Attenuation | 5 GHz Attenuation |
|---|---|---|
| Gypsum Board (8 mm) / Foam Sheet (8 mm) / Wooden Door (40 mm) | 3 dB | 4 dB |
| Glass (8 mm) | 4 dB | 6 dB |
| Heavy Sheet Glass (12 mm) | 8 dB | 10 dB |
| Brick Wall (120 mm) / Solid Wood Door (40 mm) | 10 dB | 15 dB |
| Thick Brick Wall (240 mm) | 15 dB | 25 dB |
| Concrete (240 mm) | 25 dB | 30 dB |
Click on the “+” button as shown above to add a custom wall or a divider.
- Under devices, please select the GWN device either from adopted ones or virtual ones, then place it on the floor building accordingly, and it will display the label of the device. You can click on a device parameter icon, then configure the device name and wireless power accordingly. Many other tools and options can help the user to visualize the signal accurately, like rotating the floor plan, zooming in or out, centering the floor plan, etc. Please refer to the figure below:
Adding Devices to the Floor Plan
- Under Devices, select a GWN device from either the adopted devices list or the virtual devices list.
- Supported device types include:
- Access Points (AP)
- Wireless Routers
- Wireless Bridges
- Drag and place the device on the floor plan according to the intended deployment location.
- Click the device parameter icon to configure settings such as:
- Device name
- Wireless transmit power
- The system also supports AI Device Placement, which can intelligently recommend optimal device placement locations based on the floor layout and wireless coverage requirements.
- Additional tools are available to improve visualization accuracy, including:
- Rotate floor plan
- Zoom in / Zoom out
- Center floor plan
- Device positioning adjustments
Virtual Device Simulation
The Floor Plans feature also supports adding virtual GWN devices to help users simulate wireless coverage before performing the actual deployment. This allows administrators and deployment teams to preview device coverage ranges directly on the uploaded floor plan in real time.
Under the Devices section, users can select different categories of virtual GWN devices, including:
- Access Points (APs)
Multiple GWN AP models are supported and can be selected based on the deployment requirements and expected wireless coverage. - Wireless Routers
Different GWN router models can also be added as virtual devices to simulate router-based wireless coverage and placement. - Wireless Bridge
GWN wireless bridge model is supported as virtual devices and can be used to simulate point-to-point or point-to-multipoint wireless bridge deployments within the floor plan.
After selecting the desired device model, users can place the virtual device directly onto the uploaded floor plan. The system will then automatically display the estimated wireless coverage range and signal propagation in real time based on:
- Device type and model
- Wireless transmit power
- Floor plan dimensions
- Walls and divider attenuation
- 2.4 GHz and 5 GHz wireless bands
This feature allows users to better visualize deployment scenarios, optimize device placement, reduce coverage blind spots, and improve the overall wireless network planning process before installing physical devices.
AI Device Placement
The system also supports AI Device Placement, which intelligently recommends optimal device placement locations based on the uploaded floor plan, wireless coverage requirements, and detected environmental conditions.
Two deployment modes are available:
- System Selection
In this mode, the AI automatically selects the most suitable GWN device models for the deployment scenario. Based on the floor plan layout, coverage requirements, wall attenuation, and deployment area, the system will automatically determine the appropriate device types, placement locations, and the recommended number of devices required for optimal wireless coverage. - Custom Selection
In this mode, users can manually select their preferred GWN device models. The AI will then analyze the uploaded floor plan and automatically optimize the placement locations and calculate the recommended number of devices needed to achieve the best possible wireless coverage using the selected device model.
This feature greatly simplifies wireless planning and helps deployment teams achieve efficient and accurate network coverage while minimizing manual adjustments and deployment guesswork.

Export RF Planning Reports
The GDMS networking supports exporting detailed RF Planning Reports based on the configured floor plans and deployment simulations. Users can achieve this by clicking the highlighted Export RF Planning Report icon within the Floor Plans interface.
This feature allows users to generate professional reports containing important deployment information such as floor plan layouts, device placements, heat map coverage results, wall attenuation configurations, and wireless signal analysis.
Exported RF planning reports can be downloaded and used for deployment documentation, customer presentations, project validation, troubleshooting reference, and installation planning. This helps deployment teams and administrators easily review, share, and archive wireless planning results for future reference and optimization.
NETWORK HEALTH
Wi-Fi Health
Network Health Monitor is a feature that monitors the Wi-Fi general performance and coverage.
On the main page of the GDMS Networking, click on “Network Health” on the sidebar.
In the same page, the user can find the Key Performance Monitor, it shows the history of the network performance. The key monitors that are shown are Connection Time, Connection Success, Coverage, Roaming Performance, Capacity & Interference, Throughput, and Packet Transfer.



Site Survey
An integrated Wi-Fi Scanner is supported on GWN Management Platforms to help the administrator scan the wireless networks in the area and to display extensive information, including SSID’s name, AP’s MAC address, Channel used, Wi-Fi Standard, Bandwidth, security standard used, Manufacturer, RSSI, … and more.
Users can press the “Detect” button to run the Wi-Fi scanner or press the “Refresh” button to refresh the results page.
ALERTS
The Alerts page displays alerts about the network. The user can specify to display only certain types, like (System, Performance, Security, or Network), or the levels. To check the alerts that have been generated, please navigate to the Web UI → Alerts page.
The alerts can be displayed either by type or level. However, that is not the only way to display them. The user can filter through the alert log using a date interval or search by MAC address or device name.
- Alert Types
The available types are System, Performance, Security, and Network, or the user can choose to display all the types.
- Alert Levels
The user can filter the alert level by the following levels: All Levels, Emergency, Warning, or Notice.
- Read/Unread Alerts
The user can filter the alerts by: All or Unread.
Alert Settings
The Alert Settings page allows administrators to configure which system events will trigger notifications. Alerts are grouped into four categories:
- System Alert
- Performance Alert
- Security Alert
- Network Alert
Each alert type can be enabled or disabled independently. When selected, the system will notify users based on the defined conditions or thresholds.
System Alert
System Alerts notify administrators about general service or operational issues across routers, switches, and access points. These include device offline/online status, upgrade results, temperature issues, and alert exceptions.
Common examples include:
- Device offline/online for a specific duration
- Upgrade succeeded or failed
- Configuration sync failed
- Temperature or optical module warnings
- Device time deviation detection
Administrators can also exclude specific Access Points from offline alerts using the exception dropdown.
Performance Alerts
Performance Alerts focus on resource usage and traffic thresholds. These alerts are useful for proactively monitoring bandwidth, CPU, memory, and client count across your network devices.
Examples of performance thresholds include:
- Network or SSID throughput exceeded (Cloud-level)
- CPU or memory usage exceeded (Router/Switch/AP)
- Channel usage or client count thresholds
- WAN or port-level throughput exceeded
- Packet loss on switch ports
Each threshold can be customized using percentage or Mbps values.

Security Alerts
Security Alerts provide early warnings for potential attacks or rogue device detection. These events rely on enabling security features in advance.
Supported alerts include:
- Basic attack detected (e.g., DoS)
- Spoofing attack detected
- Rogue AP detected on the network
Network Alerts
Network Alerts report changes in port, RF, or client behavior across the network. This helps identify connectivity issues or disruptions at the physical and wireless levels.
Monitored conditions include:
- WAN/PPPoE failures or disconnections
- VPN tunnel and client status changes
- Port up/down status and PoE events
- Channel radar detection and RF activity
- Client authentication failures or wireless connection issues
These alerts provide deeper visibility into how devices and users interact with the network.

