GWN7600(LR)/GWN7610 – User Manual

  • Updated on May 7, 2025

OVERVIEW

Grandstream’s versatile Wi-Fi Access Points (APs) deliver high-performance networking and reliable coverage for both indoor and outdoor environments. The outdoor models are built to withstand challenging conditions with durable, weatherproof designs. These APs are compatible with Grandstream’s robust management platforms, including both cloud-based and on-premise solutions, providing seamless control and scalability. Additionally, an embedded controller in the user interface enables straightforward local network management. Grandstream Wi-Fi APs are designed to meet the needs of businesses and enterprises of all sizes, with the flexibility to grow alongside your organization.

Caution

Changes or modifications to this product not expressly approved by Grandstream, or operation of this product in any way other than as detailed by this User Manual, could void your manufacturer warranty.

Note

“Out of the box” Grandstream Access Points are not affected by this issue. APs with old firmware are only affected after changing into client-bridge mode. Please refer to our white paper of “WPA Security Vulnerability” here.

PRODUCT OVERVIEW

Technical Specifications

GWN7610

GWN7600

GWN7600LR

Wi-Fi Standards

IEEE 802.11 a/b/g/n/ac

Antennas

3x 2.4GHz, gain 3dBi
3x 5GHz, gain 3dBi

2x 2.4GHz, gain 3dBi
2x 5GHz, gain 3dBi

2x 2.4GHz, gain 4dBi
2x 5GHz, gain 5dBi

Wi-Fi Data Rates

IEEE 802.11ac: 6.5 Mbps to 1300 Mbps
IEEE 802.11a: 6, 9, 12, 18, 24, 36, 48, 54 Mbps
IEEE 802.11n: 6.5 Mbps to 450 Mbps
IEEE 802.11b: 1, 2, 5.5, 11 Mbps
IEEE 802.11g: 6, 9, 12, 18, 24, 36, 48, 54 Mbps

IEEE 802.11ac: 6.5 Mbps to 867 Mbps
IEEE 802.11a: 6, 9, 12, 18, 24, 36, 48, 54 Mbps
IEEE 802.11n: 6.5Mbps to 300Mbps; 400Mbps with 256-QAM on 2.4GHz
IEEE 802.11b: 1, 2, 5.5, 11 Mbps
IEEE 802.11g: 6, 9, 12, 18, 24, 36, 48, 54 Mbps

*Actual throughput may vary depending on many factors including environmental conditions, distance between devices, radio interference in the operating environment and mix of devices in the network

Frequency Bands

2.4GHz radio : 2.400 – 2.4835 GHz
5GHz radio: 5.150 – 5.250 GHz, 5.725 – 5.850 GHz (FCC, IC, RCM)

2.4GHz radio : 2.400 – 2.4835 GHz
5GHz radio: 5.150 – 5.250 GHz, 5.725 – 5.850 GHz
*Not all frequency bands can be used in all regions. The band 5150-5350 MHz is restricted to indoor use only in all EU states.

Channel Bandwidth

2.4G: 20 and 40 MHz
5G: 20, 40 , 80 MHz

Wi-Fi and System Security

WEP, WPA/WPA2-PSK, WPA/WPA2 Enterprise (TKIP/AES); WPA3, anti-hacking secure boot and critical data/control lockdown via digital signatures, unique security certificate and random default password per device.

MIMO

3×3:3 2.4GHz

3×3:3 5GHz

2×2:2 2.4GHz (MIMO)

2×2:2 5GHz (MU-MIMO)

Coverage Range

Up to 575 ft. (175 meters)

Up to 541 ft. (165 meters)

Up to 984 ft. (300 meters)

*Coverage range can vary based on environment

Maximum TX Power

5G: 26dBm (FCC) / 20dBm (CE)
2.4G: 26dBm (FCC) / 17dBm (CE)

5G: 22dBm (FCC) / 20dBm (CE)
2.4G: 22dBm (FCC) / 17dBm (CE)

2.4G: 26dBm (FCC) / 16dBm (CE)
5G: 26dBm (FCC) /18dBm (CE)

*Maximum power varies by country, frequency band and MCS rate

Receiver Sensitivity 

2.4G
802.11b:-92dBm@11Mbps; 802.11g:-76dBm@54Mbps; 802.11n 20MHz:
-73dBm@MCS7; 802.11n 40MHz:-70dBm@MCS7

5G
802.11a: -94dBm@6Mbps; 801.11a: -77dBm@54Mbps; 802.11ac 20MHz:
-69dBm@MCS8; 802.11ac HT40: -65dBm@MCS9; 802.11ac 80MHz: -61dBm@MCS9

SSIDs

32 SSIDs total, 16 per radio (2.4GHz & 5GHz)

Concurrent Clients

250+

450+

Network Interfaces

2x autosensing 10/100/1000 Base-T Ethernet Ports

Auxiliary Ports

1x USB 2.0 port, 1x Reset Pinhole, 1x Kensington lock

1x Reset Pinhole

Mounting

Indoor wall mount or ceiling mount, kits included

Outdoor base bracket and cover bracket included

LEDs

3 tri-color LEDs for device tracking and status indication

1 tri-color LEDs for device tracking and status indication

Network Protocols

IPv4, IPv6, 802.1Q, 802.1p, 802.1x, 802.11e/WMM

QoS

802.11e/WMM, VLAN, TOS

Network Management

Embedded controller can manage up to 50 local GWN APs
GDMS Networking offers a free cloud management platform for unlimited GWN APs.
GWN Manager offers premise-based software controller for up to 50,000 GWN APs.

Auto Power Saving

Self-power adaptation upon auto detection of PoE or PoE+

Power and Green Energy Efficiency

DC Input: 24VDC/1A
Power over Ethernet 802.3af/802.3at compliant
Maximum Power Consumption:13.8W

Power over Ethernet 802.3af and 802.3at compliant
Maximum Power Consumption: 12.9W (PoE supply); 23.0W (PoE+ supply)

Environmental

Operation: 0°C to 50°C
Storage: -10°C to 60°C
Humidity: 10% to 90% Non-condensing

Operation: -30°C to 60°C
Storage: -30°C to 70°C
Humidity: 5% to 95% Non-condensing

Physical

Unit Dimension: 205.3 x 205.3 x 45.9mm; Unit Weight: 540g
Unit + Mounting Kits Dimension : 205.3 x 205.3 x 50.9mm; Unit + Mounting Kits Weight : 600g
Entire Package Dimension: 258 x 247 x 86mm; Entire Package Weight: 900g

Unit Dimension: 180.4mm x 180.4mm x 40.8mm
Unit+Mounting Kits Dimension: 180.4mm x 180.4mm x 48.8mm
Entire Package Dimension: 228.5 x 220 x 79mm; Entire Package Weight: 854g

Unit Dimension: 290×150×35mm; Unit Weight: 708g
Unit + Mounting Kits Dimension : 290×150×56mm; Unit + Mounting Kits Weight: 1528.2g
Entire Package Dimension: 423×187×97mm; Entire Package Weight: 1844g

Package Content

GWN7610 802.11ac Wireless AP, Mounting Kits, Quick Start Guide

GWN7600 802.11ac Wave-2 Wireless AP, Mounting Kits, Quick Start Guide

Outdoor Long Range 802.11ac Wave-2 Wi-Fi AP, Mounting Kits, Quick Start Guide

Waterproof Grade

IP66-level weatherproof capability when installed vertically

Compliance

FCC, CE, RCM, IC

Technical Specifications

INSTALLATION

Before deploying and configuring the GWN76xx, the device needs to be properly powered up and connected to the network. This section describes detailed information on installation, connection, and warranty policy of the GWN76xx.

Equipment Packaging

  • GWN76xx
GWN76xx Equipment Packaging

Main Case (GWN7610, GWN7600)

Yes (1)

Mounting Bracket

Yes (1)

Ceiling Mounting Bracket

Yes (1)

Plastic Expansion Bolt

Yes (3)

M3 NUT

Yes (3)

Screw (PM 3 x 50)

Yes (3)

Screw (PM 3.5 x 20)

Yes (3)

Quick Installation Guide

Yes (1)

GWN76xx Equipment Packaging

  • GWN7600LR

Below is the equipment packaging for the GWN7600LR model.

GWN7600LR Equipment Package

Main Case

Yes (1)

Cover Interface

Yes (1)

Base Bracket

Yes (1)

Cover Bracket

Yes (1)

Assembled Screw

Yes (4)

Locknut

Yes (4)

Anchors + Screws

Yes (4)

Screw (PM8 x 115)

Yes (4)

Quick Installation Guide

Yes (1)

GWN7600LR Equipment Packaging

GWN76XX Access Point Ports

GWN7610GWN7600 Ports
GWN7600LR Ports

Port Description
Power Power adapter connector (24V, 1A) for GWN7600 and GWN7610.
NET/PoEEthernet RJ45 port (10/100/1000Mbps) supporting PoE/PoE+.
*GWN7600 supports PoE (802.3af) only.
NET Ethernet RJ45 port (10/100/1000Mbps) to your router or another GWN76XX series.
USB USB 2.0 port (for future IOT & location-based applications)
*Available on GWN7610 and GWN7600 only.
RESETFactory reset button.
Press for 7 seconds to reset factory default settings.
Quick press will only reboot the unit.
GWN76XX AP Ports Description

Power and Connect GWN76XX Access Point

Step 1:

Connect one end of a RJ-45 Ethernet cable to the NET or PoE/NET port of the GWN76XX unit.

Step 2:

Connect the other end of the Ethernet cable(s) into a LAN port to your Network. (Use PoE/PoE+ switch for GWN76XX).

Step 3:

For GWN7610/GWN7600 connect the 24V DC power adapter into the power jack on the back of the access point. Insert the main plug of the power adapter into a surge-protected power outlet. Otherwise, PoE can be used if the switch port does provide PoE power.

Notes

GWN7600LR can be powered using PoE(802.3af)/PoE+(802.3at) switch via PoE/NET port while GWN7600 can be powered using PoE (802.3af) switch via PoE/NET port. In this case, both power and network connectivity will be provided over the PoE/NET port. GWN7600/GWN7610 has a PoE detection daemon that will monitor the status and update maximum allowable power for USB ports in real time.

Step 4:

Wait for the GWN76XX to boot up and acquire an IP address from the DHCP Server.

Connecting GWN AP GWN7600 as an example
Warranty

If the GWN76XX Wireless Access Point was purchased from a reseller, please contact the company where the device was purchased for replacement, repair, or refund.

If the device was purchased directly from Grandstream, contact our Technical Support Team for an RMA (Return Materials Authorization) number before the product is returned. Grandstream reserves the right to remedy warranty policy without prior notification.

Wall/Ceiling Mount Installation GWN76XX

GWN7610, GWN7600 can be mounted on the wall or ceiling, please refer to the following steps for the appropriate installation. This is the GWN7600 example:

Wall Mount – GWN76xx

Step1:

Position the mounting bracket at the desired location on the wall with the arrow pointing up.

Wall Mount Steps 1 2

Step 2:

Use a pencil to mark the four mounting holes (screw holes DIA 5.5mm, reticle hole DIA 25mm).

Step 3:

Insert screw anchors into the 5.5 mm holes. Attach the mounting bracket to the wall by inserting the screws into the anchors.

Wall Mount Steps 3 4

Step 4:

Connect the power cable and the Ethernet cable (RJ45) to the correct ports of your GWN7610/GWN7600.

Step 5:

Align the arrow on the GWN AP with the arrow on the locking tab of the mounting bracket and ensure that your GWN is firmly seated on the mounting bracket.

Wall Mount Steps 5 6

Step 6:

Turn the GWN clockwise until it locks into place and fits the locking tab.

Ceiling Mount

Step 1:

Remove the ceiling tile.

Ceiling Mount Steps 1 2

Step 2:

Place the ceiling backing plate in the center of the ceiling tile and mark the mounting screw holes (screw holes DIA 5.5mm, reticle hole DIA 25mm).