Alert Notification
The Alert Notification page is used to configure how alerts are delivered for the current account. You can add email recipients, configure a 3rd-party platform destination, and then enable the notification methods you want for each alert.
Alert notification settings are configured per account. Each account can choose which alerts to receive and which destinations to use (Web, Email, App, or a 3rd-party platform).
For platform-specific setup details (Wave, WhatsApp, Telegram, and Webhook), refer to the guide below: GDMS Networking Alert Notifications to Third-Party Platforms
At the top of the page, enter the Email Address values that should receive alert notifications. Use Add “New Item” to add additional email recipients.
Under 3rd-Party Platforms, select the destination type (Wave, WhatsApp, Telegram, or Webhook) and enter the required information for that platform (for example, Token). Once a 3rd-party destination is configured, you can enable alert forwarding by using the 3rd-Party Platform toggle in the alert list.
Alert delivery is configured per alert item. Select the alert category tab, then enable or disable the available notification methods for each alert under Notification Type (Web, Email, App, and 3rd-Party Platform).
SETTINGS
Wi-Fi
All Wi-Fi-related settings are available on this page. The page is organized into three sections: Wireless LAN, Global Radio Settings, and Mesh.
Wireless LAN
The Wireless LAN section lists the SSIDs configured under the current network and shows their main status at a glance (for example: whether the SSID is enabled, its VLAN ID, which band it uses, how many devices are online, the security type, and captive portal status).
To help you find the right SSID quickly, you can use the controls at the top of the list:
- Select device: filters the list to SSIDs related to a specific device (useful when you have many APs and only want to check what applies to one device).
- Search (Name/Remark/Device Group): lets you locate an SSID by its name, its remark/description, or the assigned device group.
- + Add: creates a new SSID.
Each SSID row also provides operation icons. Typically, you can:
- Click the gear icon to edit the SSID settings.
- Click the QR code icon to generate a QR code for the SSID.
- Click the trash icon to delete the SSID.
The QR code option is mainly used for faster sharing and onboarding. For example, you can display the QR code and let users scan it to join the Wi-Fi network (depending on device/OS support), or download the QR code image to share it through email or chat.
Below the Wireless LAN section, you will also find:
Global Radio Settings: manages radio parameters that apply across SSIDs and access points (for example global band behavior and transmit power).
Mesh: enables wireless mesh networking between supported access points, with options that help extend coverage when wired uplinks are not available.
Add SSID
To add a new SSID, navigate to Web UI → Settings → Wi-Fi page → Wireless LAN section then click the “Add” button. A new page will pop up, enter different settings to add a new SSID.
Basic | |
WiFi | Check to enable Wi-Fi for the SSID |
Name | Set or modify the SSID name. |
Remark | Optional label to help distinguish SSIDs, especially when multiple SSIDs use the same name. This label may be shown next to the SSID name in other pages (for example, SSID lists and SSID selection menus). |
Schedule | Select a schedule to control when the SSID is broadcast. Choose None to keep the SSID available at all times, or click Add New Schedule to create a new schedule. |
Client IP Assignment | Select between Bridge or NAT |
Associated VLAN | Check to Enable VLAN and enter VLAN ID, otherwise, this SSID will be using the default network group. |
Enable Captive Portal | Click on the checkbox to enable the captive portal feature. |
SSID Band | Select the Wi-Fi band the GWN will use, three options are available: |
Enable MLO | Allows the device to connect to multiple Wi-Fi bands (e.g., 2.4GHz + 5GHz and 6GHz) at the same time. Helps boost speed, reduce lag, and make the connection more stable. Requires compatible client devices. |
Access Security | |
Security Type | Set the security type, 5 options are available:
Note: When providing a WPA passphrase, you can enable the “Set Passphrase Reset Cycle” option. This feature allows the system to automatically rotate the Wi-Fi password at scheduled intervals, helping improve wireless network security and reduce long-term unauthorized access risks. |
802.11w | Disabled:disable 802.11w; Optional: either 802.11w supported or unsupported clients can access the network; Required: only the clients that support 802.11w can access the network. |
Access Control | |
MAC Filter | Controls access based on device MAC addresses. Choose Allowlist to only let approved devices connect, or Blocklist to keep specific ones out. If no list is selected while Allowlist is enabled, no clients will be able to connect. Note: The total number of MAC addresses across all blocklists is limited to 1000 entries. |
Client Isolation | Client isolation feature blocks any TCP/IP connection between connected clients to GWN76xx’s Wi-Fi access point. Client isolation can be helpful to increase security for Guest networks/Public Wi-Fi. Available modes are:
|
Client Time Policy | Configures the client time policy. Default is None. |
Bandwidth Control | Select Bandwidth Control (Per-SSID or Per-Client), then select from the Bandwidth rules previously created. |
Schedule | Select a schedule that will be applied to this SSID, schedules can be managed from the menu “Settings → Profiles → Schedule”. |
OS Filter | Whitelist or blacklist clients based on what OS they are using.
Warning: This feature requires certain client functionality to work, and some clients’ OS may not be supported. |
OS Whitelist/Blacklist | Note: this option is only availabe if OS Filter is enabled. Select one or more or All from the list below:
|
IP Source Guard | When enabled, clients using static IP addresses will be blocked from accessing the Internet. |
Device Assignment | |
Select from the Devices list the ones to be part of this SSID. Note: If an AP or router that uses the Wi-Fi network is selected, new APs will be automatically added to the network. | |
Advanced | |
SSID Hidden | Select to hide SSID. SSID will not be visible when scanning for Wi-Fi, to connect a device to hidden SSID, users need to specify SSID name and authentication password manually. |
Multi-VLAN | Multi-VLAN is useful for assigning different VLANs to different users, devices, or network segments on the same SSID to improve network segmentation, security, and traffic management. |
DTIM Period | Configures the frequency of DTIM (Delivery Traffic Indication Message) transmission per each beacon broadcast. Clients will check the AP for buffered data at every configured DTIM Period. You may set a high value for power saving consideration. |
Wireless Client Limit | Configure the limit for wireless client. If there’s an SSID per-radio on a network group, each SSID will have the same limit. So, setting a limit of 50 will limit each SSID to 50 users independently. 0 means limit is disabled. |
Client Inactivity Timeout | AP will remove the client’s entry if the client generates no traffic at all for the specified time period. The client inactivity timeout is set to 300 seconds by default. |
Multicast/Broadcast Suppression | Disable: all of the broadcast and multicast packages will be forwarded to the wireless interface. Enable: all of the broadcast and multicast packages will be discarded except DHCP/ARP/IGMP/ND; Enable with Proxy ARP enabled: enable the optimization with Proxy ARP enabled in the meantime. |
Convert IP multicast to unicast | Once selected, AP will convert multicast streams into unicast streams over the wireless link. Which helps to enhance the quality and reliability of video/audio stream and preserve the bandwidth available to the non-video/audio clients. |
Enable Voice Enterprise | Enable this feature to help clients connected to the GWN76xx to perform better roaming decision.
Note: 11R is required for enterprise audio feature, 11V and 11K are optional. Enable Voice Enterprise is only available under “WPA/WPA2” and “WPA2” Security Mode. |
Enable 802.11r | Check to enable 802.11r |
Enable 802.11k | Check to enable 802.11k |
Enable 802.11v | Check to enable 802.11v |
ARP Proxy | Once enabled, AP will avoid transferring the ARP messages to Stations, while initiatively answer the ARP requests in the LAN. |
Enable Bonjour Gateway | Click to enable Bonjour Gateway Note: If enabled, client Bonjour requests on SSID can be forwarded to the VLAN of Bonjour services (such as Samba). |
Enable U-APSD | Configures whether to enable U-APSD (Unscheduled Automatic Power Save Delivery) |
Target Wake Time | Enables TWT (Target Wake Time), a Wi-Fi 6/7 power-saving feature that lets the AP and clients agree on specific times to communicate. This reduces constant checking and helps compatible devices stay in low-power mode longer, extending battery life. Note: Only available on Wi-Fi 6/7 models. Not effective if Wi-Fi 5 compatibility mode is enabled. |
Add Wireless LAN
Global Radio Settings
On this page the Administrator can configure the global radio settings which will affect all the GWN devices with the wireless signal, it’s a convenient way to configure all the device’s wireless signal at once.
To configure a specific device (GWN AP or Wireless GWN router), navigate to Web UI → Devices, then click on the device or the configuration icon then select the Configuration Tab. Refer to the figure below:
Selecting the option “Use Radio Settings” from the drop-down list will use the settings configured on the Global Radio Settings section.
Please refer to the table below:
General | |
Band Steering | Select from the drop-down list, four options are available:
|
Client Steering | This feature will help Wi-Fi client to roam to other APs within same Network. Steering happens when clients is inactive or active clients with the standards 802.11K&V support. |
RSSI Threshold | It will start monitoring the RSSI for the clients in order to redirect them to another GWN AP in the same network. This prevents clients from remaining associated with AP with less than ideal RSSI, which can cause poor connectivity and reduce performance for other clients. Default is -75. |
Client Access Threshold | It will start monitoring the number of clients’ connections with the AP, once reaching configured threshold, it will roam to the other. Default is 30. |
Airtime Fairness | Allows faster clients to have more airtime than slower clients. |
Beacon Interval | Configures interval between beacon transmissions/broadcasts.
Notes:
Default value is 100ms. Valid range: 40 – 500 ms. |
Country/Region | Displays the country/region of the AP. |
2.4G/5G | |
Channel Width | Choose the Channel Width, note that wide channel will give better speed/throughput, and narrow channel will have less interference. 20MHz is suggested in very high-density environment. |
Channel | Select “Auto” or a Dynamically Assigned by RRM. Default is “Auto”. |
Custom Channel | Select a custom channels. Note: that the proposed channels depend on Country Settings under Settings → System. |
Radio Power | Set the Radio Power, it can be Low, Medium, or High or Custom or Dynamically assigned by RRM or Auto. Note : Dynamically assigned by RRM activates TPC and CHD:
Custom: allows users to set a custom wireless power for both 5GHz/2.4GHz band, the value of this field must be between 1 and 31. |
Enable Short Guard Interval | Check to activate this option to increase throughput. |
Allow Legacy Devices (802.11b) | Check to support 802.11b devices to connect the AP in 802.11n/g mode. (2.4GHz setting) |
Enable Minimum RSSI | Check to enable RSSI function, this will lead the AP to disconnect users below the configured threshold in Minimum RSSI (dBm). |
Minimum RSSI (dBm) | Enter the minimum RSSI value in dBm. If the signal value is lower than the configured minimum value, the client will be disconnected. The input range is from “-94” or “-1”. |
Enable Minimum Rate | Specify whether to limit the minimum access rate for clients. This function may guarantee the connection quality between clients and AP. |
Minimum Rate (Mbps) | Specify the minimum access rate. Once the client access rate is less than the specified value, AP will kick it off. Available values are: 1Mbps, 2Mbps, 5Mbps, 6Mbps, 9Mbps, 11Mbps or 12Mbps. |
Wi-Fi5 Compatible Mode | Some old devices do not support Wi-Fi6 well and may not be able to scan the signal or connect poorly. After turning on this switch, it will switch to Wi-Fi5 mode to solve the compatibility problem. At the same time, it will turn off Wi-Fi6 related functions. |
Global Radio Settings
Mesh
Wireless Mesh Network is a wireless extension of the traditional wired network using multiple access points connected through wireless links to areas where wired access is not an option while also expanding the coverage of the WLAN network.
In the traditional WLAN network, the uplink of the AP is a wired network (usually an Ethernet Link):
- The advantages of a wired network are security, anti-interference, and stable bandwidth.
- The disadvantages are high construction cost, long periods of planning and deployment, and difficulty of change in case a modification is needed.
However, these are precisely the advantages of wireless networks. As a result, a Wireless Mesh Network is an effective complement to wired network.
In addition, Mesh networking provides a mechanism for network redundancy. When an abnormality occurs in a wired network, an AP suffering the uplink failure can keep the data service continuity through its Mesh network.
For more details about the GWN Mesh Network feature, please don’t hesitate to read the following technical paper:
Users can set some Mesh Network parameters under the menu “Settings → Wi-Fi → Mesh”, as shown in the figure below:
| Enable Mesh | Enables Mesh networking functionality, allowing APs to communicate wirelessly with each other to extend wireless coverage without requiring a wired uplink connection. When enabled, the AP supports up to 5 SSIDs under the same VLAN. |
| Scan Interval (s) | Specifies how often the AP scans for neighboring Mesh devices and evaluates wireless backhaul connections. The configurable range is from 10 to 300 seconds. |
| Interface | Selects the wireless band used for Mesh communication. Available options include 2.4G, 5G, and 5G & 6G. The 6G option is only supported on certain models. For details, please refer to Device Comparison. The 2.4G option is only supported on APs; however, 2.4G channels are generally more susceptible to interference and instability, therefore their use is not recommended for Mesh backhaul deployments. |
| Wireless Cascade | Specifies the maximum allowed Mesh cascade level (hop count) between APs. Higher cascade levels allow Mesh connections to extend further across multiple APs. The supported range is from 1 to 3. |
Manually Configure Mesh Uplink
GDMS Cloud Networking allows administrators to manually control the mesh uplink of a meshed AP by specifying which AP should act as its CAP (Central AP). This provides greater control over the mesh topology and helps ensure that an RE (Remote AP) connects to an AP with a suitable signal strength.
The mesh uplink can be configured from Network Topology using either of the following methods:
Method 1: Configure the Uplink from the Uplink Tab
- In Network Topology, click the meshed AP whose uplink you want to configure. The selected AP is highlighted.
- Open the Uplink tab in the AP config/uration panel.
- Under Uplink Device, review the available APs detected as potential CAPs. The list displays the MAC address and RSSI of each detected AP.
- Select one of the following options:
- Automatically establish uplink: Allows the system to automatically select the CAP for the RE.
- Manually select an Uplink Device: Allows you to specify the AP that the RE should use as its CAP.
- When manually selecting the uplink, use the displayed RSSI values to identify an AP with a suitable signal strength.
- Click Save to apply the configuration.
Method 2: Configure the Uplink by Drag and Drop
- In Network Topology, locate the meshed AP.
- Drag the meshed AP and drop it onto the AP that you want to use as its CAP.
- A confirmation window appears displaying the selected Uplink Device.
- Verify the selected CAP and click Save.
- The meshed AP will update its mesh connection and establish the uplink through the newly selected CAP.
After either configuration method is applied, the RE disconnects from its current CAP and re-establishes the mesh connection with the newly selected CAP. The re-establishment process may take up to 15 minutes.
LAN
This page shows all the created VLANs as well as the Default VLAN (Default LAN), as well as the global switch settings that affect all the added GWN switches.
The user can click on “+Add” button to add a LAN/VLAN, then specify the name, VLAN ID, Gateway, and IPv4/IPv6. For more details please refer to the figure and table below:
Field | Description |
LAN Name | Name of the LAN/VLAN interface (1–64 characters). Used for internal reference. |
VLAN ID | Numeric VLAN ID used for tagging (2–4094). |
VLAN-Only Network | Enables VLAN-only (Layer 2) mode with no IP interface/routing on this VLAN. |
Gateway | Select the gateway device (Router, Switch, or Device Group) managed by GDMS Networking. |
Enable Captive Portal | Enables Captive Portal for this LAN so clients can be redirected to a portal for authentication/onboarding. |
Captive Portal Policy | Select the Captive Portal policy to apply when Captive Portal is enabled. |
IPv4 | Enables IPv4 addressing for this LAN interface. |
Gateway IPv4 Address/Prefix Length | Defines the gateway IPv4 address and subnet (CIDR format, e.g., 192.168.1.1/24). |
DHCP Service | Select DHCP Server, DHCP Relay, or Close (disable DHCP) for this LAN. |
IPv6 | Enables IPv6 addressing for this LAN interface. |
Interface ID | Auto-generates the IPv6 interface ID based on the selected MAC address (when enabled). |
Custom Interface ID | Manually set a specific IPv6 interface ID (when required). |
IPv6 Preferred DNS Server | Optional preferred DNS server for IPv6 clients. |
IPv6 Alternative DNS Server | Optional secondary DNS server for IPv6 clients. |
IPv6 Relay from WAN | Enables DHCPv6 relay from the WAN interface to this LAN (when applicable). |
IPv6 Address Assignment | Select how IPv6 addresses are assigned on this LAN (method depends on platform/device support). |
Add VLAN
Static IP Binding
GDMS Networking supports the Static IP Binding function, that allows administrators to centrally manage and assign fixed IP addresses to connected clients in a unified manner. This feature helps ensure that specific client devices always receive the same IP address from the network, which is especially useful for devices such as printers, cameras, servers, or other devices requiring stable and consistent network addressing for management and communication purposes.
The below options can be configured for each Static IP Binding
| VLAN | Selects the VLAN associated with the static IP binding entry. The client device will receive the assigned IP address within the selected VLAN network. |
| Hostname | Specifies a name or label for the client device. This helps administrators easily identify the device within the network. |
| Client MAC Address | Defines the MAC address of the client device that will be associated with the static IP assignment. The system uses this MAC address to identify the device and reserve the configured IP address for it. |
| IP Address | Specifies the static IP address that will always be assigned to the client device matching the configured MAC address. |
Switch Settings
Global Switch Settings allow the user to configure the general settings for all the GWN78XX switches which have been added to the account, instead of configuring the settings individually for each switch.
Radius Authentication | |
Radius Authentication | Select a Radius server or click Add New RADIUS |
Voice VLAN | |
Voice VLAN | Toggle voice VLAN on/off. |
Multicast | |
IGMP Snooping VLAN | Select the IGMP Snooping VLAN. |
MLD Snooping VLAN | Select the MLD Snooping VLAN. |
Unknown Multicast Message | Configures how the switch (IGMP Snooping/MLD Snooping) handles packets from unknown groups. |
DHCP Snooping Settings | |
DHCP Snooping | Toggle DHCP Snooping on/off |
802.1X | |
Guest VLAN | Configures whether to enable the guest VLAN function for the global port. |
Other | |
Jumbo Frame | Enter the size of the jumbo frame. Range: 1518-10000 |
Black Hole MAC Address | Select a Black Hole MAC Address from the list or click Add New MAC group |
Internet
Internet configurations like adding/configuring WAN ports or configuring Load-balancing/backup (Failover) between the WANs port are found here, please navigate to Web UI → Settings → Internet page.
WAN
In this section, the user can add WAN (router WAN port or a device group) or edit previously created WAN ports, and the number of WAN ports is determined by how many GWN routers are added/adopted to GDMS Networking/GWN Manager accordingly. Once, the WAN/Device group is added, then the user can monitor the network health for the last 12 hours.
Please navigate to Web UI → Settings → Internet page → WAN section.
- Network Health
Network Health is a feature that monitors the WAN (WAN ports or Device group) and displays the status for the last 12 hours for each WAN/device group with color code.
Hover with the cursor over the color to see more details like Packet loss percentage, duration etc.
Green: Online
Grey: Offline
Red: High Packets Loss
- Add or Edit a WAN/Device group
To edit a WAN click on the entry or click on the “Configure icon” under operation, and to add a WAN click on the “Add” button on the top of the page. on the next page, the user can configure the WAN name, router (WAN port or logical device group), physical port, connection type (DHCP, Static or PPPoE), MTU, DDNS, DMZ, UPnP, etc. Please check the figures and table below:
WAN Name | Specify a name for the WAN |
Router | Select a router or a Device group from the drop-down list |
Physical Port | Select the physical port (WAN port) from the drop-down list |
Connection Type |
The default setting is “Obtain IP automatically (DHCP)” |
Static DNS | Check Static DNS then enter the Preferred DNS Server and the Alternative DNS Server |
Preferred DNS Server | Enter the preferred DNS Server |
Alternative DNS Server | Enter the Alternative DNS Server |
Maximum Transmission Unit (MTU) | Configures the maximum transmission unit allowed on the WAN.
|
WAN Port MAC Address | Select from the drop-down list either to:
Default is “Use Default MAC Address” |
Custom MAC Address | Enter the custom MAC Address to be used with this WAN. |
Tracking IP Address 1 | Configures tracking IP address of WAN port to determine whether the WAN port network is normal. |
Tracking IP Address 2 | Add another alternative address for Tracking IP Address |
VLAN Tag | Select if either to enable or disable VLAN Tag. |
VLAN Tag ID | Enter the VLAN tag ID. |
Priority | Enter the priority Note: Range 0-7 and 7 is the highest priority |
Multiple Public IP Addresses | Please use with Port Forward function, so that you can access to router via public IP address. |
Public IP Address | Enter one or more public IP addresses Click on “+” icon or “–” icon to add or delete public IP addresses |
IPv6 | |
IPv6 | Enable this option to use IPv6 on this specific WAN. |
Connection Type | Select the connection type fromt the drop-list, three options are available:
The default setting is “Obtain IP automatically (DHCPv6)”. |
Static DNS | Enable this option to enter statically assigned DNS |
Preferred DNS Server | Enter the preferred DNS Server |
Alternative DNS Server | Enter the Alternative DNS Server |
IPv6 Relay to VLAN | Once enabled, relay IPv6 addresses to clients on the LAN side. Note: This function will take effect only “IPv6 Relay from WAN” is enabled on VLAN. |
Tracking IPv6 Address 1 | Configures tracking IP address of WAN port to determine whether the WAN port network is normal |
Tracking IPv6 Address 2 | Add another alternative address for Tracking IP Address |
DDNS | |
DDNS | Toggle ON or OFF the DDNS function, default is OFF Note: On the router, DDNS function can only be enabled on one WAN port. |
Service Provider | Select the DDNS provider from the list Note: Includes providers like no-ip.com, freedns.afraid.org, Oray, etc. |
Username | Enter the username for your DDNS account. Note: Required for third-party DDNS providers. |
Password | Enter the password for your DDNS account. Note: Required for third-party DDNS providers. |
Domain | Enter the domain registered with your DDNS provider. Note: Must match the domain you’ve set up with the DDNS provider. |
IP Source | Choose whether to use the WAN IP or Public IP for DDNS updates. Note: Select WAN IP to use in the same network segment. Public IP reflects external visibility. |
Update Interval (min) | Set how often the router updates the DDNS IP address. Note: Valid range is 1 to 1440 minutes. |
Cloud DDNS | Enable to use GDMS Networking’s built-in DDNS without an external provider. Note: No login required. Automatically generates a *.gwn.ai domain. |
Domain (Cloud DDNS) | Displays the generated gwn.ai domain name. Note: Read-only. Click ‘Update’ to regenerate the subdomain. |
IP Source (Cloud DDNS) | Choose WAN or Public IP for the cloud DDNS. Note: Same logic as standard DDNS affects domain resolution visibility. |
Update Interval (min, Cloud DDNS) | Set how frequently the router reports the IP to GDMS cloud. Note: Valid range is 1 to 1440 minutes. |
DMZ | |
Destination Group | Select the destination group from the drop-down list. |
UPnP | |
UPnP | Toggle ON or OFF the UPnP function, default is OFF Note: If UPnP (Universal Plug and Play) is enabled, devices on LAN can request the router to port forward automatically |
Destination Group | Select the destination group from the drop-down list. |
Add/edit a WAN
Internet Source
In this section of internet configuration, under internet source, the user can configure load balancing or backup (Failover) between the previously added WANs. Either click on the entry or “Configure icon” to edit previously added internet sources or click on the “Add” button to add a new one, refer to the figure below:

Here, the user can specify the name for the Load Balance or Backup, select the router/device group and specify the weight for each uplink.
- Default: If enabled, the subsequent WAN added by the router will be associated with the Internet Source
- Interface: In an Internet source, each interface can only be selected once, and only interfaces of the same router or the same device group are supported in an Internet source.
- Weight: Weight value determines the ratio at which connections are sent through each member. The default is 1. Enter a value from 1~10 with 10 being the highest weight.

Name | Enter the name of the Internet Source configuration. |
Router | Select the router to use. |
Mode | Select the mode of operation of the router.
|
Default | If enabled, the subsequent WAN added by the router will be associated with the Internet Source. |
Interface (Preferred Interface) | Select the preferred interface(s)
|
Alternative Interface | This option appears only when the mode is set to “Backup”.
|
Standby Interface | This option appears only when the mode is set to “Standby”. Select the interface to use when the other interfaces fail. The standby interface only takes effect when all primary interfaces fail. Note: Interfaces configured as standby will lose connectivity. |
VPN
GDMS Networking and GWN Manager support many VPNs including PPTP, IPSec (Site-to-Site), OpenVPN®, and WireGuard®.
GDMS Networking and GWN Manager support more than one GWN router with single or multi-WAN on the same network, thus when configuring a VPN it’s important to specify which router (WAN/Device group) and interface will be used.
- PPTP: supports client and server.
- IPSec (Site-to-Site): supports manual and auto mode.
- OpenVPN®: supports client and server.
- WireGuard®: server side.
Setup Wizard
The VPN Setup Wizard is a step-by-step assistant designed to help users configure VPN tunnels more easily and quickly. It supports four common protocols:
- OpenVPN®
- WireGuard®
- IPSec (Site-to-Site)
- PPTP
The wizard helps users choose the correct scenario (e.g., client-to-site or site-to-site), fill in the minimum required settings, and deploy the VPN configuration in fewer steps. This is useful for both first-time setups and fast testing environments.
To access the wizard: Navigate to Settings → VPN → Setup Wizard
Select a VPN Protocol
The wizard starts by letting you select a VPN type. Each has specific use cases and benefits.
Protocol Overviews:
- OpenVPN®:
Secure, open-source VPN protocol suitable for cross-platform connections (Windows, Mac, Android, iOS). Supports certificate-based authentication and is ideal for remote workforce access or site-to-site encryption over public networks. - WireGuard®:
Lightweight and modern protocol with fast setup and minimal overhead. Ideal for mobile users or low-resource devices. Supports quick configuration export for peers. - IPSec (Site-to-Site):
Enterprise-grade encryption standard. Suitable for building permanent tunnels between two fixed locations (e.g., HQ ↔ Branch). Supports dynamic IP updates and hardware acceleration. - PPTP:
Legacy protocol with broad compatibility. Easy to configure but not recommended for high-security needs. Best for internal or low-risk use cases.
OpenVPN® Configuration Wizard
Choose between:
- Client-to-Site – For remote users to connect securely to a central office.
- Site-to-Site – To connect two office networks over the internet.
Once selected, the wizard will guide through server selection, certificate management, and encryption options.
For advanced configuration, refer to OpenVPN® Manual Setup.
WireGuard® Configuration Wizard
WireGuard uses fewer parameters for faster setup. You’ll be prompted to:
- Name the connection
- Choose the router and WAN interface
- Assign the local IP and subnet
For advanced features like Peers and Remote Clients, refer to WireGuard® Manual Configuration.
IPSec (Site-to-Site) Wizard
Designed for secure office-to-office tunnels. Simply select the Site-to-Site mode, and the wizard handles tunnel basics like endpoint roles and tunnel IPs.
Why use this:
- Ideal for permanent, encrypted connections between two static sites
- Supports automatic rebuild after WAN IP changes
For detailed control and manual tuning, see IPSec Site-to-Site Setup.
PPTP Wizard
Choose:
- Client-to-Site – For basic remote user access
- Site-to-Site – For simple office-to-office bridging
PPTP is the easiest to set up, but less secure. Only use it in trusted environments or for quick internal access.
For more configuration options, refer to PPTP Setup.
To add a new VPN or a VPN user, please navigate to Web UI → Settings → VPN and then click on the “Add” button as shown in the figure below:
PPTP
PPTP is a data-link layer protocol for wide area networks (WANs) based on the Point-to-Point Protocol (PPP) and developed by Microsoft that enables network traffic to be encapsulated and routed over an unsecured public network such as the Internet. Point-to-Point Tunneling Protocol (PPTP) allows the creation of virtual private networks (VPNs), which tunnel TCP/IP traffic through the Internet.
The below figure shows the configuration for adding a PPTP Client, it’s also possible the say way to add a PPTP Server. When adding a PPTP Client make sure to specify the username and password as well.
Type | Select either PPTP Client or PPTP Server to configure. |
Name | Enter a name for the PPTP client. |
Status | Toggle ON or OFF to enable or disable the PPTP Client VPN. Note: PPTP Server: Once disabled, the PPTP service will also be disabled. |
Server Address | Enter the IP/Domain of the remote PPTP Server. |
Username | Enter the Username for authentication with the VPN Server. |
Password | Enter the Password for authentication with the VPN Server. |
Router | Select from the drop-down list the router/device group that this VPN will be using. |
Interface | Select from the drop-down list the exact interface of the router/device group. |
MPPE Encryption | Enable / disable the MPPE for data encryption. By default, it’s disabled. |
IP Masquerading | This feature is a form of network address translation (NAT) which allows internal computers with no known address outside their network, to communicate to the outside. It allows one machine to act on behalf of other machines. |
Maximum Transmission Unit (MTU) | This indicates the size of the packets sent by the router. Please do not change this value unless necessary. |
Remote Subnet | Configures the remote subnet for the VPN. The format should be “IP/Mask” where IP could be either IPv4 or IPv6 and mask is a number between 1 and 32. example: 192.168.5.0/24 |
VPN – Add PPTP Client
Type | Select either PPTP Client or PPTP Server to configure. |
Name | Enter a name for the PPTP Server. |
Status | Toggle ON or OFF to enable or disable the PPTP Client/Server VPN. Notes: Once disabled, the PPTP service will also be disabled. |
Server Local Address/Prefix Length | Specify the server local address with the prefix length |
Client Start Address | specify client start IP address |
Client End Address | specify client end IP address |
Router | Select from the drop-down list the router/device group that this VPN will be using. |
Interface | Select from the drop-down list the exact interface of the router/device group. |
MPPE Encryption | Enable / disable the MPPE for data encryption. By default, it’s disabled. |
LCP Echo Interval (sec) | Configures the LCP echo send interval. |
LCP Echo Failure Threshold | Set the maximum number of Echo transfers. If it is not answered within the set request frames, the PPTP server will consider that the peer is disconnected and the connection will be terminated. |
LCP Echo Adaptive |
|
Maximum Transmission Unit (MTU) | This indicates the size of the packets sent by the router. Please do not change this value unless necessary. By default is 1450. |
Maximum Receive Unit (MRU) | MRU indicates the size of the received packets. By default is 1450. |
Preferred DNS Server | specify the preferred DNS server. Ex: 8.8.8.8 |
Alternative DNS Server | specify the alternative DNS server. Ex: 1.1.1.1 |
VPN – Add PPTP Server
IPSec (Site-to-Site)
Internet Security protocol- IPsec is mainly used to authenticate and encrypt packets of data sent over the network layer. To accomplish this, they use two security protocols – ESP (Encapsulation Security Payload) and AH (Authentication Header), the former provides both authentications as well as encryption whereas the latter provides only authentication for the data packets. Since both authentication and encryption are equally desirable, most of the implementations use ESP.
IPsec supports two different encryption modes, they are Tunnel (default) and Transport mode. Tunnel mode is used to encrypt both payloads as well as the header of an IP packet, which is considered to be more secure. Transport mode is used to encrypt only the payload of an IP packet, which is generally used in gateway or host implementations.
GDMS Networking and GWN Manager support IPsec (Site-to-Site) that can help encrypt and secure traffic between two sites using two GWN routers. It supports manual configuration and auto mode.
Mode | Select the mode: Manual or Auto. Note: If Auto is selected, the LAN subnet and WAN IP will be automatically set to the peer router, and will synchronize automatically after the change, and the IPSec link will not be disconnected due to the change of WAN IP. |
Name | Specify a name for IPSec VPN. |
Status | Toggle ON or OFF to enable or disable the IPSec VPN. Note: Once disabled, the associated VPN services will also be disabled. |
Router | Select from the drop-down list the router/device group that this VPN will be using. |
Interface | Select from the drop-down list the exact interface of the router/device group. |
Peer | Set the IP address of the WAN port so the peer network automatically connects with the current network. |
VPN – Add IPSec auto mode
For the manual mode, please refer to the figure and table below:
General | |
Mode | Select the mode: Manual or Auto. Note: If Auto is selected, the LAN subnet and WAN IP will be automatically set to the peer router, and will synchronize automatically after the change, and the IPSec link will not be disconnected due to the change of WAN IP. |
Name | Specify a name for IPSec VPN. |
Status | Toggle ON or OFF to enable or disable the IPSec VPN. Note: once disabled, the associated VPN services will also be disabled. |
Remote address | Specify the remote IP address |
Router | Select from the drop-down list the router/device group that this VPN will be using. |
Interface | Select from the drop-down list the exact interface of the router/device group. |
Pre-shared key | Specify a pre-shared key |
Local Network | Set the local IP address and mask length of the protected traffic. Please enter an IP address or subnet (e.g., 192.168.122.0/24) |
Remote Network | Set the peer IP address and mask length of the protected data flow. Please enter an IP address or subnet (e.g., 192.168.122.0/24) |
Advanced Settings | |
IKE Version | Select from the drop-down list the IKE version: IKEv1 or IKEv2. |
IKE SA Lifetime (sec) | Specify the IKE SA Lifetime (sec), default is 28800. |
Local Source IP | Enter the local Source IP address. |
Local ID | Set the local ID to identify the identity of the local device for the remote device to verify its legitimacy. |
Remote ID | Set the remote ID to authenticate the identity of the remote device. This parameter must be consistent with the local ID set on the remote device. |
Negotiation Mode | Select the negotiation mode from the drop-list, two options are list: Main or Aggressive. |
Encryption Algorithm | Select from the drop-down list the encryption algorithm to use, the available ones are:
Default is AES-256 |
Hash Algorithm | Select from the drop-down list the Hash algorithm to use, the available ones are:
Default is SHA2-256 |
DH Group | DH (Diffie-Hellman) group, select from the drop-down list the DH group, available groups are Group 2,5,14,19,20,21. |
Reconnect | Set whether to renegotiate the connection when it is about to expire. |
Number of Reconnections | Specify the number of reconnections. Note: The range is 0-10. 0 means continuous attempts to negotiate a connection. |
DPD (Dead Peer Detection) | Toggle ON or OFF DPD. Note: DPD is a method that is used by devices to check for the current existence and availability of IPsec peers. |
DPD Delay Time (sec) | Set the delay time for connecting DPD keepalive packets. |
DPD Idle Time (sec) | Set the amount of time to remain idle if no response is received from the peer. |
DPD Action |
|
IPSec SA Lifetime (sec) | Specify the IPSec SA lifetime, default is 3600. |
ESP Encryption Algorithm | Select from the drop-down list the ESP Encryption Algorithm, the available ones are:
Default is AES-256. |
ESP Hash Algorithm | Select from the drop-down list the ESP Hash Algorithm, the available ones are:
Default is SHA2-256 |
PFS Group | Select from the drop-down list the PFS group, the available ones are: Group 2,5,14. Default is disabled. |
VPN – Add IPSec Manual mode
OpenVPN®
OpenVPN® is a virtual private network system that secures site-to-site or point-to-point traffic in routed or bridged configurations and remote access facilities. It supports both the client and server side.
GDMS Networking and GWN Manager support both OpenVPN® Client and Server side also certificates management for ease of use.
Type | Select the OpenVPN®: Client or Server |
Name | Enter a name for the OpenVPN® server. |
Status | Toggle ON or OFF to enable or disable the OpenVPN® Server. Note: Once disabled, the OpenVPN® service will also be disabled. |
Protocol | Choose the Transport protocol from the dropdown list, either TCP or UDP. The default protocol is UDP. |
Router | Select from the drop-down list the router/device group that this VPN will be using. |
Interface | Select from the drop-down list the exact interface of the router/device group. |
Local Port | Configure the listening port for OpenVPN® server. The default value is 1194. |
Authentication Mode | Choose the server mode the OpenVPN® server will operate with. 4 modes are available:
|
Encryption Algorithm | Choose the encryption algorithm from the dropdown list to encrypt data so that the receiver can decrypt it using same algorithm. |
Digest Algorithm | Choose digest algorithm from the dropdown list, which will uniquely identify the data to provide data integrity and ensure that the receiver has an unmodified data from the one sent by the original host. |
TLS Identicy Authentication | This option uses a static Pre-Shared Key (PSK) that must be generated in advance and shared among all peers. This feature adds extra protection to the TLS channel by requiring that incoming packets have a valid signature generated using the PSK key. |
TLS Identity Authentication Direction | Select from the drop-down list the direction of TLS Identity Authentication, three options are available (Server, Client or Both). |
TLS Pre-Shared Key | If TLS Identicy Authentication is enabled, enter the TLS Pre-Shared Key. |
Duplicate client certificates are allowed | Click on “ON” to allow duplicate Client Certificates |
Redirect Gateway | When redirect-gateway is used, OpenVPN® clients will route DNS queries through the VPN, and the VPN server will need to handle them. |
Push Routes | Specify route(s) to be pushed to all clients. Example: 10.0.0.1/8 |
LZO Compression Algorithm | Select whether to activate LZO compression or no, if set to “Adaptive”, the server will make the decision whether this option will be enabled or no. |
Allow Peer to Change IP | Allow remote change the IP and/or Port, often applicable to the situation when the remote IP address changes frequently. |
CA Certificate | Select a generated CA from the dropdown list or add one. |
Server Certificate | Select a generated Server Certificate from the dropdown list or add one. |
IPv4 Tunnel Network/Mask Length | Enter the network range that the GWN70xx will be serving from to the OpenVPN® client. Note: The network format should be the following 10.0.10.0/16. The mask should be at least 16 bits. |
VPN – Add OpenVPN® Server
Type | Select the OpenVPN®: Client or Server |
Name | Enter a name for the OpenVPN® Client. |
Status | Toggle ON or OFF to enable or disable the OpenVPN® Client. Note: Once disabled, the associated VPN services will also be disabled. |
Protocol | Specify the transport protocol used.
Note: The default protocol is UDP. |
Router | Select from the drop-down list the router/device group that this VPN will be using. |
Interface | Select from the drop-down list the exact interface of the router/device group. |
Local Port | Configures the client port for OpenVPN®.The port between the OpenVPN® client and the client or between the client and the server should not be the same. |
Remote OpenVPN® Server | Configures the remote OpenVPN® server. Both IP address and domain name are supported. |
OpenVPN® Port | Configures the remote OpenVPN® server port |
Authentication Mode | Choose the server mode the OpenVPN® server will operate with. 4 modes are available:
|
Encryption Algorithm | Choose the encryption algorithm. The encryption algorithms supported are:
|
Digest Algorithm | Select the digest algorithm. The digest algorithms supported are:
|
TLS Identity Authentication | Enable TLS identity authentication direction. |
TLS Identity Authentication Direction | Select the indentity authentication direction.
|
TLS Pre-Shared Key | Enter the TLS pre-shared key. |
Routes | Configures IP address and subnet mask of routes, e.g., 10.10.1.0/24. |
Deny Server Push Routes | If enabled, client will ignore routes pushed by the server. |
IP Masquerading | This feature is a form of network address translation (NAT) which allows internal computers with no known address outside their network, to communicate to the outside. It allows one machine to act on behalf of other machines. |
LZO Compression | Select whether to activate LZO compression or no, if set to “Adaptive”, the server will make the decision whether this option will be enabled or no. |
Allow Peer to Change IP | Allow remote change the IP and/or Port, often applicable to the situation when the remote IP address changes frequently. |
CA Certificates | Click on “Upload” and select the CA certificate |
Client Certificate | Click on “Upload” and select the Client Certificate. |
VPN – Add OpenVPN® Client
VPN User
In this section, the user can add a VPN user for either PPTP VPN or OpenVPN®. Please refer to the figure and table below:
Name | Enter a name for the user. This name will not be used to log in. |
Status | Enable or disable this account. |
Server Type | Choose the type of the server.
|
Server Name | Select the VPN server fromt the drop-list |
Username | Enter the username. This username will be used to log in. Note: only alphanumeric characters and @ ! $ % – _ are supported. |
Password | Enter the password. Note: only alphanumeric characters and @ ! $ % – _ are supported. |
Client Subnet | Set the IP address and mask length of the subnet for the client to access. Please enter an IP address or subnet (e.g., 192.168.2.0/24) |
Only if OpenVPN® is selected | |
Client Certificate | Select from the drop-down list the client certificate. |
VPN – Add VPN User
WireGuard®
WireGuard® is a free and open-source VPN solution that encrypts virtual private networks, easy to use, high performance and secure.
GDMS Networking and GWN Manager support WireGuard® as well, a Server local address can be specified while a private key can be generated with one click then after that the public key can be copied and shared with the client.
Name | Specify a name for Wireguard® VPN. |
Status | Toggle ON or OFF to enable or disable the Wireguard® VPN. |
Router | Select from the drop-down list the router/device group that this VPN will be using. |
Interface | Select from the drop-down list the exact interface of the router/device group. Note: one WAN only supports creating one WireGuard®. |
Listening Port | Set the local listening port when establishing a WireGaurd® tunnel. Default: 51820 |
Server Local Address/Prefix Length | Specify the server local address with the prefix length |
Private Key | Click on “One-Click Generation” text to generate a private key. |
Public Key | The public key will be generated according to the private key. Click on “Copy” text to copy the public key. |
MTU | This indicates the size of the packets sent by the router. Please do not change this value unless necessary. By default is 1450. |
VPN – Add WireGuard®
Once the Wireguad tunnel is created , the peers can be added as shown below:
| Add Type | Specifies how the WireGuard peer configuration will be created. Auto automatically generates WireGuard peer configurations for devices such as smartphones and computers, allowing the configuration to be downloaded or scanned via QR code from the Peer list. Manual allows administrators to manually configure the peer settings. |
| Name | Defines the name or label of the WireGuard peer. This helps administrators identify and manage the VPN peer connection. |
| Allowed IP | Specifies the IP address or subnet that is allowed to communicate through the VPN tunnel for this peer. A total of 8 Allowed IP entries can be added if needed. |
| Preferred DNS Server | Specifies the primary DNS server that will be assigned to the VPN peer when connected through the WireGuard tunnel. |
| Alternative DNS Server | Specifies a secondary or backup DNS server for the VPN peer connection. |
Traffic Management
On this page, the user can manage traffic by either adding static routes (IPv4 or IPv6) or adding Policy Routes.
Static Routes
Static routing is a form of routing by manually configuring the routing entries, rather than using a dynamic routing traffic for any service that requires a static address that never changes.
GDMS Networking and GWN Manager support setting manually IPv4 or IPv6 Static Routes which can be accessed from Web UI → Settings → Traffic Management page → Static Routes section.
All the Static routes either IPv4 or IPv6 will be listed here.
Click on button to add a static route, the user has the option between IPv4 or IPv6.
Policy Route
GDMS Networking and GWN Manager support managing more than one GWN router on the same network, with multiple GWN routers added, the user will have many internet sources, which will enable the user to specify which traffic can be forwarded to an internet source (Load Balance/Backup). Also, a schedule can be applied to this policy route to only be active based on the schedule selected.
Navigate Web UI → Settings → Traffic Management page → Policy route section and then click on the “Add” button to add a policy route, please refer to the figure below:
Name | Specify a name for the policy route |
Status | Toggle ON or OFF to enable or disable the policy route |
IP Family | IP Family, default is IPv4 |
Protocol Type | Select from the drop-down list the protocol type:
|
Router | Select from the drop-down list the router or the device group Note: for device groups, only router group is supported |
Source Group | Select the source group from the drop-down list |
Source IP Address/Mask Length | Set the source IP address and mask length of the packet to be matched. Please enter an IP address or subnet (e.g., 192.168.122.0/24) |
Destination IP address/mask length | Set the destination IP address and mask length to match the packet. For example, 192.168.122.0/24 |
Internet Source | Select the internet source (WAN/Load Balance/Backup) from the drop-down list |
Schedule | Select a schedule from the drop-down list or click on “Add New Schedule” to add one. |
Add Policy Route
QoS
The QoS (Quality of Service) feature allows administrators to manage and prioritize network traffic to ensure better bandwidth allocation and application performance across the network. Administrators can create Bandwidth Policies to control and filter traffic based on parameters such as IP addresses, ports, protocols, interfaces, and applications, while also defining traffic actions and DSCP priorities.
Below is a description for each configurable option:
| Type | Selects the QoS configuration type. Bandwidth Policy is used to create traffic matching and bandwidth control rules, while Bandwidth Channel is used to allocate guaranteed and maximum bandwidth for different priority levels. |
| Name | Specifies the name or label of the QoS policy for easier identification and management. |
| Status | Enables or disables the QoS policy. |
| Address Family | Defines the IP version used by the policy. Available options are Any, IPv4, or IPv6. |
| Protocol Type | Specifies the traffic protocol type the policy applies to. Available options include TCP/UDP, TCP, or UDP. |
| Router/Group | Selects the target router or device group where the QoS policy will be applied. |
| Source Interface | Specifies the source network interface from which the traffic originates. |
| Source IP Address/Prefix Length | Defines the source IP address or subnet range to match traffic for the QoS rule. |
| Source Port | Specifies the source port number or port range used for traffic matching. |
| Destination Interface | Specifies the destination network interface where the traffic is forwarded. |
| Destination IP Address/Mask Length | Defines the destination IP address or subnet range used for traffic matching. |
| Destination Port | Specifies the destination port number or port range for the QoS rule. |
| Application | Allows the administrator to match traffic based on specific applications or services. |
| DSCP Priority | Defines the DSCP priority level used for traffic classification and prioritization. |
| Action | Specifies the action applied to matched traffic. Permit allows the traffic normally, while Channel Rate Limit applies bandwidth limitation rules. |
| Rewrite DSCP | Allows administrators to rewrite or modify the DSCP value of matched packets for traffic prioritization purposes. |
| LAN IP Rate Limit | Enables LAN-side IP-based bandwidth rate limiting for matched traffic. |
| Schedule | Specifies a schedule during which the QoS policy will be active and enforced. |
In addition, the Bandwidth Channel feature allows administrators to allocate guaranteed and maximum uplink/downlink bandwidth values for different priority levels, helping ensure that critical services and applications receive sufficient network resources during periods of heavy traffic usage.
This feature is particularly useful for optimizing network performance, prioritizing important business applications, limiting non-critical traffic, and improving overall traffic management across supported GWN routers and device groups. Please refer to the options below for more information:
| Type | Selects the QoS configuration mode. Bandwidth Channel is used to allocate and manage bandwidth resources across different traffic priority levels. |
| Name | Specifies the name or label of the bandwidth channel configuration for easier identification and management. |
| Router/Group | Selects the target router or device group where the bandwidth channel configuration will be applied. |
| Uplink Guaranteed Bandwidth (Kbps) | Defines the minimum guaranteed upload bandwidth reserved for traffic managed by this bandwidth channel. |
| Uplink Max Bandwidth (Kbps) | Specifies the maximum allowed upload bandwidth for this bandwidth channel. Leaving the field empty means no bandwidth limit is applied. |
| Downlink Guaranteed Bandwidth (Kbps) | Defines the minimum guaranteed download bandwidth reserved for this bandwidth channel. |
| Downlink Max Bandwidth (Kbps) | Specifies the maximum allowed download bandwidth for this bandwidth channel. Leaving the field empty means no bandwidth limit is applied. |
| Channel Priority | Defines the bandwidth allocation and traffic priority levels used by the bandwidth channel configuration. Lower priority numbers represent higher traffic priority. |
| Priority | Specifies the traffic priority level, where 0 represents the highest priority and 7 represents the lowest priority. |
| Guaranteed Bandwidth Ratio (%) | Defines the percentage of guaranteed bandwidth reserved for the corresponding priority level. |
| Max Bandwidth Ratio (%) | Specifies the maximum percentage of bandwidth allowed for the corresponding priority level. |
| Rewrite DSCP | Allows administrators to rewrite the DSCP value for traffic matching the corresponding priority level to support traffic classification and prioritization across the network. |
Firewall and Security
The Firewall & Security page combines all configurations related to security and traffic control. It is divided into six main sections:
- Port Forwarding
- Wired Firewall Rules
- Wireless Firewall Rules
- Rogue AP
- Security Defense
- Advanced Security Settings
Click on any section to expand the list of rules or click the Add button to create a new configuration.
Port Forwarding
Port forwarding is redirecting the communication request from one address and port to another address and port. A source IP Address and port will be mapped to a Destination IP Address, port, and Group.
To add port forwarding, navigate to Web UI → Settings → Firewall & Security page → Port Forwarding tab.
Refer to the following table for the port-forwarding option when editing or creating a port-forwarding rule:
Name | Enter a name for the port forwarding rule. |
Status | Toggle on/off the rule status. |
Protocol Type | Select the transport protocol used.
|
Interface | Select the WAN port |
WAN IP Address | Enter the WAN IP address for Internet clients to access this server; if an interface is selected, leave this field blank and all IP addresses on that interface can be used for port forwarding. |
Source Address Type | Select the address type that will be entered
|
Source Address | Sets the IP address that external users access to this device. If not set, any IP address on the corresponding WAN port can be used |
Source Port | Set a single or a range of Ports. |
External Port | The service port that the router provides to the WAN. External users obtain services by sending requests to this port. You can enter a port number or a range of ports (e.g. 5-23). |
Internal IP Address | Set the The IP address of the network host acting as the server in the LAN IP address. |
Internal Port | The service port provided by the router to the local network, i.e. the LAN service port. If the source port is entered in a range, the destination port must also be entered in a range, and the port range difference must be consistent (for example, the source port can be entered as 10-20, and the destination port can be entered as 11-21, and the port range difference is 10). |
Port Forwarding
Wired Firewall Rules
Wired Firewall Rules allow administrators to control traffic through the GWN devices using various rule types. Administrators can define rules to allow, deny, drop, or manipulate traffic based on source/destination, protocol, port, and more. These rules are essential for managing inbound and outbound network security and routing behavior.
To configure Wired Firewall Rules, navigate to:
Web UI → Settings → Firewall & Security → Wired Firewall Rules tab
Four rule types are supported:
- Inbound Rules – Control incoming traffic to the network
- Forwarding Rules – Define how traffic is passed across network interfaces
- SNAT Rules – Rewrite the source address for outgoing packets
- DNAT Rules – Rewrite the destination address for incoming packets
Click the + Add button to configure a new rule.
Inbound Rules
Inbound Rules control traffic entering the router from external networks. These rules are typically used to allow or restrict access to services hosted within the internal network.
You can define rules based on:
- Source group, MAC, IP, port
- Destination IP and port
- Protocol type
- Router and IP family (IPv4/IPv6)
- Action to take: Accept, Reject, or Drop
Field | Description |
Type | Select the type of firewall rule. For this setup, choose ‘Inbound Rules’. |
Name | Enter a descriptive name for the rule (1–64 characters). Example: Inbound Rule. |
Status | Toggle this switch to enable or disable the rule. |
IP Family | Choose the IP version to match traffic: Any, IPv4, or IPv6. |
Protocol Type | Select the protocol to filter traffic. Options: TCP, UDP, UDP/TCP, ICMP, IGMP, ALL. |
Router | Select a router group. Only router groups are supported for rule application. |
Source Group | Choose the WAN or VLAN group where traffic originates from. |
Source MAC Address | Optionally define a MAC address to narrow the rule scope. Leave blank for all MACs. |
Source IP Address/Mask Length | Specify the originating IP or subnet. Example: 192.168.122.0/24. |
Source Port | Optional. Use commas for multiple ports or ranges. Example: 4, 5-10. |
Destination IP Address/Mask Length | Define where traffic is headed. Example: 192.168.1.0/24. |
Destination Port | Optional. Use commas for multiple ports or ranges. Example: 80, 1000-2000. |
Action | Choose how to treat matching traffic: – Accept: Allow – Reject: Deny with response – Drop: Deny silently |
Add Inbound Rule
Forwarding Rules
Forwarding Rules define how traffic is relayed across internal interfaces. These are typically used to manage routing decisions between LAN segments or VLANs within the network.
Field | Description |
Type | Select the type of the firewall rule. In this case, ‘Forwarding Rules’. |
Name | Enter a name to identify the forwarding rule (1–64 characters). |
Status | Toggle the rule on or off. |
IP Family | Select the IP version: IPv4, IPv6, or Any. |
Protocol Type | Choose the type of traffic to control: TCP, UDP, UDP/TCP, ICMP, IGMP, or ALL. |
Router | Select the router or router group this rule applies to (only router groups are supported). |
Source Group | Select a source group such as a WAN or VLAN. If set to ‘All’, more specific rules take priority. |
Source MAC Address | Optionally specify a source MAC address to match. |
Source IP Address/Mask Length | Define the source IP or subnet (e.g., 192.168.122.0/24). |
Source Port | Specify individual ports or ranges using commas (e.g., ‘4, 5-10’). |
Destination Group | Required: Select the destination group, such as WAN or VLAN. |
Destination IP Address/Mask Length | Set the IP/subnet range targeted by the rule (e.g., 192.168.122.0/24). |
Destination Port | Specify destination ports or ranges (e.g., ’80, 1000-2000′). |
Action | Choose how to handle matching traffic: Accept (allow), Reject (deny with response), or Drop (silently discard). |
Add Forwarding Rule
SNAT (Source NAT) Rules
SNAT Rules allow the router to rewrite the source IP address of outbound packets. This is typically used for hiding internal IP addresses behind a public IP when accessing external services.
Key configuration points include:
- Source IP and rewrite source IP
- Source and destination port mapping
- Destination group
SNAT ensures that return traffic can be routed correctly back to the originating device by modifying the source IP.
Field | Description |
Name | Enter a name for the SNAT rule (1–64 characters). |
Status | Toggle to enable or disable the SNAT rule. |
IP Family | Select IPv4 (currently the only supported type). |
Protocol Type | Choose the applicable protocol: TCP, UDP, UDP/TCP, ICMP, IGMP, or ALL. |
Router | Select the router or router group the rule applies to. Only router groups are supported. |
Source IP Address/Mask Length | Specify the original source IP or subnet of the outgoing traffic (e.g., 192.168.1.0/24). |
Rewrite Source IP Address | Enter the new IP address that will replace the original source IP. |
Source Port | Optionally define the original source port(s) or port range(s), comma-separated (e.g., 80, 1000-2000). |
Rewrite Source Port | Optionally enter the new source port(s) that should replace the original ones. |
Destination Group | Select the destination group (WAN/VLAN). |
Destination IP Address/Mask length | Optionally define the destination IP or subnet for filtering purposes (e.g., 10.1.1.0/24). |
Destination Port | Optionally enter destination ports or port ranges to apply SNAT only to certain services. |
Add SNAT
DNAT (Destination NAT) Rules
DNAT Rules allow the router to rewrite the destination IP address of incoming traffic. This is commonly used for port forwarding to internal hosts.
You can configure:
- Source conditions (group, IP, port)
- Destination group and IP
- Rewrite destination IP
DNAT is essential for exposing internal services to the outside world while preserving internal addressing.
Field | Description |
Type | Select DNAT to configure destination network address translation. |
Name | Enter a name for the DNAT rule (1–64 characters). |
Status | Toggle to enable or disable this rule. |
IP Family | Select IPv4 for DNAT rules (IPv6 is not supported for this rule type). |
Protocol Type | Choose the protocol to match traffic (e.g., TCP, UDP, UDP/TCP, ICMP, IGMP, ALL). |
Router | Select the router or router group where this rule will apply. |
Source Group | Select the source group (WAN or VLAN) for matching incoming traffic. |
Source IP Address/Mask Length | Enter source IP or subnet to match (e.g., 192.168.1.0/24). |
Source Port | Define the original port or port range for the match (e.g., 80, 8000-8080). |
Destination Group | Choose the destination group (WAN or VLAN). |
Destination IP Address/Mask length | Specify the original destination IP address or subnet to match. |
Rewrite Destination IP Address | Enter the internal IP to which the traffic will be redirected. |
Destination Port | Original port(s) for matching the destination (e.g., 443, 1000-2000). |
Rewrite Destination Port | Enter the new port(s) for redirecting the matched traffic. |
NAT Reflection | Toggle to enable NAT reflection (loopback) for internal access via external IP. |
NAT Reflection Source | Choose whether the NAT reflection source is ‘Internal’ or ‘External’. |
Add DNAT
Wireless Firewall Rules
This section is located under Web UI → Settings → Firewall & Security page → Wireless Firewall rules tab, it does allow users to control the outgoing and incoming traffic from clients connected to the adopted/paired GWN devices by manually setting up policies to either deny or permit the traffic for wireless traffic based on protocol type and by specifying SSIDs and destinations.
Type | Select the type of the firewall rule: Inbound rules or Outbound rules |
Name | Enter a name for the wireless firewall rule. |
Service Protocol | Select the Service protocol type from the drop-down list. |
Policy |
|
Source | Select the source, it can be from a Particualar IP or Network then enter the IP and/or the subnet. Note: this option is only available when the type selected is Inbound rules. |
Destination | Select the destination, it can be from a Particualar IP, Network or Domain. then enter the IP/Domain and/or the subnet. |
SSID | If All is selected, this rule will also be applied to new SSIDs (Wireless LAN). Note: this option is only available when the type selected is Outbound rulesl |
Add Wireless Firewall Rules
Rogue AP
GDMS Networking and GWN Manager offer the ability to prevent malicious intrusion into the network and increase the wireless security access of clients when introducing the Rogue AP detection feature to the adopted/paired GWN devices. The detected devices will be listed with all the details under the “Alerts” page for further intervention.
Navigate to Settings → Firewall & Security page → Rogue AP section, The below figure shows the configuration page to enable Rogue AP detection.
Enable Rogue AP Detection | Select to either to enable or disable Rogue AP scan. |
Detect Range | Specify the rogue AP detect range.
Default is Same Channel. |
Countermeasure Level | Countermeasures level specifies the type of attacks which will be
Default is Disabled. |
Containment Range | Specify the containment range:
Default is Same Channel. |
Sub-string for Spoofing SSID | The AP broadcasting SSID with the specified string will be classified as a Spoofing SSID. |
Trusted AP | You can specify MAC address of the trusted AP, which should be |
Untrusted AP | You can specify MAC address of the untrusted AP, which should be formatted as XX:XX:XX:XX:XX:XX. If an AP is defined as untrusted AP, countermeasures will be executed on it when countermeasure is enabled. |
Rogue AP
Security Defense
The Defense Configuration features under Firewall & Security enhance the security posture of GDMS Networking-managed devices by providing protection against common network attacks such as DoS (Denial of Service), Flooding, Port Scanning, and Spoofing.
These settings allow administrators to fine-tune real-time defense behavior with flexible thresholds and control mechanisms to mitigate malicious traffic and spoofing attempts before they affect network performance or availability.
Navigate to: Settings → Firewall & Security → Security Defense
Basic Attack Defense
The Basic Attack Defense tab allows enabling protection against several types of network flood and scan attacks, with options to configure exception rules by IP address and set custom blocking thresholds and durations.
Main Controls
- Basic Attack Defense: Enables or disables all attack defense features globally.
- IP Exception: Allows specific IP addresses to bypass defense rules.
Flood Attack Defense Types
- SYN Flood Attack Defense: Blocks excessive TCP SYN requests, commonly used in DoS attacks.
- UDP Flood Attack Defense: Blocks high volumes of UDP traffic.
- ICMP Flood Attack Defense: Protects against excessive ICMP ping requests.
- ACK Flood Attack Defense: Detects and blocks suspicious TCP ACK packet floods.
Each rule includes:
- Status Toggle: Enable or disable defense.
- Blocking Threshold (pps): Packets per second allowed before triggering the block.
- Blocking Duration (s): Duration in seconds that traffic is blocked after threshold is exceeded.
Scan Attack Defense
- Port Scan Defense: Detects and blocks traffic patterns that indicate port scanning activity.
- Blocking Threshold (packets/m): Limit of packets per minute.
- Blocking Duration (s): Block time after detection.
Abnormal Packet Attack Defense
Enables blocking for specific unusual or malformed packet types. Checkboxes allow you to selectively enable protection for:
- IP Option
- TCP Flag
- Land Attack
- Smurf
- Fraggle
- Ping of Death
- Trace Route
- IP Fragment
- Unassigned Protocol Numbers
- SMAC=DMAC
- Large ICMP Packet Control
Spoofing Defense
The Spoofing Defense tab provides advanced protection against address spoofing threats, such as forged IP or MAC addresses used to disguise malicious actors on the network.
Features:
- Spoofing Defense: General toggle to enable spoofing countermeasures.
- ARP Spoofing Defense: Prevents manipulation of ARP responses to poison network address resolution.
How it works:
When enabled, GDMS verifies the consistency of the source and destination MAC addresses in the Ethernet frame and ARP header. If mismatches are detected, the ARP packets are discarded to protect against spoofing and ARP poisoning. Additionally, VRRP MAC addresses will not be added to the ARP table when this feature is active.
Notes:
- All defense rules are device-level settings managed through GDMS Networking and must be configured per network needs.
- Thresholds should be carefully set to balance security and network stability.
- These defense mechanisms are especially valuable for public-facing networks or deployments with heightened security requirements.
Advanced Security Settings
ALG stands for Application Layer Gateway. Its purpose is to prevent some of the problems caused by router firewalls by inspecting VoIP traffic (packets) and if necessary modifying it.
To configure ALG, navigate to Web GUI → Settings → Firewall & Security page → Advanced Security Settings tab.
PROFILES
Portal policy
The policy configuration page allows adding multiple captive portal policies which will be applied to SSIDs and contains options for different authentication types a splash page that can be easily configured as shown in the next section.
Each SSID can be assigned a different captive portal policy, for example, company ABC could have a specified Wi-Fi for staff people who can access via a portal policy requiring a user username and password for authentication and another SSID for guest people who can sign in via their Facebook account; also, they could assign either an internal or external Splash page.