Step 3:

Insert the screws through the mounting bracket.

Ceiling Mount Step 3

Step 4:

Connect the power cable and the Ethernet cable (RJ45) to the correct ports of your GWN76XX.

Ceiling Mount Step 4

Step 5:

Align the arrow on the GWN AP with the arrow on the locking tab of the mounting bracket and ensure that your GWN is firmly seated on the mounting bracket and connect the network and power cables.

Ceiling Mount Steps 5 6

Step 6:

Turn the GWN clockwise until it locks into place and fits the locking tab.

Note

Ceiling mounting is recommended for optimal coverage performance.

Mounting Instructions for GWN7600LR

Please refer to the following steps to mount your GWN7600LR correctly.

  1. Prepare the Cover Bracket by inserting the 4 screws (PM8) into corresponding holes.
  2. Attach the Cover Bracket with screws on the vertical/horizontal Mounting Bolt where GWN7600LR will be installed.
  3. Assemble the Base Bracket with the Cover Bracket using provided locknuts and screws (PM8).
  4. Connect the Ethernet cable (RJ45) to the correct ports of your GWN7600LR.
  5. Align the GWN7600LR with the Base Bracket and pull it down to the right position.
  6. Install the 2x Assembled screws to fix GWN7600LR on the Mounting Bolt.
GWN7600LR Vertical Mounting
GWN7600LR Horizontal Mounting

GETTING STARTED

The GWN76XX Wireless Access Point provides an intuitive web GUI configuration interface for easy management to give users access to all the configurations and options for the GWN76XX’s setup.

This section provides step-by-step instructions on how to read LED patterns, discover the GWN76XX, and use its Web GUI interface.

LED Patterns

The panel of the GWN76XX has different LED patterns for different activities, to help users read the status of the GWN76XX whether it is powered up correctly, provisioned, in the upgrading process, and more, for more details please refer to the below table.

LED Status

Indication

OFF

Unit is powered off or abnormal power supply

Blinking green

Firmware update in progress

Solid green

Firmware update successful

Blinking red

Delete paired slave – Factory reset initiated

Solid red

Firmware update failed

Solid purple

Unit not provisioned

Blinking blue

Unit provisioning in progress

Solid blue

Unit is provisioned successfully

Blinking White

Used for Access Point location feature

Solid Yellow

Mesh disconnection

Blinking purple

Slave AP is disconnected from the master device (e.g., no network or master device is offline).

LED Patterns

Discover the GWN76XX

Once the GWN76XX is powered up and connected to the Network correctly, users can discover the GWN76XX using one of the below methods:

Method1: Discover the GWN76XX using its MAC address

  1. Locate the MAC address on the stickers of the unit, which is located on the back of the device, or on the package.
  2. From a computer connected to same network as the GWN76XX , type in the following address using the GWN76XX’s MAC address on your browser https://gwn_.local<mac>.local
Example

if a GWN76XX has the MAC address 00:0B:82:8B:58:30, this unit can be accessed by typing https://gwn_000b828b5830.local/ on the browser.

Discover the GWN76XX using its MAC Address

Method 2: Discover the GWN76XX using the GWN Discovery Tool

  1. Download and install the GWN Discovery Tool from the following link: https://www.grandstream.com/support/tools
  2. Open the GWNDiscoveryTool, click on Select to define the network interface, then click on Scan.
  3. The tool will discover all GWN76XX Access Points connected on the network showing their MAC, IP addresses, and firmware version.
  4. Click on Manage Device to be redirected directly to the GWN76XX’s configuration interface, or type in manually the displayed IP address on your browser.
GWN Discovery Tool

Use the Web GUI

Users can access the GWN76XX using its WebGUI, the following sections will explain how to access and use the Web Interface.

Access Web GUI

The GWN76XX embedded Web server responds to HTTPS GET/POST requests. Embedded HTML pages allow users to configure the device through a Web browser such as Microsoft IE, Mozilla Firefox, Google Chrome, etc.

GWN76XX Web GUI Login Page

To access the Web GUI:

  1. Make sure to use a computer connected to the same local Network as the GWN76XX.
  2. Ensure the device is properly powered up.
  3. Open a Web browser on the computer and type in the URL using the MAC address as shown in [Discover the GWN76XX ] or the IP address using the following format: http(s)://IP_Address
  4. Enter the administrator’s login and password to access the Web Configuration Menu. The default administrator’s username is always “admin” and the password is the unique default Wi-Fi Password available on the sticker on the back of the unit.
Note:

GWN AP’s web UI access will be locked for 15 mins after 5 login failures

WEB GUI Languages

Currently, the GWN76XX series web GUI supports 17 languages including English, Chinese, Spanish, etc. Users can select the displayed language at the upper right of the web GUI either before or after login.

GWN76XX Web GUI Language Login page

Overview Page

Overview is the first page shown after successful login to the GWN76xx’s Web Interface. This page provides an overall view of the GWN76xx information presented in a Dashboard style for easy monitoring along with firmware version and date-time information at the top.

GWN76xx Dashboard

Users can quickly see the status of the GWN76xx for different items, please refer to the following table:

APShows the number of Access Points that are Discovered, Paired (Online), and Offline. Users may click on (•••) to go to the Access Points page for basic and advanced configuration options for the APs.
Clients Shows the total number of connected clients, and a count of connected clients to each Channel. Users may click on (•••) to go to the Clients page for more options.
AP Channel DistributionShows the Channel used for all APs that are paired with this Access Point.
Top APShows the Top APs list, users may sort the list by number of clients connected to each AP or data usage combining upload and download. Users may click on to go to the Access Points page for basic and advanced configuration options for the APs.
Top SSIDShows the Top SSIDs list, users may assort the list by number of clients connected to each SSID or data usage combining upload and download. Users may click on (•••) to go to the SSID page for more options.
Top Clients Shows the Top Clients list, users may sort the list of clients by their upload or download. Users may click on (•••) to go to the Clients page for more options.
Alert/NotificationShows 3 types of Alerts/Notifications: Critical, Major and Normal. Users can click (•••) to pop up the list of Alert and Notification.
Overview
Note

Note that Overview page in addition to other tabs can be updated each 15s, 1min ,2min and 5min or Never by clicking in the upper bar menu (Default is 15s).

New Firmware Notification: Starting from firmware version 1.0.5.13/1.0.5.14, and once a different OFFICIAL firmware is released on the Grandstream Networks website, the master AP will pop up a reminder notification to the administrator to upgrade the device. You can click on the New button to be redirected to the release note of the new firmware version, for upgrading steps please refer to section [UPGRADING AND BACKUP/RESTORE].

Save and Apply Changes

When clicking on the “Save” button after configuring or changing any option on the web GUI pages. A message mentioning the number of changes will appear on the upper menu. Click button to apply changes.

Apply Changes

GWN MANAGEMENT PLATFORMS

GDMS Networking

Starting from firmware 1.0.6.41/1.0.6.43, the GWN76xx can be managed by your GDMS Networking account, GDMS Networking web interface now can be accessed at https://www.gdms.cloud.

GDMS Networking Architecture

GWN Manager

Starting from firmware 1.0.13.1, the GWN76xx can be managed and monitored by your GWN Manager account, GWN Manager On-premises Access Points Controller platform can be installed using the link below: https://www.grandstream.com/support/firmware

GWN Manager Architecture
Note:

GWN Manager installation is supported on virtual machines. Please refer to GWN Management Platform User Guide for more detailed information.

USING GWN76XX AS A STANDALONE ACCESS POINT

The GWN76XX can be used in Standalone mode, where it can act as Master Access Point Controller or in Slave mode and managed by another GWN76XX Master.

This section will describe how to use and configure the GWN76XX in standalone mode.

Connect to GWN76XX Default Wi-Fi Network

GWN76XX can be used as a standalone access point out of the box, or after a factory reset with Wi-Fi enabled by default.

After powering the GWN76XX and connecting it to the network, GWN76XX will broadcast a default SSID based on its MAC address GWN [MAC’s last 6 digits], and a random password.

Note that GWN76XX’s default SSID and password information are printed on the MAC tag of the unit as shown in the below figure.

MAC Tag Label

USING GWN76XX AS MASTER ACCESS POINT CONTROLLER

Master Mode allows a GWN76XX to act as an Access Point Controller managing other GWN76XX access points. This will allow users to add other access points under one controller and manage them in an easy and centralized way.

Master/Slave mode is helpful with large installations that need more area zone coverage with the same controller.

GWN76XX Web GUI Login Page
Warning

Set unit as Master option will forbid the GWN76XX Access Point from being paired by other Master GWN76XX and can only act as a Master Access point controller. Users will need to perform a factory reset to the GWN76XX , or unpair it from the initial GWN76XX to make it open to Master Access Point mode again.

Login Page

After login, users can use the Setup Wizard tool to go through the configuration setup or exit and configure it manually. Setup Wizard can be accessed anytime by clicking on while on the web interface.

Setup Wizard

Discover and Pair Other GWN76xx Access Points

First, note that by default the GWN controller access point will automatically discover all APs connected to the same LAN (broadcast domain), there is also a possibility to pair and provision remote APs using DHCP option 43 with the master direction explained below.

Master Direction

To pair and manage access points located on remote networks, the admin needs to configure the IP address of the master AP on DHCP option 43 which will be sent to the slave access point during the booting stage and allow the save/master connection to be established remotely. GWN76xx accepts option 224 encapsulated in option 43, and the syntax is in TLV format. A simple example of DHCP 43 configuration would be:

224(Type)12(Length)10.157.0.234(Value) translated into Hex as e00c31302e3135372e302e323334

Scenario example: a company has two offices connected via VPN (master AP located on network 192.168.1.0/24 and slave AP located on remote network 192.168.2.0/2). On the remote network, the admin can set DHCP option 43 using the GWN70xx router as the following value:

encap: 43,224,”192.168.1.100”.

The slave AP has the option ”Allow DHCP Option 43 to override GWN Manager Address” enabled by default.

Option 43 Override

After that, the slave AP will be listed on the master AP discovered devices and ready for the pairing and provisioning process which is described in the next steps.

To Pair a GWN76XX access point connected to the same Network as the GWN76xx follow the below steps:

1. Connect to the GWN76xx Web GUI as Master and go to Access PointsConfiguration.

Discover and Pair GWN76XX

2. Click on  to discover access points within GWN76xx Network, the following page will appear.

Discovered Devices

3. Click on Pair  under Actions, to pair the discovered access point as slave with the GWN76xx acting as Master.

The paired GWN76XX access point will appear Online, users can click on  to unpair it.

GWN76XX Online

If a GWN76xx is not being discovered or the pair icon is grey color, make sure that it is not being paired with another GWN76XX Access Point acting as Master Controller. If yes, users will need to unpair it first, or reset it to factory default settings in order to make it available for pairing by other GWN76xx Access Point Controller

AP Location

GWN76xx supports a handy feature which allows users to locate other Access points by blinking LED. To use the feature, navigate on the master web GUI under “Access Points → Status” page and click on the icon near the desired AP, and it corresponding unit will start blinking the LEDs.

Transfer AP – Transfer Network Group

Users can easily transfer the AP from the local master to the GDMS Networking or GWN Manager account by clicking on When you already have Network/Wi-Fi configurations on your GWN account, using this feature will let you choose existing Network/SSID to adopt your local AP.

Navigate to AP Web UI → Access Points → Configuration page, please refer to the figure below:

Access points configuration page

Then select where to transfer the select AP, either GDMS Networking or GWN Manager.

Transfer AP

After this step, you will be redirected to GDMS Networking/GWN Manager page, select the network and click on “Save” button to complete the transfer.

GDMS Networking Select Network

This feature will allow you to transfer your local configurations to your cloud account. For more details, please refer to GDMS Networking – User Guide.

Failover Master

In a Master-Slave architecture, having a backup Master is critical for redundancy and failover function, thus, and in order to avoid a single point of failure in your wireless network, you can specify a slave AP as failover master. Whenever it detects the master is down, it will promote itself as failover master within a time frame of around 20~30 minutes by entering failover mode. After then, if the master AP comes back, failover master will automatically go back to slave mode, or if the master does not come back to alive, Administrator can login using “failover” account to turn the failover master as true master and take over all controls.

Failover Master

Users could select the Failover Master by following below steps:

Log into Web GUI of the Master access point then navigate to Access points → Configuration then click on and finally select the candidate access point from the drop-down list to be used as a Failover AP.

Failover AP

Failover Mode

Once Failover slave has been selected, the primary master will send the configuration of the network to the Failover slave and the slave will start monitoring the status of the primary master to detect any failure for any reason (network connection loss, power outage).

In case of failure, the Failover slave will promote itself to a temporary backup master while waiting for the primary master to come back.

During the Failover mode users could access the web GUI of the Failover slave using a special Failover account with same admin password.

  • Username = failover
  • Password = admin password
Failover Mode GUI

The Failover mode has only read permission on the configuration and limited options, users still can reboot other slave Access points in case it is needed.

Users also can press on « Switch to Master » button to set the Failover slave as the new primary master of the wireless network, once this is done they have full write permission control over the web GUI option as usual. Use that button to switch to master and takeover the rest of the APs.

Important notes

If you click « Switch to Master », this would be become a non-revertible behavior. Failover Slave will become actual master and the prior master cannot take back the control anymore.

When Failover Slave is switched to Master, you will use the Prior Master AP credentials: username: admin, and the admin password.

Otherwise, when original master comes back online, then Failover Slave will become slave again to prior original Master.

Takeover Feature

This feature is used to re-pair the slave APs whose master has gone offline with another master AP in the same subnet. Please follow the steps to takeover slave APs from another master:

Step 1. Log in to the Web GUI of Master and click on “Discover APs” on the Access Points Page.

Takeover Step 1

Step 2. Select the one or multiple APs to be taken over then click on the “takeover” button of the target AP.

Takeover Step 2

Step 3. Enter the Takeover key which is the admin password of the previous master AP.

Takeover Step 3

Transfer to Master

From the Master Access Point, the Administrator does have the capability to assign any Slave Access point to become the new Master to manage all the already paired Access points.

Navigate to Web UI → Access Points → Status, refer to the figure below:

Switch to Master

Click on button, the following warning message will prompt to confirm the procedure:

Transfer Master Role to another device confirmation message

When the process is finished, the original Master will turn to be a slave for the new Assigned Master and to log in to the new Master AP web interface, you will need to use the previous Master Admin password.

The new assigned Master AP web interface
Note

All the previously existed paired APs will be provisioned with the new Master AP.
The Switch to Master option is unlimited action and does not require any reset for the already paired APs.

Client Bridge

The Client Bridge feature allows an access point to act as a wireless bridge and connect the wired-only clients to the wireless network. When an access point is configured in this way, it will share the Wi-Fi connection to the LAN ports directly. This is not to be confused with a mesh setup. The configured AP will not accept wireless clients in this mode.

Once an SSID has the Client Bridge Support enabled, the AP adopted in this SSID can be turned into Bridge Client mode by click the then the Bridge button .

Please note that once an AP is turned into Client Bridge mode, it cannot be controlled by a Master anymore, and a factory reset is required to turn it back into normal AP mode.

Client Bridge
Client Bridge

To verify, you may access the bridged AP configuration, then under Status, the option “Client Bridge Mode” would be set to Isolated as shown in the figure down below:

Client Bridge Mode
Important notes

The access point that will be operating on bridge mode, must be set with a fixed IP address before activating the bridge mode on the access point.

Users must enable client bridge support option under SSID or SSID Wi-Fi settings in order to have it fully functional.

The Client Bridge requires the SSID to not have any VLAN ID enabled

USING GWN76xx AS SLAVE ACCESS POINT

GWN access points can be paired as a slave to a master, this master can be another GWN access point, GWN router, or GDMS Networking/GWN Manager.

If the GWN access point is added to either GDMS Networking or GWN Manager, the Speed Test feature will be available to users. Please for more details check GWN Management Platforms – User Guide (Configure a GWN Access Point).

Slave Mode allows the users to access specific service and system settings.

GWN76xx slave login page

Notes:

  • If the AP is slave to a Master controller, the default username is admin, and the default password is the master AP’s password.
  • If the AP is paired to the GDMS Networking the default username is admin, and the default password is the SSH Password (GDMS Networking → System → Settings).
Slave AP Web Interface

Service

The TR-069 interface page allows the settings to enable remote and safe configuration of network devices. Refer to section [TR-069] for details regarding each field.

Slave AP Service Settings

System

The system section provides access to the Manager settings and Debug sections.

Manager Settings

The Master (Manager Address) and Port can be found here to GWN76xx AP be discovered by the Manager.

Manager Settings

Manager Address

Enter the IP address of the GWN Manager

Manager Port

Enter the port set for the GWN Manager

Allow DHCP Option 43 Override Manager Address

This configuration will not be effective if AP has been managed by cloud.

Manager settings

Debug

Slave AP debug

Core Files
when a crash event happens on the unit, it will automatically generate a core dump file that can used by the engineering team for debugging purposes.


Ping/Traceroute
Allows the users to Ping and traceroute. Input the target’s IP address or URL and click on run.


One key Debug
Allows to capture Wireless, Portal, or Mesh traffic and logs will be found in Core Files.


SSH Remote Access
Enables the SSH remote access on the slave AP.


Log
Allows the users to retrieve the logs generated for troubleshooting purposes.

ACCESS POINTS

From the access points page, the administrator can monitor different information regarding the access points of the selected network, this section is separated into 2 sub-sections: Status and Configuration.

Status

The Status page lists all the access points assigned to the selected network, along with the possibility to perform some basic operations such as locating the device (LEDs start blinking in White) or clearing the usage data, also users can check more detailed information about each access point and benefit from useful debugging tools which can help diagnose issues when they appear.

Access Points Status

To get more detailed information about the status of a specific access point, users can click on the desired AP then a page similar to the following will show up:

AP Info

The first tab “Info” shows general information about the access point such as the firmware version, IP address, Uptime, etc. The second tab “Current Client” displays the clients connected to this AP and the last tab is used by administrator for debugging purposes and provides the following tools:

  • Core Files, when a crash event happens on the unit, it will automatically generate a coredump file that can used by engineering team for debugging purposes.
  • Ping/Traceroute tools, such as the ping utility, traceroute tool.
  • Capture helps to capture traffic based on duration, interface, protocol, MAC address, IP address and ports, and there is also the option for custom rules.
  • One Key Debugging, to capture Wireless, Portal or Mesh traffic and logs will be found in Core Files.
Debug Tool Tab

Configuration

The configuration page allows the administrator to Upgrade, Reboot, Add to SSIDs, Configure, Transfer network group, Transfer AP, Discover AP, Failover.

Configuration Page

Upgrade

Select slave AP(s) to upgrade and press button.

Refer to [Upgrading Slave Access Points] for more details.

Reboot slave AP

To reboot a slave AP, select it then click on button. the below confirmation message will be displayed:

Reboot Access Point

Move Access Points

The administrator can move GWN Access points from one network to another. Click on Move button and the following window will popup, select the network where to move the access point and click on move.

Moving Access Points between Networks

Delete Access Points

To delete an access point, select it, then click on reboot button, the following confirmation message will be displayed:

Delete Access Point

Configure Access Points

To configure an access point, select and click on button. A new config page will popup:

Access Point Configuration Page

The following settings can be configured from this page:

Device Name

Set GWN76xx’s name to identify it along with its MAC address.

Fixed IPv4

Check this option to configure the device with a static IP configuration; it must be in the same subnet with the default Network Group; Once enabled, these fields will show up: IPv4 Address/IPv4 Subnet Mask/IPv4 Gateway/Preferred IPv4 DNS/Alternate IPv4 DNS.

Fixed IPv6

Check this option to configure the device with a static IP configuration; it must be in the same subnet with the default Network Group; Once enabled, these fields will show up: IPv6 Address/IPv6 Prefix Length/IPv6 Gateway/Preferred IPv6 DNS/Alternate IPv6 DNS.

LED

Configure the LED: Four options are available: Use System Settings, Always on, Always off, or Schedule.

Band Steering

Band Steering will help redirect clients to a radio band 2.4G or 5G, depending on what is supported by the device, to increase efficiency and benefit from the maximum throughput.

Four options are allowed:

• Disable Band steering: This will disable the band steering feature and the access point will accept the band chosen by the client.

• 2G in Priority: 2G Band will be prioritized over 5G Band.

• 5G in Priority: 5G Band will be prioritized over 2G Band

Balance: Band Steering will balance between the clients connected to 2G and 5G.

• Use Radio Settings: GWN will use the value configured under Radio page.

Enable Schedule

Configure a schedule for when the Wi-Fi will be ON or Off, by default it is disabled. The user can enable it and select a schedule from the drop-down list or use radio settings.

WLAN Hardware Acceleration

This setting enables or disables hardware acceleration for WLAN operations. When enabled, the access point utilizes hardware resources to accelerate WLAN processing, potentially improving performance.

Options:

  • Enabled: Activates hardware acceleration.

  • Disabled: Deactivates hardware acceleration.

Note: Changes to this setting will take effect after the device reboots.

Fast SSID Build

When enabled and there are fewer than 8 SSIDs on the access point, creating or deleting SSIDs takes effect more quickly. This setting controls how fast the AP rebuilds SSIDs and can inherit the value from the radio settings.

Note: This feature is not supported on SSIDs using MLO or WPA2/WPA3 with PPSK without RADIUS. This option is also available on model GWN7674.

Port Aggregation

Enables bonding of Ethernet ports into a single logical uplink. Increases total bandwidth and provides link redundancy.

Note: Must be supported on the peer device.

Link aggregation Type 

Select the bonding method:
LACP (dynamic negotiation) or Static (manual config).

Note: Both sides must match to form a valid link group.

Disable Port

Select “NET” from the drop-down list to disable the Ethernet the NET port.

Link Type

If GWN76xx access point is connected to a router or a switch, the NET/PoE port can by configured as a Trunk or Access.

Note: The hardware specifications of the access point model determine the number of ports, their types and speeds.

PVID

Configures the VLAN ID of the port

Allowed VLAN(s)

Configure the VLAN ID(s) allowed to pass through the port. Multiple VLAN IDs can be entered such as 1,2,3,7. Up to 16 VLAN IDs can be configured. If no value is configured, the port allows all VLANs

2.4G/5G  (802.11b/g/n/ax)

Disable 2.4GHz/5GHz

This feature allows the user to disable/enable its 2.4GHz/5GHz band on the AP.

Channel Width

Choose the Channel Width, note that wide channels will give better speed/throughput, and narrow channel will have less interference. 20Mhz is suggested in a very high-density environment. Default is “Use Radio Settings”, the AP then will use the value configured under the Radio page.

Channel

Select Use Radio Settings, or a specified channel, default is Auto. Note that the proposed channels depend on Country Settings under System Settings → Maintenance. Default is “Use Radio Settings”, the AP then will use the value configured under Radio page.

Radio Power

Set the Radio Power depending on the desired cell size to be broadcasted, five options are available: “Low”, “Medium”, “High”, “Custom” and “Use Radio Settings”.

The default is “Use Radio Settings”, the AP then will use the value configured under the Radio page

Enable Minimum RSSI

Configure whether to enable/disable Minimum RSSI function. This option can be either Disabled or Enabled and set manually or set to Use Radio Settings.

Minimum Access Rate Limit

Specify whether to limit the minimum access rate for clients. This function may guarantee the connection quality between clients and APs. This option can be either Disabled or Enabled and set manually or set to Use Radio Settings.