Internal Splash Page
Please refer to the table below when configuring the Internal Splash Page.
Name | Enter the name of the Captive Portal policy |
Splash Page | Select Splash Page type, Internal or External. Note: this table is only about internal splash page. |
Client Expiration | Configures the period of validity, after the valid period, the client will be re-authenticated again. |
Client Idle Timeout | Specify the idle timeout value for guest network connection. Once timed out, guest should re-authenticate for further network use. Note: this option is not applicable to voucher guests and payment guests. |
Timeout Duration of Unauthenticated Clients (minutes) | Set the timeout time for unauthenticated clients. After the timeout, unauthenticated client devices are disabled from using Wi-Fi. |
Failsafe Mode | Once enabled, guest can access internet when the authentication server or external portal is unreachable. Note: only the Radius, custom field and Voucher authentications support this feature. |
Daily Limit |
|
Splash Page Customization | Select a splash page from the drop-down list or click “Add New Splash Page“. |
Landing Page | Choose the landing page, 2 options are available:
|
Enable HTTPS Redirection | Check to enable/disable HTTPS service. If enabled, both HTTP and HTTPS requests sent from stations will be redirected by using HTTPS protocol. And station may receive an invalid certification error while doing HTTPS browsing before authentication. If disabled, only the HTTP request will be redirected. |
Enable Secure Portal | If enabled, HTTPS protocol will be used in the communication between STA and AP. Otherwise, the HTTP protocol will be used. |
Pre Authentication Rule(s) | |
Destination | Defines which destinations can be reached before authentication.
|
Service | Defines which services can be reached before authentication.
|
Post Authentication Rule Type |
|
Post Authentication Rule(s) | |
Destination | Destination can be either IP Address, Hostname or Subnet/Prefix |
Service |
|
Portal Policy – Internal Splash Page
External Splash page
Please refer to the table below when configuring the External Splash Page.
Name | Enter the name of the Captive Portal policy |
Splash Page | Select Splash Page type, Internal or External. Note: this table is only about external splash page. |
Platform | Select the Radius Authentication Method provided by external portal platform. |
If Linkyfi, Purple or Universal Platform is selected | |
External Splash Server Address | Enter the External Splash Page URL, and make sure to enter the pre-authentication rules request by the external portal platform in the pre-authentication configuration option. |
RADIUS Authentication | Select a RADIUS from the drop-down list or click on “Add New Radius“. |
If Aiwifi platform is selected | |
URL Pre-shared Key | The configuration will be used to generate the signature. Please enter 20-32 characters, support entering numbers, English, characters (excluding spaces) |
Timeout Duration of Unauthenticated Clients (minutes) | Set the timeout time for unauthenticated clients. After the timeout, unauthenticated client devices are disabled from using Wi-Fi. |
External page | Please enter the Redirect URL provided by external portal platform. |
Enable HTTPS Redirection | Check to enable/disable HTTPS service. If enabled, both HTTP and HTTPS requests sent from stations will be redirected by using HTTPS protocol. And station may receive an invalid certification error while doing HTTPS browsing before authentication. If disabled, only the HTTP request will be redirected. |
Pre Authentication Rule(s) | |
Destination | Defines which destinations can be reached before authentication.
|
Service | Defines which services can be reached before authentication.
|
Post Authentication Rule Type |
|
Post Authentication Rule(s) | |
Destination | Destination can be either IP Address, Hostname or Subnet/Prefix |
Service |
|
Portal Policy – External Splash Page
Splash page
Splash page allows users with an easy-to-configure menu to generate a customized splash page that will be displayed to the users when trying to connect to the Wi-Fi.
On this menu, users can create multiple splash pages and assign each one of them to a separate captive portal policy to enforce the selected authentication type.
The generation tool provides an intuitive “WYSIWYG” method to customize a captive portal with a very rich manipulation tool.
Users can set the following:
- Authentication type: Add one or more ways from the supported authentication methods:
For Free | Clients can log in without authentication. |
Simple Password | The user can specify a password that clients must enter to authenticate. Note: Simple passwords support all characters except spaces. |
Radius Server | Authentication using a RADIUS server. |
Voucher | Authentication using a Voucher code. |
Custom Field | Collects guest information using a customizable form before granting network access (not credential-based authentication).
|
Authentication using Email. | |
SMS | Authentication using SMS, with Twilio or Amazon SMS Service Provider. |
Active Directory | Authentication using Active Directory. |
SAML SSO | Authentication using SAML Single Sign-On (SSO) through an external identity provider (IdP). |
Authentication using Facebook account. | |
X | Authentication using X account. |
Authentication using Google account. |
Splash page – Authentication types
- Set up a picture (Company Logo) to be displayed on the splash page.
- Customize the layout of the page and background colors.
- Customize the Terms of Use text.
- Visualize a preview for both mobile devices and laptops.
Advertisement
On this page, advertisements can be enabled and forced on each access point, where users will be forced to view media content (images or videos) before being granted access to the network.
Click on the “Add” button to add media content (images or videos) then specify the “Force to watch duration” (in seconds).
Rotation: when there are many media contents, the user can specify the rotation (Random, Regular interval, or Regular time), then the preset time can be specified.
WiFi4EU
Once enabled, the top area of the splash page will display the information about WiFi4EU. The language can be set as well as the Network UUID.
Self-test modus: A WiFi4EU supplier can test if the snippet is correctly installed and if its portal is compliant by enabling the snippet self-test modus.