Wi-Fi5 Compatible Mode

Some old devices do not support Wi-Fi6 well and may not be able to scan the signal or connect poorly. After turning on this switch, it will switch to Wi-Fi5 mode to solve the compatibility problem. At the same time, it will turn off Wi-Fi6 related functions.

Access Point Configuration Settings

Note:

The administrator can filter access points by Model or search by name/MAC of the device. Click on Save Button to save the changes and apply them to the AP.

Reset Access Points

To reset an access point, select and click on button, a confirmation message will be displayed, click on to confirm the operation.

Reset Access Point

SSID

When using GWN76XX as Master Access Point, users can create different SSIDs and assign GWN76XX Slave Access Points to them.

Log in as Master to the GWN76XX Web GUI and go to SSID.

SSID

Click on “Add” button to add a new SSID.

Add a new SSID

When editing or adding a new SSID, users will have two tabs to configure:

  • Wi-Fi: Please refer to the below table for Wi-Fi tab options

Basic

SSID

Set or modify the SSID name.

Enable SSID

Check to enable Wi-Fi for the SSID.

Client IP Assignment

If set to Bridge mode, it allows the AP to pass the client’s traffic to the network without modifying it, making the AP function transparently.

If set to NAT mode, clients will get the IP addresses from the specified NAT pool. And clients connected to different APs are isolated from each other.

VLAN

Click to enable VLAN, this option is only availabe is Client IP Assignment is set to Bridge.

VLAN ID

Enter the VLAN ID corresponding to the SSID. This is available when Client IP Assignment is set to Bridge and VLAN is enabled.

SSID Band

Select the Wi-Fi band the GWN AP will use: 2.4GHz, 5GHz, or 6GHz for Wi-Fi 6E models.

Enable MLO

Enables Multi-Link Operation (MLO), which allows simultaneous use of multiple links (e.g., on 2.4GHz, 5GHz and 6GHz) to enhance throughput and reliability.

Note: Supported only on the Wi-Fi 7 AP.

Access Security

Security Mode

Set the security mode for encryption, 8 options are available:

WEP 64-bit: Using a static WEP key. The characters can only be 0-9 or A-F with a length of 10, or printable ASCII characters with a length of 5.

WEP 128-bit: Using a static WEP key. The characters can only be 0-9 or A-F with a length of 26, or printable ASCII characters with a length of 13.

WPA/WPA2: Using “PSK” or “802.1x” as WPA Key Mode, with “AES” or “AES/TKIP” Encryption Type.

WPA2: Using “PSK”, “PPSK” or “802.1x” as WPA Key Mode, with “AES” or “GCMP-128” Encryption Type.

WPA2/WPA3: Using “SAE-PSK” or “802.1x” as WPA Key Mode, with “AES” or “GCMP-128” Encryption Type.

WPA3: Using “SAE” or “802.1x” as WPA Key Mode, with “AES” or “AES/TKIP” Encryption Type.

WPA3-192: Using “802.1x” as WPA Key Mode, with “GCMP-256” or “CCMP-256” Encryption Type.

OSEN: This mode is used with release 2 of Hotspot 2.0 Release 2 OSU (Online Signup Server) for client provisioning.

Open: No password is required. Users will be connected without authentication. Not recommended for security reasons.

Note: GWN products support for 802.1x (PEAP-MSCHAPv2 and EAP-TLS) requires external AAA server to permit authentication and centralized access management.

WEP Key

Enter the password key for WEP protection mode. This field is available only when “Security Mode” is set to “WEP 64-bit” or “WEP 128-bit”.

WPA Key Mode

Three modes are available:

PSK: Use a pre-shared key to authenticate to the Wi-Fi.

802.1X: Use a RADIUS server to authenticate to the Wi-Fi.

PPSK: Allow admin to configure Private Pre-Shared Key as an alternative to 802.1X authentication.

Note: PPSK is supported only when the “Security Mode” is set to WPA2.

PPSK management is available at Access Control → PPSK.

WPA Encryption Type

Two modes are available:

AES: This method changes dynamically the encryption keys making them nearly impossible to circumvent.

AES/TKIP: use both Temporal Key Integrity Protocol and Advanced Encryption Standard for encryption, this provides the most reliable security.

Note: This field is available only when “Security Mode” is set to “WPA/WPA2” , “WPA2”, “WPA2&WPA3”, “WPA3” or “WPA3-128”.

WPA Pre-Shared Key

Set the access key for the clients, and the input range should be: 8-63 ASCII characters or 8-64 hex characters. This field is available only when “Security Mode” is set to “WPA/WPA2”, “WPA2”, “WPA2/WPA3” or “WPA3”.

802.11w

The 802.11w standard is used to prevent certain types of WLAN DoS attacks. 802.11w extends strong cryptographic protection and provides data integrity and replay protection for broadcast/multicast Robust management frames. Users can set this option to Disabled:disable 802.11w; Optional: both the supported and unsupported 802.11w clients may have the network access authority; Required: only the client supported 802.11w have the network access authority.

MAC-Based RADIUS

Once enabled, the client MAC address will be used as the username and password for access control through the RADIUS server.

RADIUS Sever Address

Configure RADIUS authentication server address. This field is available only when “WPA Key Mode” is set to “802.1x”.

RADIUS Server Port

Configure RADIUS Server Listening port. Default is: 1812. This field is available only when “WPA Key Mode” is set to “802.1x”.

RADIUS Server Secret

Enter the secret password for client authentication with RADIUS server. This field is available only when “WPA Key Mode” is set to “802.1x”.

Secondary RADIUS Server

Check the box to enable settings a secondary RADIUS server. Then you need to specify below three fields:

RADIUS Server Address: Enter the secondary RADIUS server address.

RADIUS Server Port : Enter the secondary RADIUS server port. The default port is 1812 and the range is 1-65535.

RADIUS Server Secret: Enter the secret password for client authentication with the secondary RADIUS server.

RADIUS Accounting Server

Configure the address for the RADIUS accounting server. This field is available only when “WPA Key Mode” is set to “802.1x”.

RADIUS Accounting Server Port

Configure RADIUS accounting server listening port. Default is 1813. This field is available only when “WPA Key Mode” is set to “802.1x”.

RADIUS Accounting Server Secret

Enter the secret password for client authentication with RADIUS accounting server. This field is available only when “WPA Key Mode” is set to “802.1x”.

Secondary RADIUS Accounting Server

Check the box to enable settings for a secondary RADIUS accounting server. Then you need to specify below three fields:

RADIUS Accounting Server Address: Enter the secondary Accounting RADIUS server address.

RADIUS Accounting Server Port: Configures the secondary RADIUS accounting server listening port. Default is 1813.

RADIUS Accounting Server Secret: Enter the secret password for client authentication with the secondary RADIUS accounting server

RADIUS NAS ID

Enter the RADIUS NAS ID. This field is available only when “WPA Key Mode” is set to “802.1x”.

Enable Hotspot2.0

Check to activate Hotspot2.0 in the SSID. This field is available only when “WPA Key Mode” is set to “802.1x”. Refer to [Hotspot 2.0] for more details

Hotspot2.0 Profile

Select the Hotspot2.0 profile to use in the SSID. This field is available only when “WPA Key Mode” is set to “802.1x”. Refer to [Hotspot 2.0] for more details

Enable Captive Portal

Click on the checkbox to enable the captive portal feature.

Use MAC Filtering

Choose Blacklist/Whitelist to specify MAC addresses to be excluded /included from connecting to the zone’s Wi-Fi.

Default is Disabled.

MAC Blacklist/Whitelist

This option is only available if Use MAC Filtering is set to Whitelist/Blacklist.

Note: Clients in the selected access list can not access to the SSID. Total limited to 1024, contained the Global Blacklist.

Enable Dynamic VLAN (beta)

When enabled, clients will be assigned with an IP address from corresponding VLAN configured on the RADIUS user profile. This field is available only when “WPA Key Mode” is set to “802.1x”.

Client Isolation

Client isolation feature blocks any TCP/IP connection between connected clients to GWN76XX. Client isolation can be helpful to increase security for Guest networks/Public Wi-Fi. Three modes are available:

Radio: Wireless clients can access to the internet services, GWN7xxx router and the access points GWN76XX but they cannot communicate with each other.

Internet: Wireless clients will be allowed to access only the internet services and they cannot access any of the management services, either on the router nor the access points GWN76XX.

Gateway MAC: Wireless client scan only communicate with the gateway, the communication between clients is blocked and they cannot access any of the management services on the GWN76XX access points.

Custom MAC: customized MAC address, other wireless STAs are isolated. The gateway MAC address must be included in the customization.

Custom MAC Address

This field allows you to specify the custom MAC addresses that need to be isolated.

Note: The gateway MAC address must also be included.

Example: c0:74:ad:33:44:55, c0:74:ad:99:AA:BB

Plus (+) Icon: Click this icon to add a new MAC address to the list.
Minus (-) Icon: Click this icon to remove a MAC address from the list.

OS Filtering

The OS Filtering option allows you to control access to the network based on the operating system of the client devices. This feature can be set to either blacklist or whitelist specific operating systems.

Options:

• Disabled: No filtering based on the operating system (default).
• Blacklist: Blocks devices with specified operating systems from accessing the network.
• Whitelist: Allows only devices with specified operating systems to access the network.

OS Whiltelist/Blacklist

Depending on the selected mode (Blacklist or Whitelist) for OS Filtering, you can specify which operating systems to block or allow.

Available OS options:

• All
• Windows
• macOS
• iOS
• Linux
• Android

Advanced

SSID Hidden

Select to hide SSID. SSID will not be visible when scanning for Wi-Fi, to connect a device to hidden SSID, users need to specify SSID name and authentication password manually.

DTIM Period

Configure the frequency of DTIM (Delivery Traffic Indication Message) transmission per each beacon broadcast. Clients will check the AP for buffered data at every configured DTIM Period. You may set a high value for power saving consideration.  Default value is 1, meaning that the AP will have DTIM broadcast every beacon. If set to 10, AP will have DTIM broadcast every 10 beacons. Valid range: 1 – 10.

Wireless Client Limit

Configure the limit for wireless clients. If there is a SSID per-radio on a LAN, each SSID will have the same limit. For example, setting a limit of 50 will limit EACH ssid to 50 users independently.

Note: If set to 0, it disables the limit.

Client Inactivity Timeout(s)

AP will remove the client’s entry if the client generates no traffic at all for the specified time period. The client inactivity timeout is set to 300 seconds by default. Range from 60-3600 seconds.

Client Bridge Support

Configure the Client Bridge Support to allow the access point to be configured as a bridge to connect wired only clients wirelessly to the network. When an access point is configured in this way, it will share the Wi-Fi connection to the LAN ports directly. Once an SSID has Client Bridge Support enabled, the AP adopted in this SSID can be turned into Bridge Client mode by clicking the Bridge button.

Client Time Policy

Select a time policy to be applied to all clients connected to this SSID.

Multicast/Broadcast Suppression

When set as “Disabled”: all of the broadcast and multicast packages will be forwarded to the wireless interface.

When set as “Enabled”: all of the broadcast and multicast packages will be discarded except DHCP/ARP/IGMP/ND;

When set to “Enable with Proxy ARP enabled”: AP will enable the optimization with Proxy ARP enabled in the meantime.

Convert IP multicast to unicast

When set as “Disabled”: none of the multicast package will be converted;

When set as “Passive mode”: AP will never initiatively broadcast IGMP queries, and the IGMP snooping item will be aged out 300 seconds after it is registered, which may result in the failure of forwarding multicast data.

When set as “Active mode”: AP will initiatively broadcast IGMP queries to keep updating of the IGMP snooping items.

Enable Schedule

Enable this option to assign a schedule for the bandwidth rule.

Schedule

Within the time of schedule, SSID can be used.

Enable Voice Enterprise

Check to enable/disable Voice Enterprise. The roaming time will be reduced once enabled voice enterprise.

• The 802.11k standard helps clients to speed up the search for nearby APs that are available as roaming targets by creating an optimized list of channels.

• When the signal strength of the current AP weakens, your device will scan for target APs from this list. When your client device roams from one AP to another on the same network, 802.11r uses a feature called Fast Basic Service Set Transition (FT) to authenticate faster. FT works with both pre-shared key (PSK) and 802.1X authentication methods.

• 802.11v allows client devices to exchange information about the network topology, including information about the RF environment, making each client network aware, facilitating overall improvement of the wireless network.

Note: 11R is required for enterprise audio feature, 11V and 11K are optional. This field is available only when “Security Mode” is set to “WPA/WPA2” or “WPA2”.

Enable 11R

Check to enable 802.11r. This field is available only when “Security Mode” is set to “WPA/WPA2” or “WPA2”.

Enable 11K

Check to enable 802.11k

Enable 11V

Check to enable 802.11v

ARP Proxy

This option will enable GWN AP to answer the ARP requests from the LAN for its connected Wi-Fi clients. This is mainly to reduce the airtime consumed by ARP Packets.

Enable U-APSD

This option will allow the user to enable/disable the Unscheduled Automatic Power Save Delivery feature.

Enable Bonjour Gateway

Once enabled, the client Bonjour on the SSID is forwarded to the VLAN of the Bonjour service (such as Samba). Not supported on GWN7610, GWN7600/GWN7600LR.

Target Wakeup Time

Configure whether to enable TWT (target wake up time) .Some terminal drivers are old and may have compatibility issues after being enabled.

Note: Only take effect for WIFI6 models.

Enable Multi-VLAN

Enable Multi-VLAN for this SSID to assign different VLANs to connected devices.

When enabled, specify the VLAN ID and associate it with AP devices connected to this SSID.

Use the plus (+) icon to add new VLANs and APs, and the minus (−) icon to remove them.

Note:  This Multi-VLAN will have higher priority than the SSID VLAN.

SSID – Wi-Fi

  • Device Membership: Used to add or remove paired access points to the SSID. The MAX SSID number is separately counted for each band (2.4GHzor 5Ghz).

The maximum allowed SSID for each band now is as below:

ModelMAX SSID
GWN7610/GWN7600(LR)32
MAX SSID on each band
Graphical user interface, application Description automatically generated
Device Membership

Click on to add the GWN76XX to the SSID or click on to remove it.

Wi-Fi Phones (WP) series device fast configuration

This feature helps to quickly create and configure SSID based on Wi-Fi phones (WP series) default configurations, WP phones come by default with an SSID name and password.

Navigate to SSIDs page, then click on Configure WP Series Devices button as shown below:

SSIDs → Configure WP Series Devices

Specify the timeout duration for SSID (wp_master) to be visible, if no device was connected during that period then it will be disabled, the timeout duration is in minutes within the range of 10-1440 minutes.

Configure WP Series Devices Timeout

Click “Save” button, and use a WP phone to connect to the SSID (wp_master).

The SSID default password is already pre-configured with the WP phone.

WP phone

For more details visit: https://documentation.grandstream.com/knowledge-base/wp816-user-guide/#auto-connection

CLIENTS

Users can access clients list connected to GWN76XX from Web GUI Clients to perform different actions to wireless clients.

Clients
  • Click on under Actions to check client’s status and modify basic settings such Device’s Name.
  • Click on to block a client’s MAC address from connecting to the zone’s SSID.
  • Click on to release Wi-Fi offline client IP lease.

Users can press button to customize items to display on the page. Following items are supported:

Clients Select Items

ACCESS CONTROL

Access List

From this menu, users can manage the blacklist of clients that will be blocked from accessing the Wi-Fi network globally, click on “Edit” icon as shown below to add/remove MAC addresses of the client to/from global blacklist.

Global Blacklist
Managing the Global Blacklist

A second option is to add custom access lists that will be used as matching mechanism for MAC address filtering option under SSIDs to allow (whitelist) or disallow (blacklist) clients access to the Wi-Fi network.

Click on “Add” button in order to create new access list, then fill it with all MAC addresses to be matched.

Adding Client Access List
Note:

The total number of entries is limited to 1024, including the Global Blacklist. For the GWN7600, GWN7610.

Users can also Import/Export the client access lists in CSV format as shown below:

ImportExport the client access

Users can check « Enable Schedule » to assign a schedule to the list and set the time it will take effect.

Adding New Access List

Once this is done, this access list can be used under SSID Wi-Fi settings to filter clients either using whitelist or blacklist mode.

Use MAC Filtering

Time Policy

The timed client disconnect feature allows the system administrator to set a fixed time for which clients should be allowed to connect to the access point, after which the client will no longer be allowed to connect until the user configurable cool-down period is reached.

The configuration is based on a policy where the administrator can set the amount of time for which clients are allowed to connect to the Wi-Fi. The administrator can also set the reconnect type and value for the users  to reconnect after they have been disconnected.

To create a new policy, go under Captive Portal  →  Time Policy and add new one.

Then set the following parameters:

OptionDescription
NameEnter the name of the policy.
EnabledCheck the box to enable the policy.
Limit Client Connection TimeSet the amount of time a client may be connected.
Client Reconnect Timeout TypeSelect the method with which we will reset a client’s connection timer so they may reconnect again. Options are: Reset Daily. Reset Weekly. Reset Hourly. Timed Reset.
Client Reconnect TimeoutIf “Timed Reset” is selected, this is the period for which the client will have to wait before reconnecting.
Day of the WeekIf “Reset Weekly” is selected, this is the day when the reset will be applied.
Hour of the DayIf “Reset Weekly” or “Reset Daily” is selected, this is the hour and day when the reset will be applied.
Time Policy Parameters
Note:

Time tracking shall be accounted for on a per-policy basis, such that a client connected to any SSID assigned the time tracking policy will accrue a common counter, regardless of which SSID they are connected to (as long as those SSIDs all share the same time tracking policy).

Banned Clients

The clients that have been banned after time disconnect feature has taken effect, these clients will not be allowed to connect back until timeout reset or you can unblock a client by clicking on the icon.

BanUnban Client

Bandwidth Rules

The bandwidth rule is a GWN76XX feature that allows users to limit bandwidth utilization per SSID or client (MAC address or IP address).

This option can be configured from the GWN76XX WebGUI under “Bandwidth Rules”.

The following figure shows an example of MAC address rule limitation.

Graphical user interface, application Description automatically generated
MAC Address Bandwidth Rule

Click to add a new rule, the following table provides an explanation about different options for bandwidth rules.

FieldDescription
EnabledEnable/Disable the Bandwidth rule.
SSIDSelect which SSID will be affected by the bandwidth rule limitation.
Range ConstraintChoose the type of rule to be applied on bandwidth utilization from the dropdown list, three options are available: Per-SSID: Set a bandwidth limitation on the SSID level. Per-User: Set a bandwidth limitation per Client. MAC: Set a bandwidth limitation per MAC address. IP Address: Set a bandwidth limitation per IP address.
MACEnter the MAC address of the device to which the limitation will be applied, this option appears only when MAC type is selected.
IP addressEnter the IP address of the device to which the limitation will be applied, this option appears only when IP Address type is selected.
Enable ScheduleEnable this option to assign a schedule for the bandwidth rule.
Upload LimitSpecify the limit for the upload bandwidth using Kbps or Mbps.
Download LimitSpecify the limit for the download bandwidth using Kbps or Mbps.
Bandwidth Rules

The following figure shows examples of bandwidth rules:

Bandwidth Rules

The same settings for bandwidth management are available from the following menus:

Navigate on the web GUI under “Clients → Edit → Bandwidth Rules” where you can set the Upstream and Downstream rate in Mbps.

Private Pre-Shared Key (PPSK)

PPSK (Private Pre-Shared Key) is a way of creating Wi-Fi passwords per group of clients instead of using one single password for all clients. It’s also possible to assign it for one single device client with a MAC Address.

Note:

  • Before adding a PPSK account, first create an SSID with WPA Key Mode set to “PPSK Without RADIUS or with RADIUS” under Web UI → SSIDs.
  • The maximum number of allowed PPSK accounts is 300.

To configure PPSK, please navigate to Web UI → Access Control → PPSK, then click on “Add” button to add a new PPSK account.

Add a PPSK Profile

In case where the Maximum Number of Access Clients set to 1, then an option to specify a MAC Address is added. Please refer to the figure below:

PPSK Maximum Number of Access Clients

SSID

Select the SSID from the drop-down list

Note: the SSID WPA Key Mode must be set to “PPSK Without RADIUS or With RADIUS“.

Account

Set a name for this PPSK profile.

Wi-Fi Key

Enter a Wi-Fi key.

Confirm Wi-Fi Key

Confirm the Wi-Fi key (must be the same)

Maximum Number of Access Clients

Enter the maximum number of access clients (devices) that are allowed to use this key, once the maximum number is reached, the key will not be used to connect to Wi-Fi.

MAC

In case the maximum number of access clients is set to 1, then the user can specify the MAC address as well for even more security.

Upload Limit

set a max upload limit (Mbps/Kbps)

Download Limit

set a max download limit (Mbps/Kbps)

VLAN

specify a VLAN or leave it empty (Default VLAN).

Description

Enter a descritpion for this PPSK profile.

PPSK

CAPTIVE PORTAL

Captive Portal feature on GWN76XX AP helps to define a Landing Page (Web page) that will be displayed on Wi-Fi clients’ browsers when attempting to access Internet. Once connected to a GWN76XX AP, Wi-Fi clients will be forced to view and interact with that landing page before Internet access is granted.

The Captive Portal feature can be configured from the GWN76XX Web page under “Captive Portal”.

The page contains following sub-menus: Guest, Policy List, Splash Page and Vouchers.

Guest

This section lists the clients connected or trying to connect to Wi-Fi via Captive Portal.

Captive Portal Guest Page

Click on “Kick out” button to kick out connected clients.

Users can press button to customize items to display on the page. Following items are supported:

Captive Portal Guest Page Select Items

Policy List

Users can customize a portal policy in this page.

Captive Portal Policy List
  • Click on to edit the policy.
  • Click on to delete the policy.
  • Click on to add a policy.

The policy configuration page allows adding multiple captive portal policies which will be applied to SSIDs and contains options for different authentication types. A splash page can be easily configured as shown in the next section.

Administrator can use an internal or external splash page.

Add a New Policy

Internal Splash Page

Below table lists the items policy add page configures

Name

Enter the name of the Captive Portal policy

Splash Page

Select Splash Page type, in this case “Internal”

Authentication Type

The following types of authentications are available:

  • Log in for free: when choosing this option, the landing page feature will not provide any type of authentication instead, it will prompt users to accept the license agreement to gain access to the internet.

  • Radius Server: Choosing this option will allow users to set up a RADIUS server to authenticate connecting clients.

  • Social Login Authentication: Choosing this option will allow users to enable authentication on Facebook, Twitter, or Google.

  • Vouchers: Choose this page when using authentication via Vouchers.

  • Login with password: Choose this page when using authentication via a password.

  • SAML SSO: Choosing this option will allow users to authenticate clients using SSO Server.

  • Active Directory: Choosing this option will allow users to set up an Active Directory server to authenticate connecting clients.

Client Expiration

Configure the period of validity, after the valid period, the client will be re-authenticated again.

Note: the maximum duration is 30 days.

Client Idle Timeout

Configure the time when the client will automatically deauthenticate when it is idle. This does not apply to Voucher Captive portal mode.

Note: the maximum duration is 24 hours.

Unauthenticated Client Timeout

Configure a timeout period, after which unauthenticated client devices will be disconnected, and reconnection is not allowed.

Note: the maximum duration is 24 hours.