Port Profile
Port profiles are a convenient way to provision a GWN device (ex: GWN switches) interfaces easily. Name a profile then select the relevant configurations, like VLAN, Rate, Speed limit, LLDP, etc. Also for security, we can enable Storm control, Port Isolation, Port Security, and 801.1X Authentication.
To create a new Port Profile or edit an existing one, please navigate to Web UI → Settings → Profiles page → Port Profile section.
General | |
Profile Name | Specify a name for the profile. |
Native VLAN | Select from the drop-down list the native VLAN (Default LAN). |
Allowed VLAN | Check the allowed VLANs from the drop-down list (one VLAN or more). |
Voice VLAN | Toggle ON or OFF Voice VLAN. Note: Please first enable the Voice VLAN in the Global LAN Settings. |
Rate | Specify the rate (port speed) from the drop-down list. |
Duplex Mode | Select the duplex mode:
|
Flow Control | When enabled, if congestion occurs on the local device, the device sends a message to the peer device to notify it to stop sending packets temporarily. After receiving the message, the peer device stops sending packets to the local device. Note: When duplex mode is “Half-duplex”, the traffic control does not take effect. |
Enable Port STP | Toggle ON or OFF the Port STP. |
Incoming Speed Limit | Toggle ON or OFF the incoming speed limit. |
CIR (Kbps) | Configures the Committed Information Rate, which is the average rate of the traffic to pass through. |
Outbound Speed Limit | Toggle ON or OFF the outbound speed limit. |
CIR (Kbps) | Configures the Committed Information Rate, which is the average rate of the traffic to pass through. |
LLDP-MED | Toggle ON or OFF the LLDP-MED. |
Network Policy TLV | Toggle ON or OFF the network policy TLV. |
Security | |
Storm Control | Toggle ON or OFF storm control. |
Broadcast | Toggle ON or OFF Broadcast and then specify the control trhreshold (pps = packet per second). |
Unknown Multicast | Toggle ON or OFF Broadcast and then specify the control trhreshold (pps = packet per second). |
Unknown Unicast | Toggle ON or OFF Unknown Unicast and then specify the control trhreshold (pps = packet per second). |
Port Isolation | Toggle ON or OFF port isolation. |
Port Security | Toggle ON or OFF port security. Note: after enabled, start MAC address learning including the dynamic and static MAC addresses. |
Maximum number of MACs | Specify the maximum number of MAC addresses allowed. Note: after the maximum number is reached, if a packet with a non-existing source MAC address is received, regardless of whether the destination MAC address exists or not, the switch will consider that there is an attack from an illegal user, and will protect the interface according to the port protection configuration. |
Sticky MAC | Toggle ON or OFF Sticky MAC. Note: after enabled, the interface will convert the learned secure dynamic MAC address into Sticky MAC. If the maximum number of MAC addresses has been reached, the MAC addresses in the non-sticky MAC entries learned by the interface will be discarded, and whether to report a Trap alert is determined according to the port protection configuration. |
802.1X Authentication | Toggle ON or OFF 802.1x authentication. |
User Authentication Mode | Select the user authentication mode from the drop-down list
|
Method | Select the method from the drop-down list. |
Guest VLAN | Toggle Guest VLAN ON or OFF. Note: Enable the Guest VLAN in the Global LAN Settings first. |
Port Control | Select the port control from the drop-down list:
|
Re-authentication | Configures whether to enable re-authentication for the device connected to the port. |
Add port profile
Once the Port profile is added the user can apply it on a GWN device/device group ports (ex: GWN switches).
Under the Devices page, select the relevant device, and under the Port tab, select the ports then apply the Port Profile on these ports. please refer to the figure below:
Mac Groups
The MAC Group feature in GDMS Networking allows administrators to define and manage groups of MAC addresses for use in authentication and access control policies across APs, routers, and switches. This centralized approach helps streamline the configuration of MAC-based authentication and improves consistency across the network.
You can assign a MAC Group to SSID settings, switch port policies, and access lists for granular client control. Each MAC Group can include multiple MAC address entries, each representing an individual device.
Navigation: Go to Settings → Profiles → MAC Groups
Create a MAC Group
To create a new MAC Group:
- Click Add on the MAC Group page.
- Enter a Group Name.
- Add MAC addresses to the list using the Add MAC button.
- Optionally, use the CSV import function for bulk entry.
- Click Save.

MAC Groups can be applied in various contexts depending on the device type, here are some examples:
For Access Points (GWN APs), MAC Groups can be selected under SSID settings using the MAC Authentication field (Blocklist). This allows or denies client access based on the MAC address.
For Switches (GWN78XX), MAC Groups can now be applied directly to port policies through MAC Authentication.
For Routers, MAC Groups may be referenced in various policy rules (depending on model and use-case), allowing consistent centralized access control across device types.
Bandwidth Rules
The bandwidth rule is a platform feature that allows users to limit bandwidth utilization per SSID or client (MAC address or IP address).

Schedule
A schedule can be created here to be applied in many places like rebooting or LED for example.
RADIUS
This page allows the user to add a RADIUS to be used in Portal policy or Wi-Fi security for example.
Private Pre-Shared Key (PPSK)
PPSK (Private Pre-Shared Key) is a way of creating Wi-Fi passwords per group of clients instead of using one single password for all clients.
To configure PPSK, please navigate to Web UI → Settings → Profiles → PPSK, then click on the “Add” button to add a new PPSK Group.

Give the PPSK Group a name, and after that click on the “Add” button to add a new PPSK.
When generating PPSKs automatically, set Number of PPSKs to define how many PPSK entries will be created in the selected PPSK group. You can also set Max Num of Access Clients to limit how many client devices are allowed to be online using the same PPSK.
This is the result of the above configuration: 300 PPSKs have been created, each allowing up to 512 access clients. If the email was added then click on the Email icon to send the credentials in the email, if it was not pre-configured before you will be prompted to enter the email first.
It’s also possible to manually assign a Wi-Fi password for a number of clients.
Refer to the table below for a description of each field:
Field | Description |
Account Name | Name/identifier for this PPSK entry (used to distinguish PPSKs within the PPSK group). |
Wi‑Fi Password | The pre-shared key that clients will use to connect. You can enter it manually or use One‑Click Generation to create one automatically. |
One‑Click Generation | Generates a random Wi‑Fi Password for this PPSK entry. |
Max Num of Access Clients | Maximum number of client devices allowed to be online using this same PPSK at the same time (range: 1–512). |
MAC | Optional MAC binding. When Max Num of Access Clients is set to 1, you can bind a MAC address so only that device can use this PPSK. If the PPSK is used from a different MAC address, that device cannot access the SSID. |
Bandwidth Control | Enable/disable per‑PPSK bandwidth limits. When enabled, Upload Limit and Download Limit become available. |
Upload Limit (Kbps) | Maximum upload throughput allowed for clients using this PPSK (shown in Kbps). |
Download Limit (Kbps) | Maximum download throughput allowed for clients using this PPSK (shown in Kbps). |
VLAN | Optional VLAN ID applied to traffic from clients using this PPSK (valid range: 2–4093, excluding 666). |
Email Address | Optional recipient email. If provided, GDMS will email the PPSK credentials (e.g., Account Name, Wi‑Fi Password, Max Num of Access Clients) to the end user after saving. |
PPSK – Manual
Another way is to upload a CSV file, please download the reference template.

Now, the user can apply this PPSK group to any SSID, refer to the figure below:
- Exporting PPSK Entries
Administrators can now easily export all PPSK entries within a PPSK group for backup, audit, or sharing purposes.
To export PPSKs:
- Navigate to Settings →
Profiles → PPSK - Locate the PPSK group you want to export
- Click the Download icon in the Operation column
This will download a CSV file containing all configured PPSKs, including key assignments and user labels (if defined).
Certificates
In this section, the user can create CA, Client, and Server certificates that can be used with OpenVPN either for the client or server side.
The user can either click on the “Add” button to add a new certificate or click on the “Import” button to import them from his local machine to the GDMS Networking or GWN Manager.
This page will be shown after clicking on the “Add” button, then the user can select between a CA Certificate or a Certificate which can be either for a Server or a Client based on the option “Certificate Type“. Please refer to the figures and tables below:
Type | Select the type of certificate either CA Certificate or Certificate. |
Name | Enter the certificate’s name. |
Key Length | Choose the key length for generating the CA certificate.The following values are available:
|
Digest Algorithm | Select the digest algorithm.
Note: Hash is a one-way function, it cannot be decrypted back. |
Expiration (D) | Select the duration of validity of the certificate. The number entered represents the days that have to elapse before the certificate is considered as expired. The valid range is 1 – 999999. |
SAN | Enter the address IP or the domain name of the SAN (Subject Alternate Name). |
Country/Region | Select a country from the dropdown list of countries. Example: “United States of America”. |
State/Province | Enter a state name or a province. Example: California |
City | Enter a city name. Example: “San Diego” |
Organization | Enter the organization’s name. Example: “GS”. |
Organization Unit | This field is the name of the department or organization unit making the request. Example: “GS Sales”. |
Enter an email address. Example: “EMEAregion@grandstream.com” |
Profiles – Add CA Certificate
Type | Select the type of certificate either CA Certificate or Certificate. |
Name | Enter the certificate’s name. |
CA Certificate | Select from the drop-down list the CA Certificate previously created. |
Certificate Type | Select the certificate type either a server or a client certificate. |
Key Length | Choose the key length for generating the CA certificate.The following values are available:
|
Digest Algorithm | Select the digest algorithm.
Note: Hash is a one-way function, it cannot be decrypted back. |
Expiration (D) | Select the duration of validity of the certificate. The number entered represents the days that have to elapse before the certificate is considered as expired. The valid range is 1 – 999999. |
SAN | Enter the address IP or the domain name of the SAN (Subject Alternate Name). |
Country/Region | Select a country from the dropdown list of countries. Example: “United States of America”. |
State/Province | Enter a state name or a province. Example: California |
City | Enter a city name. Example: “San Diego” |
Organization | Enter the organization’s name. Example: “GS”. |
Organization Unit | This field is the name of the department or organization unit making the request. Example: “GS Sales”. |
Enter an email address. Example: “EMEAregion@grandstream.com” |
Profiles – Add Certificate (Client or Server)
Client Time Policy
The administrator can configure a Time policy that will dictate how much a client connects to the Wi-Fi if this policy is applied for the SSID.