If Authentication Type is set to RADIUS Authentication

RADIUS Server Address

Fill in the IP address of the RADIUS server.

RADIUS Server Port

Set the RADIUS server port, The default value is 1812.

RADIUS Server Secret

Fill in the key of the RADIUS server.

Radius Authentication Method

Select the RADIUS authentication method, 3 methods are available: PAP, CHAP and MS-CHAP.

Radius Retry Timeout(s)

Set the timeout for each authentication request sent to the Radius server. The valid range is 1 to 120 seconds.

Radius Retries

Set the maximum number of retires to send an authentication request for the Radius server. The valid range is 1 to 5.

If Authentication Type is set to “Social Login Authentication”

Facebook

Check to enable/disable Facebook Authentication

Facebook App ID

Fill in the Facebook App ID.

Facebook APP Secret

Set the key for the portal, once clients want to connect to the Wi-Fi, they should enter this key.

Twitter

Check this box to enable Twitter Authentication.

Force to Follow

If checked, users need to Follow owner before been authenticated.

Consumer Key

Enter the app Key to use Twitter Login API.

Consumer Secret

Enter the app secret to use Twitter Login API.

Google

Check this box to enable Google Authentication.

Google Client ID

Enter the Client Id to use Google Login API.

Google Client Key

Enter the Client Key to use Google Login API.

If Authentication Type is set to “Login with password”

Login with password

Specify a password for the captive portal.

If Authentication Type is set to “SAML SSO”

SSO Server URL

Fill in the IP address of the SSO server.

Redirect URL

Enter the redirect URL.

X.509 Cert SHA1 Fingerprint

enter the X.509 Cert SHA1 Fingerprint

If Authentication Type is set to “Active Directory”

AD Server URL

Specify Active Directory URL

Redirect URL

Enter the redirect URL

X.509 Cert SHA1 Fingerprint

enter the X.509 Cert SHA1 Fingerprint

For all Authentication Types

Use Default Portal Page

If checked, the users will be redirected to the default portal page once connected to the GWN.• If unchecked, users can manually select which Portal Page to use from Portal Page Customization drop-down list.

Portal Page Customization

Select the customized portal page from the drop-down list (if “Use Default Portal Page” is unchecked).

Landing Page

Choose the landing page, 2 options are available:

  • Redirect to the Original URL.

  • Redirect to External Page.

The Redirect External Page URL Address

Once the landing page is set to redirect to external page, user should set the URL address for redirecting.This field appears only when Landing Page is set to “Redirect to an External Page”.

Enable Daily Limit

  • Disabled: Non -day access limit.

  • According to the client limit: After opening, only the Guest is allowed to be connected once a day, and it is not allowed to authenticate again after the network use timeout.

  • Limit by authentication: The guest is accessed once a day to any authentication method. Refresh the number of times every day.

Enable HTTPS Redirection

Check to enable/disable HTTPS service. If enabled, both HTTP and HTTPS requests sent from stations will be redirected by using HTTPS protocol. And station may receive an invalid certification error while doing HTTPS browsing before authentication. If disabled, only the HTTP request will be redirected.

Enable Secure Portal

Enable Secure Portal: If enabled, unauthorized guests will be redirected to the splash page by using HTTPS protocol. If not, the HTTP protocol will be used.

Captive Portal – Policy List – Splash Page is “Internal”

Notes:

If Facebook authentication is configured, you will need to log in your Facebook account of https://developers.facebook.com/apps , and set the OAuth redirect to : https://cwp.gwn.cloud:8443/GsUserAuth.cgi?GsUserAuthMethod=3

2. If Twitter authentication is configured, you will need to log in your Twitter account of https://apps.twitter.com/app, and set the callback URLs to: http://cwp.gwn.cloud:8080/GsUserAuth.cgi

External Splash Page

FieldDescription
NameEnter the name of the Captive Portal policy
Splash PageSelect Splash Page type, in this case “External”
External Splash Page URLEnter the External Splash Page URL, and make sure to enter the pre-authentication rules request by the external portal platform in the pre-authentication configuration option.
RADIUS Server AddressFill in the IP address of the RADIUS server.
RADIUS Server PortSet the RADIUS server port, the default value is 1812.
RADIUS Server SecretFill in the key of the RADIUS server.
RADIUS Accounting ServerConfigures the address for the RADIUS accounting server address.
RADIUS Accounting Server PortConfigures RADIUS accounting server listening port (default is 1813).
RADIUS Accounting Server SecretEnter the secret password for client authentication with RADIUS accounting server.
Accounting Update IntervalEnter Update Interval for RADIUS Accounting Server. The interval unit can be set by seconds, minutes, hours, or days.
RADIUS NAS IDEnter RADIUS NAS ID. This field appears only when Splash Page is set to “External”.
Redirect URLSpecify URL where to redirect clients after authentication.
Captive Portal – Policy List – Splash Page is “External”

In case social media authentication is used, the user needs to allow some traffic between the AP and social medial platforms (Facebook API as example) to send authentication credentials and receive reply, this traffic can be allowed using the Authentication rules which are explained below.

Authentication rules

Pre-Authentication Rules

Using this option, users can set rules to match traffic that will be allowed for connected Wi-Fi users before the authentication process. For example, if users need to set up Facebook authentication, some traffic should be allowed to the Facebook server(s) to process the user’s authentication. Or simply used to allow some type of traffic for unauthenticated users.

Post-Authentication Rules

On the other hand, post authentication rules are used to match traffic that will be banned for Wi-Fi clients after authentication. As an example, if you want to disallow connected Wi-Fi clients to issue Telnet or SSH traffic after authentication then you can set post authentication rules to match that traffic and once a connected client passes the authentication process they will be banned from issuing telnet and SSH connections.

Splash Page

Files configuration page allows users to view and upload HTML pages and related files (images…).

Captive Portal Splash Page

User can add folder in corresponding folder by selecting the folder and click on .

  • Click on to upload a file from local device.
  • Click on to download the files in Captive Portal folder.
  • Click on to edit the corresponding file, in another word, to replace the file with a new one.
  • Click on to delete the file.

Vouchers

Voucher Feature Description

Voucher feature will allow clients to have internet access for a limited duration using a code that is randomly generated from GWN controller.

Note that multiple users can use a single voucher for connection with expiration duration of the voucher that starts counting after first successful connection from one of the users that are allowed.

Another interesting feature is that the administrators can set data bandwidth limitation on each created voucher depending on the current load on the network, users’ profile (VIP customers get more speed than regular ones…etc.) and the internet connection available (fiber, DSL, or cable…etc.) to avoid network congestion and slowness of the service.

Each created voucher can be printed and served to the customers for usage, and the limit is 1000 vouchers.

The usage of voucher feature needs to be combined with captive portal that is explained after this section, in order to have the portal page requesting clients to enter voucher code for authentication.

Voucher Configuration

To configure/create vouchers for clients to use, follow below steps:

  1. On controller web GUI, navigate under “Captive Portal 🡪 Vouchers
  2. Click on button in order to add a new voucher.
  3. Enter voucher details which are explained on the next table.
  4. Press save to create the voucher(s).

Notes:

  • Users can specify how many vouchers to generate with the same profile, this way the GWN will generate as many vouchers as needed with the same settings to avoid creating them one by one.
  • The administrators can verify the status of each voucher on the list (In use, not used, expired …etc.).
  • Press to print the voucher, to delete it or to renew the voucher.
Add Voucher Sample

The below figure shows the list of the vouchers after GWN randomly generates the code for each one.

Figure 84 Vouchers List

Users can click on buttons and to delete and print multiple vouchers or click button to print all vouchers at once.

Also, users can use the drop-down list filter to filter the vouchers that were created at specific date-time.

The following table summarizes description for voucher configuration parameters:

FieldDescription
Create QuantitySpecify how many vouchers to generate with the same profile/settings (duration, bandwidth, and number of users). Valid range: 1 – 1000.
Max DevicesSpecify how many users can use same voucher. Valid range: 1 – 5.
Byte LimitSpecify download byte limit for the voucher. The unit can be either M (Megabyte) or G (Gigabyte). Valid range: 10 – 1048576 (M) 1 – 1024 (G)
DurationSpecify the duration after which the voucher will expire, and clients will be disconnected from the internet. Note: in case of multiple users, the duration will start counting after the first user starts using the voucher.
Validity TimeSet the validity period of the credentials, limited to 1-365. The unit is day.
Download LimitSet the download bandwidth speed limit (in Kbps or Mbps).
Upload LimitSet the upload bandwidth speed limit (in Kbps or Mbps).
NotesNotes for the administrator when checking the list vouchers list.
Voucher Parameters

Using Voucher with GWN Captive Portal

In order to successfully use the voucher feature, users will need to create a captive portal in order to request voucher authentication codes from users before allowing them to access the internet. More details about captive portal will be covered in the next section, for voucher configuration please follow below steps.

  1. Go under “Captive Portal 🡪 Policy List” menu.
  2. Press in order to add new captive portal policy.
  3. Set the following parameters as shown on the screenshot for basic setup then save and apply.
Graphical user interface, text, application, email Description automatically generated
Captive Portal with Voucher authentication

Then go under your SSID configuration page and enable the generated captive portal under Wi-Fi settings tab.

RADIO

When using GWN76XX as Master Access Point, users can edit the frequency band used by the AP and channel used along with the Transmission power for each band.

Log in as Master to the GWN76XX Web GUI and go to Radio.

Radio General

General

Band Steering

Band Steering helps redirect dual-band and tri-band clients to the most appropriate radio band (2.4 GHz, 5 GHz, or 6 GHz, depending on what the access point supports) to improve performance and spectrum utilization.

Four options are available:

  • Disable Band steering: Disables band steering and the access point accepts the band chosen by the client.

  • 2G in Priority: Tri-band / dual-band clients are steered to the 2.4 GHz band when possible.

  • 5G in Priority: Tri-band / dual-band clients are steered to the 5 GHz band when possible.

  • 6G in Priority: Tri-band clients are steered to the 6 GHz band when available, taking advantage of the wider spectrum.

  • Balance: The access point balances client connections across the 2.4 GHz, 5 GHz, and 6 GHz bands based on spectrum utilization.

Note: It is recommended to enable Voice Enterprise on SSIDs that use Band Steering for better roaming and steering behavior.

Client Steering

This feature will help Wi-Fi clients to roam to other APs within the same Network. 

Note: Once enabled, Band Steering in Access Device → Configuration → Configure cannot be configured. SSID→Wifi Settings→802.11k will be enabled

RSSI Threshold (dBm)

This option is only available if Client Steering is enabled.

Specify the RSSI Threshold before clients get steered away to another AP.

Note: Must be an integer between -80 and -65.

Client Access Threshold

This option is only available if Client Steering is enabled.

Specify the Client Access Threshold before the AP won’t accept clients and they will be steer away to another AP with less connected clients.

Note: Must be an integer between 10 and 100.

Airtime Fairness

Allow faster clients to have more airtime than slower clients.

Beacon Interval

Configure the beacon period, which decides the frequency the 802.11 beacon management frames AP transmits. Please input integrates from 40 to 500.

  • When AP enables 0-2 SSIDs, the interval value will be effective are the values from 40 to 500.

  • When AP enables 3-8 SSIDs, the interval value will be effective are the values from 100 to 500.

  • When AP enables more than 8 SSIDs, the interval value will be effective are the values from 200 to 500.

Note: mesh feature will take up a share when it is enabled.

Enable Schedule

Configure a schedule for when the Wi-Fi will be ON or Off, by default is disable or the user can enable it and select a shedule form the drop-down list or use radio settings.

Fast SSID Build

When enabled and there are fewer than 8 SSIDs on the access point, creating or deleting SSIDs takes effect more quickly. This setting controls how fast the AP rebuilds SSIDs and can inherit the value from the radio settings.
Note: This feature is not supported on SSIDs using MLO or WPA2/WPA3 with PPSK without RADIUS. This option is only available on model GWN7674 under Wi-Fi → Radio.

Country/Region

Display the country/region of the AP.

Note: To configure the country/Region, Navigate to System → Settings page.


Scene

Configure whether to disable/enable 5.150–5.350GHz (channels 36-64) for outdoor usage.

Note: The “Scene” is only effective for the outdoor type of access points.

2.4G/5G/6G  (802.11b/g/n/ac/ax/be)

Channel Width

Choose the Channel Width, note that a wider channel will give better speed/throughput, and a narrow channel will have less interference. 20MHz is suggested in a very high-density environment.

40MHz Channel Location

Configure the 40MHz channel location when using 20MHz/40MHz in Channel Width, users can set it to be Secondary below Primary, Primary below Secondary or Auto.

Channel

Select the working channel for this radio. The available channels depend on the selected band (e.g., 2.4 GHz, 5 GHz, or 6 GHz, depending on the model) and the configured regulatory domain.

  • Auto: The access point evaluates the RF environment and selects an appropriate channel (from the allowed list) only once specifically when the radio starts or when the configuration is applied. The channel remains static during normal operation.

  • Dynamically Assigned by RRM: The access point uses Radio Resource Management (RRM) to continuously evaluate RF conditions. It adjusts the channel in real-time to reduce interference and minimize channel overlap without requiring a reboot.

Note: If the device is connected through a wireless Mesh, the channel may be determined by the mesh backhaul, and this setting might not take effect.

Default is Auto.

Channel Scan

Controls how the radio performs channel scanning for RRM when Channel is set to Dynamically Assigned by RRM.

  • Enable: Continuously scans the current working channel to collect RF information. This may cause brief interruptions and can disconnect connected clients.

  • Auto: Scans only when no clients are connected to the radio and stops scanning when a client is connected, reducing impact on active clients.

  • Schedule: Performs channel scanning only during the configured schedule period.

Note: This option is currently available only on model GWN7674.

Schedule

Select the time profile during which channel scanning is allowed when Channel Scan is set to Schedule. The radio will perform channel scanning only within the selected time period (for example, during off-peak or maintenance hours).

Note: This option is currently available only on model GWN7674 and is displayed only when Channel Scan is set to Schedule.

Custom Channel

Select the list of allowed channels for this radio. The available choices depend on the band (2.4 GHz, 5 GHz, or 6 GHz) and regulatory domain. When Channel is set to Auto or Dynamically Assigned by RRM, the access point will choose the working channel only from the channels selected here. Multiple selections are possible.

Radio Power

Set the Radio Power depending on the application, distance, and desired cell size. Options available typically include: “Low“, “Medium“, “High“, “Custom“, “Dynamically Assigned by RRM“, and “Auto“.

Auto: The access point calculates and applies the most suitable transmission power only once—upon device boot-up or when a configuration change is applied. The power level remains static thereafter.

Dynamically Assigned by RRM: The access point uses Radio Resource Management (RRM) to continuously monitor the RF environment. It actively adjusts the transmission power in real-time to optimize coverage and mitigate interference as environmental conditions change.

The default is “High

Enable Short Guard Interval

Check to activate this option to increase throughput.

Allow Legacy Devices(802.11b)

Check to support 802.11b devices to connect the AP in 802.11n/g mode. (2.4GHz setting).

Enable Minimum RSSI

Configure whether to enable/disable Minimum RSSI function. This option can be either Disabled or Enabled and set manually or set to Use Radio Settings.

Minimum Access Rate Limit

Specify whether to limit the minimum access rate for clients. This function may guarantee the connection quality between clients and AP. This option can be either Disabled or Enabled and set manually or set to Use Radio Settings.

Wi-Fi5 Compatible Mode

Some old devices are not fully compatible with Wi-Fi6 and may not be able to scan the signal or have poor connection. After turning on this feature, it will switch to Wi-Fi5 mode to solve the compatibility problem. and turn off Wi-Fi6 related functions..

Radio – Global configuration

SECURITY

Rogue AP

The GWN Access Points offer the ability to prevent malicious intrusion to the network and increase the wireless security access of clients when introducing Rogue AP detection. The detected APs will be listed with all the details under the detected section for further intervention.

Note:

Rogue AP feature is not supported on GWN7610.

The figure below is the configuration page in order to enable the Rogue AP detection and we can set the trusted APs on the network.

Rogue AP Configuration
FieldDescription
Enable Rogue AP DetectionSelect to either to enable or disable Rogue AP scan.
Detect rangeSpecify the rogue AP detect range.

Same channel: AP will execute simple detection on the APs around, this mode almost has no effects on the wireless network communication.

All channels: AP will execute a deep detection every 5 minutes. And the clients connecting to the AP will have few seconds of communication interrupt.

Default is Same Channel.
Countermeasure LevelCountermeasure level specifies the type of attacks which will be suspected by the AP. Select different levels:

High: Untrusted BSSID, Illegal access without authentication, Illegal access, Spoofing SSID.

Medium: Untrusted BSSID, Illegal access without authentication, Illegal access.
Low: Untrusted BSSID, Illegal access without authentication.

Default is Disabled.
Containment RangeSpecify the containment range:

Same channel: detect AP will countermeasure the APs in the same channel.

All channels: detect AP will countermeasure the APs in all channels at the cost of consuming of much AP performance.

Default is Same Channel.
Sub-string for Spoofing SSIDThe AP broadcasting SSID with the specified string will be classified as a Spoofing SSID.
Trusted APYou can specify MAC address of the trusted AP, which should be formatted as XX:XX:XX:XX:XX:XX. If an AP is defined as trusted AP, no countermeasures will be executed on it.
Untrusted APYou can specify MAC address of the untrusted AP, which should be formatted as XX:XX:XX:XX:XX:XX. If an AP is defined as untrusted AP, countermeasures will be executed on it when countermeasure is enabled.
Rogue AP

The figure below shows a list of all the detected rogue AP on the network scanned by the GWN access point.

Graphical user interface, application Description automatically generated
Rogue AP Detection

Firewall

This section allows users to control the outgoing and incoming traffic from clients by manually setting up policies to either deny or permit the traffic based on protocol type and by specifying SSIDs and destinations.

Graphical user interface, text, application Description automatically generated
Firewall Outbound
FieldDescription
Service ProtocolSelect type of traffic to be affected by the outbound rule like ICMP, HTTP, HTTPS… or you may add another type of traffic when selecting Custom. When set to Custom, user could enter the following:

Protocol: TCP or UDP

Port: define the port used by this protocol.
PolicyEither select to Permit or Deny Outbound traffic.
DestinationSelect either:

Particular Domain: enter FQDN of a destination or string: for instance, entering test will block service to any domain name containing string test.

Particular IP: IP address of destination.

Particular Network: Network IP address.

All: the rule will apply on all destinations.
SSIDSelect one or multiple SSIDs to apply the rule on.
Firewall- Outbound

User can define outbound and inbound rules on the traffic from the options in figure below:

Graphical user interface, text, application Description automatically generated
Firewall inbound
FieldDescription
Service ProtocolSelect type of traffic to be affected by the inbound rule like ICMP, HTTP, HTTPS… or you may add another type of traffic when selecting Custom. When set to Custom, user could enter the following:

Protocol: TCP or UDP

Port: define the port used by this protocol.
PolicyEither select to Permit or Deny inbound traffic.
SourceSelect either:

Particular IP: IP address of source.

Particular Network: Network IP address.

All: the rule will apply on all destinations.
DestinationConfigure the destination address.

All

Particular

IP Particular Domain

Particular Network
Firewall-Inbound

ARP Attack Defense

GWN Access points also support ARP Attack Defense security feature. This feature protects clients from spoofing MAC addresses by binding the MAC address to an IP address.

ARP List

Navigate to Web UI → Security → ARP Attack Defense, on the ARP list tab, the user can see the current ARP table (MAC address → IP address combination), Click on “Bind” icon to bind the MAC address to an IP address.

ARP Attack Defense ARP List

IP-MAC Binding

To make an IP-MAC address Binding manually, on the IP-MAC Binding tab, click on “Add” button and then enter the IP address and the MAC address then click save.

ARP Attack Defense IP MAC Binding

To unbind or edit, click on “Delete or Edit” icons under Actions. Please refer to figure below:

ARP Attack Defense

Strict ARP Learning option only learns ARP from the ARP Reply responding to the ARP Request sent by this device.

ARP Flood Attack Defense

Neighbor Discovery (ND) Attack Defense

ND Attack Defense is the equivalent of ARP Attack defense but using IPv6 addresses.

Navigate to Web UI → Security → ND Attack Defense page, then you can enable this security feature by clicking on “Source MAC Consistency Check for ND Messages“, now the device will check for Source MAC addresses to avoid any spoofing. There is also the option to log these events by checking “Log” option.

ND Attack Defense

SERVICE

Hotspot 2.0

This section lists the configuration page to Hotspot 2.0. This is a technology that allows mobile devices to automatically connect to available Passpoint-certified Wi-Fi hotspots. This gives the device liberty to hop from one hotspot on a network to another without the need to log in to each hotspot. This feature is currently on beta. 

To enable this feature, proceed from Access Point’s web page 🡪 Service 🡪 Hotspot 2.0:

Graphical user interface, application, email Description automatically generated
Hotspot 20
General Settings
NameSet name of the hotspot.
Domain IDSet the Domain ID.
HESSIDConfigure the Homogenous Extended Service Set Identifier information for Hotspot2.0. This value must be consistent with the BSSID of an AP to identify the AP set that provides the same network access service. The format is H:H:H:H:H:H, where H is a 2-digit hexadecimal number.
Network AccessEnable or disable internet access.
Network TypeSelect network type:
• Private network
• Private network with guest access
• Chargeable public network
• Free public network
• Personal device network
• Emergency services only network
• Test or experimental
• Wildcard
IPv4 TypeSelect IPv4 Type:
• Address type not available
• Public IPv4 address available
• Port-restricted IPv4 address available
• Single NATed private IPv4 address available
• Double NATed private IPv4 address available
• Port-restricted IPv4 address and single NATed IPv4 address available
• Port-restricted IPv4 address and double NATed IPv4 address available
• Availability of the address type not known
IPv6 TypeSelect IPv6 Type:
• Address type not available
• Address type available
• Availability of the address type not known
Network Auth TypeConfigure the Network authentication type to help users find and select the right network. Select either:
• Acceptance of terms and conditions
• On-line enrollment supported
• http/https redirection
• DNS redirection
• Not configured
OSU SSIDConfigure the Online Sign Up service’s SSID. You need to add a SSID with Security Mode is Open or OSEN or WPA2/OSEN.
Venue
Venue GroupSelect the Venue Group type:
• Unspecified
• Assembly
• Business
• Educational
• Factory
• Institutional
• Mercantile
• Storage
• Utility
• Vehicular
• Outdoor
Venue TypeSelect the Venue type, which will depend on the Venue Group.
Language CodeSelect the language.
Venue NameSet the Venue name.
Operator Name
Language CodeSelect the language.
Operator NameSet the Operator name.
Roaming Consortium
Roaming Consortium NameConfigure the Roaming Consortium Name to identify network operators. The format is H-H-H or H-H-H-H-H, where H is a 2-digit hexadecimal number.
Domain
DomainEnter the domain name.
Realm
RealmSelect the EAP Method: EAP-TLS, EAP-SIM, EAP-TTLS, EAP-AKA and EAP-AKA’.
Cellular Network Information
Cellular Network InformationEnter the Name, Country Code and Network Code.
Port Configuration
IP ProtocolConfigure the protocol type: ICMP, TCP, UDP or ESP.
Port NumberSet the protocol port.
Port StatusSet the port status to either: Open, Close or Unknown.
Terms and Condition
FilenameSpecify the filename.
TimestampSelect the timestamp
Advice of Charge
TypeSelect the type:
• Time-based
• Data-volume-based
• Time-and-data-volume-based
• Unlimited
RealmSelect the Realm.
Language CodeSelect the language code.
Currency CodeSelect the currency: XSU, BTN, INR, CNY, MOP, HKD, XAF.
XML ContentUpload XML file
Advanced
WAN Link StatusSet the WAN Link Status to either: Not configured, Link-up, Link-down or Link-test.
WAN Downlink SpeedSet Download speed.
WAN Uplink SpeedSet Upload speed.
GAS Fragmentation LimitSet GAS fragmentation limit. Default is 1400.
GAS Comeback DelaySet GAS comeback delay. Default is 0.
Disable Downstream Group-Addressed ForwardingWhen this option is disabled, it means the DGAF is enabled, the AP will forward all downlink broadcast ARP messages and wireless group broadcasts.