| Enable Time Policy | Check/Uncheck to Enable/Disable Policy |
| Name | Enter a name to identify the Policy. Supports 1 to 64 characters, including numbers, letters, and special characters. |
| Validity Time | Configure the policy duration from 1 minute to 365 days. |
| Reset Cycle | Set up a Reset mode: Daily, Weekly, or Periodically |
| Reset Time | When the Reset Cycle is Daily: configure the time of the day. When the Reset Cycle is Weekly: configure the time and the day of the week When the Reset Cycle is Periodic: configure the period (d//h/m) |
| Time Zone | Detected Automatically. This parameter can be changed under System Settings |
Hotspot 2.0
Hotspot 2.0, also known as HS2.0 or Passpoint, is a set of industry specifications developed by the Wi-Fi Alliance to improve the connectivity and user experience of Wi-Fi networks, particularly in public places. The goal of Hotspot 2.0 is to make Wi-Fi connectivity as seamless and secure as cellular networks.
Key features of Hotspot 2.0 include
- Automatic Authentication: Hotspot 2.0 enables automatic and secure connection to Wi-Fi networks without user intervention. Devices can automatically connect to Wi-Fi hotspots, similar to how cellular networks work.
- Seamless Roaming: With Hotspot 2.0, users can roam between different Wi-Fi networks without having to re-authenticate. This is especially useful in environments with multiple Wi-Fi access points, such as airports, shopping malls, and other public spaces.
- Passpoint: Passpoint is a specific implementation of Hotspot 2.0 that allows mobile devices to automatically discover and connect to Wi-Fi networks that are part of the Passpoint ecosystem. Passpoint provides a streamlined and secure connection process, making it easier for users to connect to Wi-Fi hotspots.
Hotspot 2.0 is particularly relevant in environments where reliable and secure Wi-Fi connectivity is essential, such as airports, hotels, and other public spaces. It improves the overall user experience by making Wi-Fi connectivity more like cellular connectivity, with automatic authentication and seamless roaming.
SYSTEM
General
Navigate to Web UI → Settings → System → under General to configure General settings like Country/Region, Time zone, Time, LED, Reboot Schedule, etc.
Country/Region | Select the country or region from the drop-down list. This can affect the number of channels depending on the country standards. |
Timezone | Configure time zone for GWN APs. Please reboot the device to take effect. |
Auto Sync Time | If enabled, all managed devices’ system times will be synced with GWN Cloud |
AP Login Password | Sets the APs login password with up to 8 characters. Alphanumeric characters and special characters – _ | are supported |
Device Password | Set the devices SSH remote login password other than APs (Routers and Switches), which is also the device web login password. |
LED | Select whether to always turn ON or OFF the LEDs on the APs or apply a schedule for this function. |
Reboot Schedule | Once scheduled, the current network will not work for a while during the scheduled period. |
Enable Client Connection Event | When enabled, then Client connects/disconnects events are listed under Devices → GWN device → Info page. |
Subscribe to Client Historical Data | Enabling collect the data of historical bandwidth usage for all clients in the network. Note: this will cause the storage usage increase. |
Presence API | Onced enabled, will detect and collect wireless device info. near the AP, which can be used for device positioning, pedestrian flow monitoring and so on. |
Bluetooth API | When enabled, Bluetooth client information detected near select Wi-Fi-enabled APs will be automatically collected. See API details for more information. |
Automatically add to SSIDs | If enabled, newly added GWN APs and wireless routers will be automatically provisioned for all SSIDs. |
System page – General
URL Access Log
The URL Access Log section allows administrators to configure how client browsing activity logs are stored, grouped, and exported. This feature helps with traffic analysis, domain grouping, and scheduled email reporting of access logs. Logs can be stored on the GDMS server and emailed periodically to designated recipients.
The platform System will send these logs via Email to the configured Log Receiver in the form of a downloadable link providing a CSV file format containing all the website logs visited for each client during the defined period (daily, weekly, or monthly basis).
To enable this feature, follow the below steps: navigate to “Settings → System page → URL Access Log section” and enable the URL Access Log field.
Refer to the figure and table below for more details:
Field | Description |
Log Storage | Select where to store the URL access logs. Options include ‘Do not Store’ and ‘GDMS Server’. When GDMS Server is selected, logs are stored centrally. |
If Log Storage is set to GDMS Server | |
Export URL Access Log | Toggle to enable or disable exporting of URL access logs. When enabled, a download link is sent based on the configuration. |
Export Immediately | Manual trigger to export URL logs immediately when the toggle is enabled. |
Group Metric by Main Domain | Toggle to group statistics by the main domain instead of subdomains. |
Customized Top-level Domain | Specify custom TLDs to be merged for traffic stats (e.g., .us.com). Default TLDs like .com are merged automatically. |
Email Frequency | Set how often the log export link will be sent to the specified recipient(s). Options may include Daily, Weekly, Monthly. |
URL Log Receiver | Specify one or more recipient email addresses to receive the exported log reports. Required field. |
If Log Storage is set to Remote Syslog Server | |
Remote Syslog Server Address | The Remote URL Log Server feature allows administrators to automatically forward and store URL access logs on an external remote server instead of relying only on local device storage. This enables long-term log retention, centralized log management, and easier monitoring or auditing of network activity beyond the default local storage period. Support for this feature depends on the device model. For supported models, please refer to About → Device Comparison. |
Protocol | Selects the protocol used for remote syslog communication, two options are available, UDP and TCP. |
URL Access Log
In this example, the administrator will start receiving, every week, an Email containing a downloadable link providing a CSV file containing the websites visited by the clients during the last day.
Users can click on “Export Immediately”, and then specify the time range of the URL Access Log during the last (1 – 30) days to be exported immediately.

5. Click on the “Export” button and notice the success confirmation message:

- Click the highlighted link to Download the log file and save it locally.
Once downloaded, administrators will have a CSV file tracking the Internet activity for all the clients connected to the paired GWN devices.
The CSV file will contain columns displaying the AP MAC address, the client’s hostname as well as the device MAC address, the Source and Destination IP, the URL logs, the HTTP Method (GET/POST), and the time of request.

Guest Information
If enabled, the cloud server will periodically send out the log download link based on the configured email settings. To enable this feature, follow the below steps:
- Go under “Settings → System page → Guest Information section“ and enable the Guest Information field.
- Choose to set the Email Frequency to be generated either on a daily, weekly, or monthly basis.
- Configure the Email Receiver.
NAT pool
Users can use this feature to set an address Pool from which the clients that are connected to the adopted/paired devices will acquire their IP address in that way GWN devices will act as a lightweight router.
Navigate to Web UI → Settings → System page (NAT Pool section), to configure the Gateway, DHCP Server Subnet Mask, DHCP Lease Time, and DHCP Preferred/Alternate DNS.
SNMP
This section lists the SNMPv1, SNMPv2c, and SNMPv3 options available to integrate the adopted/paired GWN devices with enterprise monitoring systems.
Users can enable the SNMP feature under Web UI → Settings → System page (SNMP section).
SNMPv1, SNMPv2c | Enable Enable SNMPv1/SNMPv2c. |
Community String | Enter the SNMP Community string. |
SNMPv3 | Enable SNMPv3. Note: If the SNMPv3 function of the switch is required to work, SNMPv1 and SNMPv2c should be enabled at the same time. |
Username | Enter the SNMPv3 username. |
Authentication Mode | Set the Authentication mode to: either MD5 or SHA. |
Authentication password | Enter the SNMPv3 authentication password. |
Privacy Mode | Set the Privacy mode to: either AES128 or DES. Note: AES128 mode is only for routers and APs. Switches use DES mode. |
Privacy password | Enter the privacy password. |
SNMP
Syslog
The Syslog Capture section provides flexible options for collecting system logs from selected devices (Access points, Routers, Switches…). Admins can choose between using a Cloud Syslog Server managed by GDMS, or a Local Syslog Server within their private network. Logs can be filtered by severity, and captures can be scheduled for specific durations and devices.
To enable this feature, follow the below steps: navigate to “Settings → System page → Syslog section“.
Refer to the figures and table below for more details:
Field | Description |
If Syslog Server is set to Cloud Syslog Server | |
Syslog Server | Select the syslog server mode. Options: ‘Cloud Syslog Server’ or ‘Local Syslog Server’. |
Syslog Level | Select the severity of logs to capture. Levels include None, Emergency, Alert, Critical, Error, Warning, Notice, Information. |
Syslog Capture Expiration | Set duration (in days, hours, minutes) for capturing logs. Capture will stop automatically upon expiration. |
Devices | Select one or more devices (e.g., AP, Router) to capture system logs from. TCP protocol is not supported for switches. |
Client | Select a specific client device (by MAC or name) to capture its logs. |
Syslog Capture | Click this button to start the syslog capture for the selected duration and devices. |
If Syslog Server is set to Local Syslog Server (extra fields) | |
Local Syslog Server Address | Enter the IP address of the local syslog server (e.g., 192.168.5.10). |
Protocol | Select the protocol (UDP or TCP) used for forwarding logs to the local syslog server. |
Syslog
ORGANIZATION
Overview
Network Overview
The Network Overview page (under Organization → Overview) provides a centralized view of your networks, device status, client counts, and alerts. It also includes tools to organize networks using tags and to access advanced functions such as Network Management.
Top Summary Panel
At the top of the page, GDMS Networking displays high-level totals for the deployment, including the number of Networks and Administrators, online/offline status for Routers, Switches, and APs, total Clients (wired and wireless), and an Alert overview (Emergency/Warning/Notice). This provides a quick snapshot of system status before drilling into a specific network.
Network Tags
Network tags help categorize networks for easier organization and filtering (for example, separating support, documentation, or testing environments). Tags are managed from the Network Overview page.
Click Network Tag to open the tag management window. From here, you can add new tags, remove existing ones, and save changes. After tags are created, they can be applied when creating or editing a network and later used for filtering.

Unassigned Devices and Filtering
The Unassigned Device indicator shows how many devices have been added to GDMS Networking but are not assigned to any network. Click this indicator to open the assignment workflow.
You can also filter the network list from the same area. Use the organization selector to switch between organizations (the network list updates based on your selection), and use Select Network Tag to filter networks by tag.
Network List Indicators and Actions
The Network List displays summarized information for each network. The default network is labeled accordingly, and networks with active notifications/alerts may display an icon for quick identification.
Use the Operation actions on each network row to manage networks directly. These shortcuts provide access to tasks such as editing network configuration, sharing a network, or deleting it (based on your account permissions).
Network Management
Click Network Management to open the management view, where networks are grouped under their corresponding organizations. This view supports multi-organization deployments and helps separate networks by tenant/customer.
From this page, you can create networks using the + icon and manage organization structure (such as adjusting organization order, depending on permissions).
Add Network
From Network Management, click the + icon to create a new network. When creating a network, you must assign it to an Organization, which helps keep networks properly separated and supports later operations such as moving networks between organizations.
On the Add Network page, select an existing organization or choose Add New Organization. Then enter the network details such as Network Name, Country/Region, and Time Zone, and assign Administrator(s) if needed. Optional settings include Clone Network, enabling Default Network, and assigning Tag(s). Click Save to create the network.
Move Network to Another Organization
GDMS Networking allows moving a network from one organization to another. This is useful when reorganizing tenants/customers or correcting where a network was initially created.
Select the network and click Move, then choose the destination organization and confirm.
Share Network
Networks can be shared from Network Overview. When sharing a network, select the appropriate permission level such as Co-management, Transfer Management, or Read-only Privilege, then choose who to share with and save the configuration.
To remove a network, click Delete and confirm. Use this option carefully, especially in multi-organization environments.

Location Overview
The Location Overview page provides a real-time geographic visualization of all network devices associated with your GDMS Networking organization. It consolidates device locations across all networks into a single interactive map view, offering a high-level operational snapshot.
This view supports device-level status indication, allowing administrators to quickly identify online/offline devices.
To access the Location Overview: Navigate to Organization → Overview → Location Overview tab.
Key Feature: Global Device Visibility
- The Location Overview shows all devices from all networks under the organization.
- Devices are represented as map pins:
- Green Pins: Device is online and accessible via GDMS Networking.
- Red Pins: Device is offline or currently unreachable.
- Devices include: Access Points, Routers, Switches, and GCC (Grandstream Cloud Controller) devices.
Map Component Settings:
Users can choose between Open Street Map and Google Maps as the underlying map component.
To change the map view:
- Click on the “Map Component” button on the top-right of the map.
- In the Map Component Settings popup, select the desired map type.
- Google Map (requires a valid Google Maps API key)
- Open Street Map (default)
Inventory
The Inventory section under Organization → Inventory allows users to manage all Grandstream devices registered to their GDMS Networking account.
Devices in the Inventory are claimed meaning they are associated with your organization and cannot be claimed by another GDMS account. This protects ownership and prevents duplicate configuration.
Devices can be:
- Claimed directly into the Inventory (without assigning to a network)
- Added directly to a network (which also claims them automatically)
- Removed from networks, but still remain in Inventory
- Deleted only if unassigned from all networks
The user can click on the “Export” button to export a CSV file containing all the GWN devices.
- Filtering Options
To simplify device management, the Inventory view includes multiple filtering tools. These filters help administrators locate devices quickly and perform actions at scale.
Available Filters:
- Connection Status
- All devices
- Online only
- Offline only
- Assignment Status
- Devices currently assigned to a network
- Devices unassigned and available for deployment
- Device Model
- Filter by specific hardware model (e.g., GWN7660, GWN7813P)
- Search Field
- Search by MAC address
- Device name
- Serial number
- Assigned network
These filters can be combined to refine results even further.
Claim Devices or Import
- Claim Device: to claim a device (GWN device MAC address and Password is required) even if the GWN device is offline, it will not be assigned to any network.

- Assign Device: to assign the device to the network (it will added to the selected network).

- Export: to export a CSV file containing all the GWN devices.
- Delete: to delete a device from the GWN management platform.
Reseller Channel
Reseller Channel will be able to support the establishment of the hierarchy agent partnership, retrieve device from ERP, and assign device to network groups or channels/agents:
- Support first-level channel or agent to bind the ERP ID and sync the device.
- Support assigning/returning/reclaiming device to network or associated company.

The user can designate the associated network directly on the CVS file.

ISP Locking
The ISP Locking feature in Grandstream GDMS Cloud allows administrators and Internet Service Providers (ISPs) to lock specific router configurations to ensure deployment consistency and prevent unauthorized modifications. Administrators can lock settings such as default passwords, SSIDs, WAN configurations, and other critical network parameters across managed routers.
GDMS Networking also supports Universal Configuration, allowing administrators to create and apply standardized configuration templates across multiple supported devices and deployments, helping simplify large-scale provisioning and maintain configuration consistency.
Prerequisites
- The router must be assigned to a network within GDMS Cloud.
- Additional privileges are required to enable this feature on your GDMS account.
To configure ISP Locking, navigate to Organization → Inventory, then click on “More” after that click on “ISP Locking“. Refer to the figure below for a visual guide:
To add a new router, click the “Add” button. To configure an existing router, click the “Configure” icon.
Fill in the required details in the “Configure ISP Locking” form, which includes the default password, WAN configuration (including VLAN Tag), and SSID information (such as SSID name and password).
Users
User Management allows the administrators to create multiple accounts for different users to log in to the platform. There are 6 base different access levels to monitor and manage GWN devices, it’s also possible to create a custom role with custom privileges.
- Super Administrator (the initial administrator)
- Platform Administrator
- Platform Administrator (Read Only)
- Network Administrator
- Network Administrator (Read Only)
- Guest Editor
Add New User
To add a new user, navigate to Organization → Users → User page, then click on the “Add” button to create a new user. Administrators can specify the nickname, email address, assigned role, and the networks that the user is allowed to access across all regions. There is also an option to enable multi-factor authentication (MFA) and automatically add the user to newly created networks.
GDMS Networking supports multiple administrator roles with different permission levels to provide flexible access control and management capabilities:
- Platform Administrator: Grants read/write permissions for all organizations, networks, and sub-accounts within the enterprise, along with the ability to create organizations, networks, and administrators with various roles, including other platform administrators.
- User Administrator: Grants read permissions for all organizations and networks under the account, with the ability to create, edit, and delete networks, view administrators and users, and create sub-accounts.
- Organization Administrator: Grants read/write permissions for all organizations, networks, and sub-accounts under the account, along with the ability to create networks and sub-accounts.
- Network Administrator: Grants read/write permissions for all networks under the account and allows the creation of guest administrators for managed networks.
- Guest Administrator: Grants read/write permissions for guest-related management along with the ability to create and manage vouchers.
Roles
In addition to the roles predefined, the user can add a custom role and choose which privileges to assign to the role. To add a new role, please navigate to Organization → Users → Roles, then click on “Add” as shown below:

Under “Organization” tab, select the organization privileges for this user.

Under “Network” tab, select the network privileges for this user.

Then create a new user account and assign the new role to it.

Associated Company
Users can add other accounts, such as sub-channels and customers, as Associated Companies. They can then share their network with them under the user name or assign devices to them.
Navigate to Organization → Users → Associated Company, then click on “Add” button to add an associated company.

To add an associated company, the associating address is required. It can be found under Organization → Users → Associated Company, then click on “View my associated company binding address” as shown above.
Once the associated company is added, devices under Organization → Inventory can be assigned to the newly added associated company, as shown in the example below:
It’s also possible to share an entire network with an associated company under Organization → Overview (the default network can’t be shared with an associated company). Please check the example below:

Account Security Settings
To enhance GDMS Networking security, users can enable Password Security. With this option, users can set a password expiration period (in days) during which the password must be changed and cannot be the same as the previous one(s). Also account idle timeout and login duration can be configured here (minutes). Multi-Factor authentication can be enabled on all accounts.
Password Security | |
Password Security | Toggle on/off the password security. |
Password Expiration (days) | Specify the number of days of validity of a password. Once the number of days configured has elapsed, the user will be prompted to change his/her password upon login. |
No Repeating Passwords | Settings this option will prevent the user from using a password which he/she had previously used. You can set the number of previous passwords which have been used to prevent them from being used again as a new password. |
Account Security | |
Idle Timeout (min) | This configures the number of minutes of a user being idle on the web GUI before he/she can be automatically logged out by the system. The user can enter a value from 5 to 1440 minutes. Configuring this value is required. |
Login Duration (min) | This configures the number of minutes a login session can last before the user is logged out automatically by the system. The user has to log in again to start after being logged out. Note: The user can enter a value between 5 and 1440 |
Multi-factor Authentication | If MFA is enabled, all accounts (including this account) will be required to use multi-factor authentication. This cannot be disabled by other users. If disabled, users will be able to toggle MFA for their own accounts. |
Account Security Settings
SAML SSO
SAML (Security Assertion Markup Language) Single Sign-On (SSO) allows users to authenticate into GDMS Networking using their organization’s centralized identity provider (IdP). This enables streamlined and secure access across systems while reducing password fatigue and administrative overhead.
With SAML SSO, administrators can configure and manage external login services (e.g., Azure AD, Okta, etc.) for users in their GDMS Networking account. Once configured, users can log in through their IdP, and roles will be assigned based on mapped permissions in the system.
To access this feature, navigate to: Organization → Users → SAML SSO tab
SAML SSO Configuration
The Configuration tab displays a step-by-step process to set up SAML SSO for your organization. The setup includes:
- Configure IdP Service
Copy the required metadata—Entity ID and ACS URL—to input into your IdP dashboard. - Set Up the SAML IdP
Input metadata from your identity provider into GDMS Networking to connect both ends. - Set Up Roles
Define which users can access the system and what they are allowed to do by mapping roles.
Clicking on Entity ID or ACS URL automatically copies the values to your clipboard for quick use in the IdP configuration panel.
Click the Add SAML IdP button to create a new configuration.
When adding a new IdP, a detailed form appears. The key fields are:
- SSO Access Code
A unique identifier used during login. This code is what users enter on the GDMS login page to trigger SSO. - IdP Entity ID
The unique identifier of your identity provider. - X.509 cert SHA1 fingerprint
This fingerprint from your IdP certificate is used for encryption and validation. - SSO Login URL
Where users will be redirected when their session expires or upon login. - SSO Logout URL
Optional. When users log out from GDMS, they’ll also be logged out of the IdP if this URL is configured.
Once all required fields are completed, click Save.
SAML SSO Role
After configuring your SAML IdP, switch to the SAML SSO Role tab to create role mappings between the IdP and GDMS Networking.
Click the Add button to create a new role mapping.
Step 1: General Settings
Set a Role Name that exactly matches the role configured in your IdP.
Step 2: UC Permissions
Define permissions related to UC (Unified Communications) features.
Step 3: Networking Permissions
Choose networking-specific permissions or assign a custom role.
Additional Help
A detailed User Guide is available directly from the platform by clicking the User Guide link in the top-right of the Configuration tab.
Alternatively, you can access the documentation here: GDMS SAML SSO User Guide
Upgrade
Devices Upgrade
This feature allows upgrading GWN devices. Under “Upgrade” menu allows the administrator to manage GWN devices’ firmware, and trigger immediate upgrades or Upgrade reminders. There is also the option for Upgrade History on the second tab.
Select the devices you wish to upgrade then click “Upgrade“. Under “Firmware Version” the users can select which version to upgrade to (Beta Firmware is also supported but not recommended).

Manager Upgrade
The users can upgrade the GWN Manager directly from the Web UI, by navigating to Organization → Upgrade page → Manager Upgrade tab.
On this page, the users can see the current version and the latest firmware available, to upgrade to the latest firmware, please click on “Upgrade” button as shown below:
The users have the option to upgrade now, upgrade later or upgrade regularly, a remark or comment about the upgrade can be also added. The overall features related to the upgrade will be listed under.
Upgrade History
On the upgrade history tab, the user can see the upgrade history of all GWN devices with details information like (device model, firmware version, upgrade status, etc), it’s also possible to search for a device using its MAC address.
Report
Administrators can generate and configure the platform to send reports periodically to the configured email addresses. Each report can be related to one or more different Network groups, providing Wi-Fi statistics (client count, bandwidth usage, client and guest statistics…etc.)
To generate the report, click on the “Create a Report” button, and a new page displaying the report details will be displayed.
The following table explains different options for report settings:
Field | Description |
Title | Enter a name for the report. |
Type | Select the report type (e.g., Statistical Report or Speed Test Report). |
Organization | Select the organization that the report belongs to. |
Network | Select the Network Group(s) to include in the report. |
Report Contents | Choose what to include in the report (e.g., Clients Count, Bandwidth Usage, Client Statistics, Guest Statistics, Top Devices/Clients/SSIDs, and WAN Bandwidth Usage Statistics). |
WAN Bandwidth Usage Statistics | Include WAN traffic/bandwidth statistics in the report. After enabling it, click Selected Devices to choose the WAN device(s) to report on. |
Report Frequency | Choose how often the report is generated (Daily, Weekly, Monthly, or Custom Range). |
Report Generate Time | Choose whether to generate the report Now or at a Later time. |
Email Address | Add one or more email recipients to receive the generated report. |
Report
Organization Change Log
The Change Log page provides a history of actions and events in your GDMS Networking account. It includes two tabs:
- System Log (system and configuration actions)
- Account Center (account activity records)
System Log
The System Log records system and configuration actions performed in the platform, including who performed the action and where it was applied.
You can filter and locate entries using:
- Date range (Start Date / End Date), including quick ranges such as Last 1 day, Last 7 days, and **Last 30 days.
- Search field to filter by Operator or IP Address
Each entry includes the following information:
- Time: When the action occurred.
- Operator: The user who performed the action.
- IP Address: The source IP used.
- Network: The related network (if applicable).
- Details: A short description of the action.
- Operation: Additional options for the log entry.
To view expanded details for a specific entry, click the three dots under the Operation column.
The More Details window displays additional information for the selected entry (for example, updated parameters and values).
Account Center
The Account Center tab records account-related activity (for example, login events). You can filter results using:
- Date range (Start Date / End Date)
- Search field to filter by Operator or IP Address
Each entry includes:
- Time
- Operator
- IP Address
- Details (for example, Login success)
Global
Import/Export
The Import/Export section provides a way to export device configuration data to files, or import configuration data in bulk using a template.
Navigation: Organization → Global → Import/Export
Export
Use Export to download configuration data as CSV files.
- Select Export.
- In Type, choose what you want to export:
- All Types: Exports multiple CSV files (for example, Network, Device Group, Device Configuration, etc.).
- Network / Devices / Device Group / SSID / LAN: Exports only the selected type.
- The browser downloads the exported CSV file(s).
Import
Use Import to upload configuration data in bulk using the provided template.
- Select Import.
- In Type, choose the data type you are importing (for example, Network, Devices, Device Group, SSID, LAN, or Port Profile).
- Click Reference template to download the import template, then fill it with your configuration data.
- Under Import File, click the upload area and select your completed template file.
- (Optional) Enable Assign the SSID in this network to the newly added router if you want GDMS to assign imported SSIDs to newly added routers. Depending on your environment, this may overwrite SSIDs created in the device’s local web interface.
- Click Import to upload and apply the configuration.
API Developer
The API Developer Mode in GDMS Networking allows organizations to securely integrate their network operations with external platforms, in-house tools, or automation workflows using a RESTful API.
This feature is designed for environments that require centralized monitoring, real-time alerts, automated provisioning, or system-to-system integration beyond the standard web interface.
Navigation: Go to API Developer from the main menu.

Enabling Developer Mode
To activate API Developer Mode:
- Toggle the Enable Developer Mode option.
- The system will generate:
- APP ID – A unique identifier used for authenticating API requests.
- Secret Key – A secure key used to obtain an access token.
- Optionally, toggle Restrict APIs to specific networks to limit access only to networks associated with the logged-in user.
Authentication Requirements
To access GDMS Networking APIs, a valid access token must be generated. The authentication process depends on your settings:
- If “Restrict APIs to specific networks” is disabled (default):
You only need your APP ID and Secret Key. - If restriction is enabled:
In addition to the APP ID and Secret Key, you must also provide your GDMS account username and password.
This adds a layer of security by ensuring the token only grants access to networks assigned to that user.
This flexible model allows both general integrations and tightly scoped access when required.
API Capabilities and Integration Highlights
GDMS Networking’s API Developer Mode provides secure, programmable access to the platform’s core features, allowing seamless integration with external systems and custom workflows.
The API supports a wide range of functions, including (but not limited to):
- Accessing real-time device and client data
- Automating configuration of networks, SSIDs, VLANs, and device groups
- Managing provisioning and deployment across distributed environments
- Receiving alerts through Webhook integration
- Retrieving Bluetooth Low Energy (BLE) client data from supported access points. Note: Bluetooth API must be enabled first under Settings → System → General.
- Configuring security features such as MAC-based authentication and RADIUS profiles
- Handling bulk import/export of network and device configurations
These capabilities enable IT teams and system integrators to build scalable, automated, and responsive network operations.
Developer Documentation
The full list of API endpoints, usage examples, authentication steps, and integration methods can be found in the official developer guide: GWN API Developer Guide
This includes:
- Access token generation
- Webhook payload format
- Endpoint descriptions and parameters
- Sample request/response structures
- Error code definitions
Speed Test Server
The Speed Test Server page is where you add and manage custom speed test servers that GDMS Networking can use when running speed tests and generating Speed Test Reports.
To open this page, go to Organization, select Global, then open Speed Test Server.
Click Add to create a new speed test server.
In the Add speed test server window, fill in the following fields:
| Field | Description |
|---|---|
| Name | Enter a name for the server (1–64 characters). |
| Server Address | Enter the server address. If the server address uses a port, include the port number. |
| Secret Key | Enter the secret key used to authenticate with the speed test server. |
| Speed Test Duration (s) | Set the test duration in seconds (10–30). |
| Number of concurrent devices | Set how many devices can run the speed test at the same time. This value cannot be 0. |
For instructions on deploying and configuring a local speed test server, refer to the Deploy a Local GWN Speed Test Server (GDMS Networking/GWN Manager) Guide.
MANAGER SETTINGS

Basic
In this section, the user can download the Manager log files by clicking on the “Export” button as shown below, as well as enabling “Remote Assistance” in case the users need professional help from experts or support.
SMTP Server
To enable email notifications from GWN Manager, the user needs first to set up the SMTP Server here, once the SMTP Server configuration is set, please click on the “Send test email” button to test if it’s working or not.
Backup & Restore
Users can Backup GWN Manager configuration as shown below:
Users can click the “Upload” button to import a backup from the local directory. Or, click the “Backup” button to back up immediately.
REQUIREMENTS
The following tables show the requirements of Grandstream networking products including GWN Access Points, GWN Routers, GWN Switches, GCC Devices, and GWN App versions (Android® and iOS®) for GWN Management Platforms (GDMS Networking & GWN Manager):
- GWN Access Points: minimum and recommended version
Model | Minimum | Recommended |
GCC6010 | 1.0.1.8 | 1.0.1.8 |
GCC6010W | 1.0.1.8 | 1.0.1.8 |
GWN7001 | 1.0.1.6 (1.0.5.35 for GWN Manager) | 1.0.5.35 |
GWN7002 | 1.0.1.6 (1.0.5.35 for GWN Manager) | 1.0.5.35 |
GWN7003 | 1.0.1.6 (1.0.5.35 for GWN Manager) | 1.0.5.35 |
GWN7052 | 1.0.5.34 (1.0.9.42 for GWN Manager) | 1.0.9.42 |
GWN7052F | 1.0.5.4 (1.0.9.42 for GWN Manager) | 1.0.9.42 |
GWN7062 | 1.0.5.34 (1.0.9.42 for GWN Manager) | 1.0.9.42 |
AP minimum and recommended version
- GWN Routers/GCC Devices: minimum and recommended version
Model | Minimum | Recommended |
GCC6010 | 1.0.1.8 | 1.0.1.8 |
GCC6010W | 1.0.1.8 | 1.0.1.8 |
GWN7001 | 1.0.1.6 (1.0.5.35 for GWN Manager) | 1.0.5.35 |
GWN7002 | 1.0.1.6 (1.0.5.35 for GWN Manager) | 1.0.5.35 |
GWN7003 | 1.0.1.6 (1.0.5.35 for GWN Manager) | 1.0.5.35 |
GWN7052 | 1.0.5.34 (1.0.9.42 for GWN Manager) | 1.0.9.42 |
GWN7052F | 1.0.5.4 (1.0.9.42 for GWN Manager) | 1.0.9.42 |
GWN7062 | 1.0.5.34 (1.0.9.42 for GWN Manager) | 1.0.9.42 |
GWN routers/GCC devices minimum and recommended version
- GWN Switches: minimum and recommended version
Model | Minimum | Recommended |
GWN7711 | 1.0.1.8 | 1.0.1.8 |
GWN7711P | 1.0.1.8 | 1.0.1.8 |
GWN7801 | 1.0.3.19 (1.0.5.52 for GWN Manager) | 1.0.5.52 |
GWN7801P | 1.0.3.19 (1.0.5.52 for GWN Manager) | 1.0.5.52 |
GWN7802 | 1.0.3.19 (1.0.5.52 for GWN Manager) | 1.0.5.52 |
GWN7802P | 1.0.3.19 (1.0.5.52 for GWN Manager) | 1.0.5.52 |
GWN7803 | 1.0.3.19 (1.0.5.52 for GWN Manager) | 1.0.5.52 |
GWN7803P | 1.0.3.19 (1.0.5.52 for GWN Manager) | 1.0.5.52 |
GWN7806 | 1.0.1.14 (1.0.5.52 for GWN Manager) | 1.0.5.52 |
GWN7806P | 1.0.1.14 (1.0.5.52 for GWN Manager) | 1.0.5.52 |
GWN7811 | 1.0.1.8 (1.0.7.64 for GWN Manager) | 1.0.7.64 |
GWN7811P | 1.0.1.8 (1.0.7.64 for GWN Manager) | 1.0.7.64 |
GWN7812P | 1.0.1.8 (1.0.7.64 for GWN Manager) | 1.0.7.64 |
GWN7813 | 1.0.1.8 (1.0.7.64 for GWN Manager) | 1.0.7.64 |
GWN7813P | 1.0.1.8 (1.0.7.64 for GWN Manager) | 1.0.7.64 |
GWN7816 | 1.0.3.8 (1.0.7.64 for GWN Manager) | 1.0.7.64 |
GWN7816P | 1.0.3.8 (1.0.7.64 for GWN Manager) | 1.0.7.64 |
GWN7830 | 1.0.3.3 (1.0.7.64 for GWN Manager | 1.0.7.64 |
GWN7831 | 1.0.3.3 (1.0.7.64 for GWN Manager) | 1.0.7.64 |
GWN7832 | 1.0.3.3 (1.0.7.64 for GWN Manager) | 1.0.7.64 |
Switch minimum and recommended version
- GWN App: minimum and recommended version
Platform | Minimum | Recommended |
iOS® | 1.0.5 | 1.6.7 |
Android® | 1.0.0.14 | 1.0.6.7 |
App minimum and recommended version
Requirements
To know more about the differences between Grandstream devices in terms of functions based on the recommended versions, please navigate to GDMS Networking Web UI → About → Device Comparison. refer to the figures below:
On this page, the users can find the minimum and recommended firmware version for each Grandstream device and APP (iOS® and Android®). If a Beta firmware is available for a device it will be also shown here.

EXPERIENCING GWN MANAGEMENT PLATFORMS
Please visit our Website: http://www.grandstream.com to receive the most up-to-date updates on firmware releases, additional features, FAQs, documentation, and news on new products.
We encourage you to browse our product-related documentation, FAQs, and User and Developer Forum for answers to your general questions. If you have purchased our products through a Grandstream Certified Partner or Reseller, please contact them directly for immediate support.
Our technical support staff is trained and ready to answer all your questions. Contact a technical support member or submit a trouble ticket online to receive in-depth support.
Thank you again for using Grandstream GWN Management Platforms, it will be sure to bring convenience to both your business and personal life.
CHANGE LOG
This section documents significant changes from previous versions of the GWN Management Platform User Manuals. Only major new features or major document updates are listed here. Minor updates for corrections or editing are not documented here.
Version 1.1.39.5
- Added support for Wi-Fi health management, including key performance metrics, customizable health thresholds, compliance tracking, and unhealthy device detection (Beta). [Network Health]
- Added support for quick viewing of stacked switches [Configure a GWN Switch (Layer 2 lite)]
- Added support for VLAN configuration in switch management page [Configure a GWN Switch (Layer 2+ / Layer 3)]
- Added support for Standby mode for router WAN policies [Internet Source]
- Added IPSG (IP Source Guard) [Wireless LAN]
- Added OWE options for SSID access security [Add SSID]
- Added support for Wireless Bridge-related alerts [System Alert]
- Added “Additional Remarks” field for supported devices [Configure a GWN Access Point]
- Added support for importing Port Profiles [Import]
- Added support for network sharing with Grandstream support team [Share Network]
- Added support for device allocation to networks on the CSV file [Reseller Channel]
- Added support for device names when claiming devices in Inventory [Inventory]
- Added custom Installer permissions [Roles]
Version 1.1.37.6
- Added Support for Wireless Bridge configuration and status management. [Wireless Bridge]
- Added support for Floor plans AI Recognition of Walls and AI Placement. [AI Device Placement] [AI Wall Detection]
- Added ability to export RF planning reports based on Floor plans. [Export RF Planning Reports]
- Added support for Multi-VLAN on SSIDs created. [Multi-VLAN]
- Added the ability to change the SSID password regularly and set the default SSID based on your organization. [Set Passphrase Reset Cycle]
- Added ability to display 802.1x Identity in client list. [802.1X Identity]
- Added support for client batch configuration. [Client batch configuration]
- Added Client Type Filter. [Client Type]
- Added client offline alarms and bandwidth usage alerts. [Client Offline Alarms and Bandwidth Usage Alerts]
- Added support for voucher template configuration and QR codes. [Using Voucher Group Templates]
- Added the Static IP Binding function menu to manage client IP bindings in a unified manner. [Static IP Binding]
- The PPSK quantity limit is optimized to be based on the device model. [PPSK Capacity]
- Added support for sending URL Access logs to external servers. [Remote Syslog Server]
- Added support to clone network settings for WAN & VPN as well as Device Group. [Group Management]
- Added the User Administrator role to manage ITSP users. [User Administrator]
- Added support for interface selection on wireless router mesh management. [Mesh]
- Added ability of WireGuard Auto Peer to support Allowed IP and DNS Server settings. [Allowed IP] [Preferred DNS Server] [Alternative DNS Server]
- Added support for router QoS configuration. [QoS]
- Added support for FXS port configuration. [FXS Configuration (GWN7062ET Only)]
- Added support for ISP Locking and adding universal configuration. [ISP Locking]
Version 1.1.35.5
- Added support for additional GWN device models. [Devices]
- Added Multi-organization management support, including enhanced organization hierarchy view, improved permission assignment, and organization transfer. [Network Overview]
- Added support for directly editing Access Point configuration files. [Configuration File]
- Added Blocked Client and Locked Client options. [Client]
- Added support for displaying devices on shared networks in Inventory. [Inventory]
- Added support for duplicate SSID names. [Wi-Fi]
- Added support for adding SSID via QR code. [Wi-Fi]
- Added support of SAML SSO authentication for the Splash Page. [Splash page]
- Added Custom Login Page and Skip Login Page options for Custom Field on the Splash Page. [Splash page]
- Added support for All Destination option and Email Service pre-authentication rules for Portal policies. [Portal policy]
- Added support for WAN traffic statistics report. [Report]
- Added support for Captive Portal on Router LAN. The Enable Captive Portal option and Captive Portal Policy selection are available when adding/editing a LAN/VLAN. [LAN]
- Added support for custom 3rd party Speed Test Servers and Speed Test Reports. [Report] [Speed Test Server]
- Added support for Alert Notifications to 3rd-party platforms, including WhatsApp, Telegram, Wave, and custom webhooks. [Alert Notification]
- Added support for retrieving Network Overview information, alert information, WAN configuration, and URL Access Logs via the API. [API Developer]
Version 1.1.33.42
- Added Email Address field for PPSK to email credentials to the end user. [PPSK]
- Added LAN importing (import LAN/VLAN configuration via CSV for bulk setup and management). [Network Overview]
- Added Device Group filter on the Clients page to filter client lists by device group. [Clients]
Version 1.1.33.5
- Updated Max Num of Access Clients limit to 512 per PPSK. [PPSK]
Version 1.1.33.2
- Added support for Webhook API alerts. [API Developer]
- Added support for BLE client API. [API Developer]
- Added rotating Floor Plans option and added more label information. [Floor Plans]
- Added support for MAC-based authentication, LACP on switch ports (for GWN78XX versions equal to or higher than 1.0.15.X). [Configure a GWN Switch]
- Added support for capturing switch syslogs. [Syslog]
- Added support for Voice VLAN, LLDP, and total input power configuration on GWN77XX. [Configure a GWN Switch (Layer 2 lite)]
- Added global blocklist limit to 1000. [Wireless LAN]
- Added “Power Supply Mode” in the switch POE status list. [Configure a Switch]
- Optimized the device list to display the uplink speed of routers and switches. [Devices]
- The Splash Portal password authentication now supports all characters (except spaces) for simple passwords. [Splash page]
- Optimized the client list to display Locked APs. [Clients]
Version 1.1.31.22
- Added Alert Icons to the network list. [Network Overview]
- Added filter for read/unread alerts on the alerts page. [Alerts]
- Support exception AP for offline alerts. [System Alert]
- Added the configuration of target wake-up time for SSID. [Wi-Fi]
- Added MAC authentication for SSID. [Wi-Fi]
- Added frequency band display of the SSID in the SSID list. [Wireless LAN]
- Added the SAML SSO Configuration to support SSO Login. [SAML SSO]
- Added defense configuration for DoS/Spoofing Attack. [Security Defense]
- Added Defense Alert for DoS/Spoofing attack. [Security Alerts]
- Added SNAT & DNAT configuration for GWN router. [SNAT] [DNAT]
- Added VPN Configure Wizard for fast and convenient setup for different VPN protocols. [VPN Setup Wizard]
- Display the locked access point for all set devices and added the configuration for the Failover Access Point. [Configure a Client]
- Added Network Tags for the network list in the overview page. [Network Tags]
- Added the function to Import Network/Device/Device Group/SSID configuration. [Network Import]
- Added Dark Web Theme support [Theme Appearance]
- Added Voucher Group Template configuration support. [Voucher Group Template]
- Added PPSK support for GWN routers and support PPSK download and export. [PPSK]
- Added VLAN2 configuration in LAN. [LAN]
- Added a method to sort RSSI by numerical order. [Clients]
- Added quick link to view Blocklist. [Clients]
- Added Real Time Chart for wireless client usage. [Client usage]
- Added filter for online/offline devices on inventory page. [Inventory]
- Added longitude and latitude configuration for devices. [Devices]
- Added display for Uplink Port of the switch. [GWN Switch – Port]
- Support the use of public IP for DDNS source IP. [DDNS]
- Support configuring the refresh interval for DDNS. [DDNS]
- Support RADIUS Profile configuration on API. [API Developer]
Version 1.1.29.15
Product Name: GDMS Networking
- Optimized the performance and stability for some business process. GWN.Cloud was renamed “GDMS Networking”. Unified GDMS entry and email notifications.
- Supports vertical and horizontal display for network topology. [Network Topology]
- Added timestamp of the last contact with GDMS Networking to the list of devices. [Devices]
- Supports router NAT Traversal to remote access devices. [NAT Traversal]
- Added selections of Icon Types for Clients. [Clients]
- Added client blocking duration setting. [Clients]
- Added a central control “Collect client historical data” for all available clients. [System]
- Support binding a client to a specific AP. [Clients]
- Supports ISP Locking for wireless routers. [ISP Locking]
- Supports setting the ports names of routers. [Configure a device]
- Added the API for basic router configuration (including port). [API developer]
Version 1.1.28.27
Product Name: GWN Manager
- Added security enhancement by verifying device password when adding a switch or a router. [Adopt a Device to GWN Manager]
Version 1.1.28.25
Product Name: GWN.Cloud and GWN Manager
- Added support of GCC601X SMB UC/Networking Convergence Solutions [Requirements]
- Added the ability to update AP info in real time when enter AP detailed page [GWN AP Info]
- Added the ability to customize MAC for client isolation in wireless LAN [Add SSID]
- Added a new feature of OS Filter in wireless LAN [Add SSID]
Version 1.1.28.9 – 1.1.28.10
Product Name: GWN.Cloud(1.1.28.9) and GWN Manager(1.1.28.10)
- Supports link speed display for APs on the device list. [Devices]
- Supports L2TPv3 configuration on GWN7660 series APs (supported only GWN.Cloud) [GWN AP L2TPv3]
- Supports cloning the LAN and wired firewall configuration [Create a new network]
- Added Beta firmware display and supports upgrading to Beta. [Requirements]
- Optimized client list sorting. [Clients]
- Supports local WAN configuration synchronization. [Add device to GWN.Cloud]
- Optimized Feedback entry. [Feedback]
- Added PPSK configuration, inventory information acquiring, and switch port information acquiring for API. [API Developer]
- Added GWN Manager Upgrade support [Manager Upgrade]
Version 1.1.27.13
Product Name: GWN.Cloud and GWN Manager
- Added Regions/Systems Switch to allow multiple regions/systems to be opened. [Region settings]
- Upgraded Account Permission, allowing comprehensive management of all Grandstream services and enable all systems in the selected region. [Merge Accounts]
- Added Associated Company to support cross-region/cross-system management on channels and customers for network sharing and device allocation. [Associated Company]
- Added Reseller Channel to support the establishment of hierarchy in agent partnership, obtain device from ERP, and assign device to network groups or channels/agents. [Reseller Channel]
- Optimized User Management, unified management of account and password security. [account security settings]
- Optimized Personal Settings page and added user type settings. [Personal Settings]
- Added API support for exporting the switch information, mainly the information and port modules in the switch details, and the information of the global switch settings. [API]
- Added API support for PPSK configuration. [API]
Version 1.1.26.11
Product Name: GWN.Cloud and GWN Manager
- Added Pre-Provisioning for Switch in device management for port Setting, port profile, and DHCP Snooping. [Switch Pre-Provisioning]
- Added remarks and serial number fields for device export. [Devices]
- Added more default Wall Types and optimized attenuation values for Floor Plans. [Floor Plans]
- Added support for topology export. [Network Topology]
- Added MAC search field in Upgrade History. [Upgrade History]
- Added a column to display the network that the device was returned from. [Inventory]
- Added support for custom role users to log in to GWN APP. [User Management]
- Increased Password Security, added password expiration and conflict limits configuration. [Personal Settings]
- Added support hiding Weak Heat Map signal. [Floor Plans]
- Removed SMTP Username/Password requirement. [SMTP Server]
Version 1.1.25.23
Product Name: GWN.Cloud and GWN Manager
- Added features of multiple VPN tunneling methods such as PPTP, IPSec, OpenVPN®, and WireGuard®, and IPSec supports automatic networking mode. [VPN]
- Added the feature of managing multiple routers at the same time on the same network. [Devices]
- Added device group management, and pre-set features for switches in the group. And a new way to select device groups in multiple businesses. [Group management]
- Added the feature of pushing cloud configuration to the local side of the device, and the push method includes manual and automatic. [Devices]
- Added a new feature for network speed test of APs. [configure a GWN Access Point]
- Added a new feature for 12-hour network health monitoring of WAN ports. [WAN]
- Added a new feature of policy routes. [Policy routes]
- Added a new feature of certificate management. [Certificate]
- Added floor plan management features, support device RF heat map preview, and convenient device placement planning. [Floor plans]
- Added the feature of Cloud DDNS service. [WAN]
- Added a new feature of VLAN interface configuration for routers. [Configure a GWN Router]
- Added alerts such as abnormal device time, abnormal temperature of the optical module, and VPN-related alerts [Alerts]
- Supports automatic time synchronization between routers and switches with cloud [System]
- Supports IPv6 PD/prefix length configuration in WAN [WAN]
- Added the ability to set the Primary Network for cloud [Network Overview]
- Added the ability to retrieve Guest information with API commands.
- Added the ability to display the Wi-Fi version used in the client’s information [Clients]
- Added the ability to Customize the Channel in the 2.4G band [Wi-Fi]
- Added the ability to disable the Router LAN ports [Configure a GWN router]
- Added the ability to configure the router/switch device password from GWN Cloud [Configure a device]
- Added the ability to support batch or single configuration for the Device Password [System]
- Added the ability to highlight mesh devices in Network Topology [Topology]
- Added the ability to configure Port Profile for Device Group [Port profile]
- Added the ability to display the router’s LAN IP address [Devices]
- Added a new feature of VLAN Interface configuration for routers [Configure a GWN router]
- Added API support for Device Name and Equipment Remarks.
Version 1.1.24.28
Product Name: GWN.Cloud and GWN Manager
- Adjust the upper limit to 300 on the number of PPSK in a group [PPSK]
- Support to display the switch port info on the client list when the client connects to the switch [Clients]
- Support the option “Timeout Duration of Unauthenticated Clients” on the external splash page [Portal Policy]
- Support the option “URL Pre-shared Key” when selecting Aiwifi as the platform of the external splash page [Portal Policy]
Version 1.1.24.23
Product Name: GWN.Cloud and GWN Manager
- Added the unified management for model of GWN7801(P),GWN7802(P),GWN7803(P)
- Added the support for Device Information, Configuration, and Debug under the Device menu for GWN switch models [Configure a GWN Switch]
- Added the support for GWN switches & port configurations through Global Switch Settings and Port Profiles [DEVICES]
- Added the support for GWN switches in Topology (including wired devices hierarchy relationship) [Network Topology]
- Added the support of GWN switches’ Alert events [ALERTS]
- Added a new feature of user role management and customizable role privilege [USER MANAGEMENT]
- Added a new feature of Organization Overview [ORGANIZATION]
- Added a new feature of Map for device location management [Map]
- Added a new feature of AP batch configuration [Configuration]
- Added a new feature of displaying Change logs’ content details [Organization Change Log]
- Added a new feature of transferring management permission for shared Network [Share a Network]
- Added a new feature of restricting APIs to specific networks [API Developer]
- Added a new feature of batch firmware upgrade for different GWN models to the recommended version [Upgrade]
- Added a new feature of disabling AP’s Ports [Configuration]
- Added a new feature of Limit by Authentication Type for Daily Limit of Captive Portal [Profiles]
- Added a new feature of Active Directory into Splash Page Logging Components [Splash Page]
- Added a new feature of grouping top website statistics by Main Domain rather than URL
- Added a new feature of PPSK With Radius into SSID Security Type [Wireless LAN]
Version 1.1.23.27
Product Name: GWN.Cloud and GWN Manager
- New Cloud Web Portal, SDN concept & UI design
- Unified GWN device management (Access points, Routers, Switches) [Devices]
- Inventory management [Inventory]
- New Network topology (replacing the old mesh topology) [Network Topology]
- New Alert design and support more alert events [Alerts]
Version 1.0.22.23
Product Name: GWN Manager
- Added feature of U-APSD for AP [SSID]
- Added feature of Email authentication for Captive Portal [Splash page]
- Added feature of post-authentication rules for Captive Portal [Portal Policy]
- Added feature of service auto start after machine reboot for GWN Manager
Version 1.0.21.17
Product Name: GWN Manager
- Added feature of reporting Probe request RSSI information
- Added feature to export APs, clients, and alerts [Devices] [Clients]
- Added feature of Google Authentication [Splash page]
- Added feature of WiFi4EU [Splash page]
- Added feature of SMS authentication for Captive Portal [Splash page]
- Added feature of Hotspot 2.0 R3 [Hotspot 2.0]
- Added support to transfer APs to GWN Manager
Version 1.0.19.8
Product Name: GWN Manager
- No major changes.
Version 1.0.19.7
Product Name: GWN Manager
- Added support for deleting the voucher in use. [Voucher]
- Added support of client name in CSV file when importing access list. [Access List]
- Added configuration of secondary radius server for WLAN 802.1x authentication. [Wi-Fi Settings]
- Added WPA3 support in the SSID setting. [Wi-Fi Settings]
- Added NET Port Type option for AP setting
Version 1.0.19.2
Product Name: GWN Manager
- Added support of Top Website statistic graph [Overview]
- Added support of Guest Count statistic graph [Captive Portal Summary]
- Added manager role: Network Administrator [USER MANAGEMENT]
- Added support of API Developer [API Developer]
- Added support of Access List Import in CSV [Access List]
- Added support of Rogue AP Detection [Rogue AP]
- Added support of SNMP [SNMP]
- Added support of Allow DHCP Option 43 to override GWN Manager Address [Discover GWN76xx]
- Added support of NAT [NAT Pool]
- Added support of Firewall [Firewall]
- Added support of Hotspot 2.0 Beta [Hotspot 2.0]
Version 1.0.10.7
Product Name: GWN.Cloud
- Added Site Survey feature [Site Survey]
- Added feature of Minimum Rate Control. [Enable Minimum Rate]
- Added feature of SSH Remote Access. [SSH Remote Access]
- Added feature of External Portal support Socifi Platform.
- Added feature of Client inactivity timeout. [Client Inactivity Timeout]
- Added feature of Upgrade Regularly [Upgrade]
- Added feature of Client Steering [Client Steering]
- Enhanced feature of Voucher: the display of remaining bytes. [Voucher]
- Enhanced feature of Dynamic VLAN
- Changed LED patterns [GWN76xx LED Patterns]
Version 1.0.9.8
Product Name: GWN.Cloud
- Added support for collecting user feedback from the GWN Cloud page. [Feedback]
- Added support for Voucher Style Customization. [Voucher]
- Added support for video URL. [Advertisement]
- Added support to export Guest Information via Email. [Email Guest Information]
- Added support for client RX/TX Rate display. [Dashboard]
- Expanded Max Devices to use the same Voucher. [Voucher]
- Added support to enable/disable client connection/disconnection events.
Version 1.0.8.17
Product Name: GWN.Cloud
- Added support for Advertisement for Captive Portal [Advertisement]
- Added support for Custom Field for Captive Portal Splash Page [Splash Page]
- Added feature of ARP Proxy. [ARP Proxy]
- Added support of Clear client data. [Clients]
- Enhanced Event log by Wi-Fi authentication event. [Event Log per AP]
- Added EU Server support. [Zone]
- Enhanced Bandwidth Rules by adding an option to limit bandwidth per client. [Range Constraint]
- Added Total Bandwidth Usage Display [Dashboard]
- Added Export Immediately feature for URL Access Logs. [URL Access Log]
Version 1.0.8.7
Product Name: GWN.Cloud
- Added support for URL logging (Except for GWN7610). [URL Access Log]
Version 1.0.7.18
Product Name: GWN.Cloud
- Enhanced Client Information. [Dashboard]
- Enhanced Access Point status. [Info]
- Added Reset access point button. [Reset Device]
- Added External Captive Portal Support. [External Splash Page]
- Added AP Scheduling Reboot. [Reboot Schedule]
- Added Change Log section. [Change Log]
- Added Account idle timeout. [Account Idle timeout]
- Added feature of Wi-Fi Statistic Report. [Report]
- Added feature of Captive Portal Guest Summary. [Guests]
- Changed SSID limit. [SSID]
- Enhanced Wi-Fi Service by adding configurable options. [Wi-Fi]
- Enhanced Captive Portal features. [Failsafe Mode] [Daily Limit] [Byte Quota] [Force To Follow] [Portal Policy]
Version 1.0.0.37
Product Name: GWN.Cloud
- This is the initial version for GWN.Cloud.
Version 1.0.0.33
Product Name: GWN Manager
- This is the initial version for GWN Manager.
Android is a trademark of Google LLC.
iOS is a trademark or registered trademark of Cisco in the U.S. and other countries and is used under license by Apple Inc.
Linux® is the registered trademark of Linus Torvalds in the U.S. and other countries.
macOS® is a trademark of Apple Inc., registered in the U.S. and other countries.
Windows® is a trademark of Microsoft Corporation in the United States and other countries.





























































































































































































































