When this option is enabled, the DGAF function is disabled, the AP will discard all downlink broadcast ARP messages and wireless group broadcasts.

Disable DGAF function to prevent attackers from using the vulnerability of all clients in the same BSS using the same Group Temporal Key (GTK) to forge Group address frames and then attack the clients.
Hotspot 2.0

SNMP

This section lists the SNMP options available to integrate the GWN76xx with monitoring systems.

SNMP
FieldDescription
EnableEnable SNMPv1/SNMPv2c.
Community StringEnter the SNMP Community string.
EnableEnable SNMPv3.
UsernameEnter the SNMPv3 authentication username.
Authentication ModeSet the authentication mode to: either MD5 or SHA.
Authentication passwordEnter the SNMPv3 authentication password.
Privacy ModeSet the authentication mode to: either AES128 or DES.
Privacy passwordEnter the privacy password.
SNMP

DHCP Server

Users could create and manage multiple DHCP server pools which will be mapped to the SSID using VLAN tag, for example when creating a DHCP pool under “System Settings 🡪 DHCP Server” users need to set a VLAN ID and the same ID should be set under the SSID field to map the configured DHCP pool with the SSID. This way users could configure multiple SSIDs mapped to multiple VLANs on the network in which case they are isolated by layer 2 switching.

The table below summarizes the configuration parameters for DHCP server.

FieldDescription
NameSet the name of the DHCP Pool.
EnableEnable/Disable the DHCP pool.
VLAN IDSet a VLAN ID, same one should be set on SSID settings to map it with the DHCP pool.
DHCP Server Static AddressConfigure the static address of the DHCP server (through which GWN Master AP will be accessible).
DHCP Server Subnet MaskSet the subnet mask for the DHCP Pool.
DHCP Start AddressSet the start address for DHCP
DHCP End AddressSet the end address for DHCP
DHCP Lease TimeSet the DHCP lease time for the clients (default 12h).
DHCP OptionsAdd the Option items for DHCP, detailed option contents can be found via: https://wiki.openwrt.org/doc/howto/dhcp.dnsmasq
DHCP GatewaySet the gateway for DHCP, and it is better to set the gateway, should be different that the static IP of the access point and on the same subnet.
DHCP Preferred DNSSet the preferred DNS for DHCP
DHCP Alternated DNSSet the alternated DNS for DHCP
DHCP Server Parameters

NAT Pool

GWN76xx NAT feature defines an address pool from which the Wi-Fi clients will acquire their IP address so that the access point acts as a lightweight home router.

Notes:

1. This option cannot be enabled when Client IP Assignment is set to Bridge mode.

2. This option is not supported in GWN7610

FieldDescription
Default GatewaySet the gateway IP address. Note: The gateway address cannot be in the same network segment as the uplink network.
DHCP Server Subnet MaskSet the gateway mask.
DHCP Lease TimeSet the DHCP Lease time.
DHCP Preferred DNSSet the preferred DNS for DHCP
DHCP Alternate DNSSet the alternated DNS for DHCP
NAT Pool Parameters

Static DHCP

Users can use this feature in order to set static DHCP that binds to certain clients, to whom you do not want the IP address to change.

To configure Static DHCP, please follow below steps:

  1. Click button to create a new entry.
  2. Enter the name of the device, along with its MAC address and IP address
DHCP Binding
  • Press Save and Apply to submit the changes.

DHCP Relay

DHCP Relay is a network device that forwards IP addresses from the DHCP Server to clients devices, even if the DHCP server is on a different network (ex: VLAN). This way we can have a dedicated DHCP server on many networks. GWN access points can be configured as a DHCP relay agent. Please follow the steps below:

Prerequisite: before configuring DHCP Relay, first we have to assign a static IP address to both devices that will be acting as a DHCP Server and DHCP Relay in our case it’s two GWN76xx Access Points.

  1. The first step in our example is to make a GWN access point as a DHCP Server, please refer to DHCP Server configuration.
  2. Navigate to Web UI → Access Points → Configuration, click on the access point or click on the “Edit” icon, then the device configuration window will show up. Set a static IP for both access points (one acting as a DHCP Server and the other one as a DHCP Relay), please refer to the figure below.
Setting up a static IP

3. To configure DHCP Relay, please navigate to GWN access point Web UI → Service → DHCP Server → DHCP Relay tab, Then enable DHCP Relay and then enter the DHCP Server Address (ex: GWN access point).

DHCP Relay
Note:

a router side configuration could be required to setup VLANs for both access points to be able to communicate.

TR-069

Graphical user interface, text, application, email Description automatically generated
TR 069
FieldDescription
Enable TR-069Configure whether to enable TR-069. Note: Once enabled, this device cannot be managed by GDMS Networking anymore.
ACS URLURL for TR-069 Auto Configuration Server (ACS).
ACS UsernameWhen AP sends a connection request to ACS, the username that ACS authenticates TR-069 client, that is AP, must be consistent with the configuration on the ACS side.
ACS PasswordThe password of ACS for AP authentication must be consistent with the configuration of ACS side.
Enable Periodic InformIf enabled, AP will send connection inform packets to ACS regularly.
Periodic Inform Interval (s)Enter the time interval when AP sends connection Inform packets to ACS regularly
CPE Cert FileEnter the certificate that AP needs to use when connecting to ACS through SSL.
CPE Cert KeyEnter the certificate key that AP needs to use when connecting to ACS through SSL.
TR-069

Notes:

1. Restrictions:

Both Master and Slave (regardless of whether it has been taken over by GDMS Networking/Local Master) support TR-069 function, and you can go to their respective local web terminal to open TR-069 and make related configuration.

If the Slave under the GDMS Networking, it will be disconnected from the Cloud. The AP can still show on the Cloud, but it is not manageable (similar to the AP taken over by the Master can be added to the Cloud); if the Slave is under the Local Master, the connection with the Local Master will be disconnected, and the Master will no longer show this AP.

2. Failover does not support TR-069 function. When multiple slaves are managed under Local Master, set a slave to failover mode. When the Master fails, the slave acts as the Master to manage other slaves. At this time, if you want to migrate to the TR-069 platform, you can only configure TR-069 for each of the other Slaves through their own local web pages. So, they need to be migrated one by one, and APs in Failover mode cannot be migrated. (After failover master get transferred into official master, by admin to login and confirm, there will be no such restriction anymore)

3. Master supports the migration of the whole setup including its slaves to TR-069, and the behavior is irreversible. If the Master turns on TR-069, all online Slave APs it controls will be migrated to the TR-069 platform, and the Master’s identity will also be changed to Slave. In this process, you need to ensure the TR-069 configuration information, especially the ACS URL is configured correctly, otherwise the migration will fail, and all AP roles remain unchanged, and the function does not affect the use.

4. If a slave is offline, it will not be migrated to TR-069. After it goes online again, it will not be migrated to the TR-069 platform either. It is still in the state of being taken over by the original Master, but is no longer managed by the Master. It cannot be managed by Cloud, but can only be taken over by other Masters or factory reset.

5. APs managed by TR-069 can be “Take Over” by Local Master. After Taken Over, TR-069 shuts down by itself, and the Local Master issues the configuration to the AP to overwrite the original configuration from TR-069. This process will take a certain amount of time.

6. An AP under TR-069 will be disconnected from TR-069 by itself after the TR-069 function is turned off on the AP’s local web UI, but it will not affect its function use and can continue to be taken over by Master/GDMS Networking.

SYSTEM

Settings

Users can access Maintenance page from GWN76XX WebGUI🡪System 🡪 Settings.

LEDs

GWN76XX Access Points series also support the LED schedule feature. This feature is used to set the timing when the LEDs are ON and when they will go OFF at customer’s convenience.

This can be useful for example when the LEDs become disturbing during some periods of the day, this way with the LED scheduler, you can set the timing so that the LEDs are off at night after specific hours and maintain the Wi-Fi service for other clients without shutting down the AP.

Following options are available:

FieldDescription
LEDs Always OffConfigure whether to disable the AP LED dictator
LEDs Always OnConfigure whether to enable the AP LED dictator
SchedulePlease choose a schedule to assign to LEDs, users can configure schedules under the menu
LEDs

Following example on the next page sets the LEDs to be turned on from 8am till 8pm every day.

LED Scheduling Sample

Basic

Basic page allows Country and Time configuration.

FieldDescription
LED VLAN VLAN ID Allow DHCP Option 43 to Override Management VLANThis feature is an enhancement in regards to optimizing and reducing energy consumption of the AP. Users can select to either Always on / Always off or to Schedule the period where the LEDs can remain on. Management VLAN: This feature allows GWN AP to be discovered/managed on a VLAN network. If enabled, APs will get IP from this VLAN. Enter VLAN ID Configures AP to get provisioned for management VLAN from DHCP Option 43 in the local server automatically. The default management VLAN will be overridden by the provisioned settings. Note: Once enabled, users cannot manually change the management VLAN.
Rebind ProtectionAnti-domain name hijacking protection. If enabled, when the address returned by the superior DNS is a private LAN address, it will be regarded as a domain name hijacking, thus discarding the analytical result. If disabled, the analytical results will not be discarded.
Legacy TLS CompatibilityDue to the security enhancement, unless Legacy TLS Compatibility (only available on 1.0.15.4 or higher version) is enabled, master AP on 1.0.15.4 or higher firmware will not be compatible with slave AP on firmware lower than 1.0.15.4. Master AP on firmware lower than 1.0.15.4 will also not be compatible with slave AP on firmware 1.0.15.4 or higher. Cloud and GWN Manager will still support both firmware. Default is enabled.
Web HTTPS PortSpecifies HTTPS port. By default, is 443.
Country/RegionSelect the country from the drop-down list. This can affect the number of channels depending on the country standards.
SceneDepending on the deployment type (Indoor or Outdoor) the additional 5Ghz channels (DFS Channels) will be available to be used. Please refer to table DFS Channels supported by Model.
Note: This field appears for Country/Region supporting DFS.
Time ZoneConfigure time zone for the GWN76XX. Make sure to reboot the device to take effect.
NTP ServerConfigure the IP address or URL of the NTP server. The device will obtain the date and time from the configured server.
Date Display FormatChange the Date Display Format, three options are possible YYYY/MM/DD, MM/DD/YYYY and DD/MM/YYYY.
Reboot ScheduleSelect the time schedule when AP will be rebooted. Refer to [S] to define time.
Basic

Account

The Access Web page provide configuration for admin and user password.

FieldDescription
Current Administrator PasswordEnter the current administrator password.
New Administrator PasswordChange the current password. This field is case sensitive with a maximum length of 32 characters.
Confirm New Administrator PasswordEnter the new administrator password one more time to confirm.
New User PasswordConfigure the password for user-level Web GUI access. This field is case sensitive with a maximum length of 32 characters.
Confirm New User PasswordEnter the new User password again to confirm.
Account


Note: User passwords registered for authentication through the web portal are stored in an encrypted form.

Mesh

In Mesh Network, wireless connection is established between multiple APs, which is used to pass-through data traffic rather than client association. Each AP will evaluate the performance of wireless channel based on several factors and choose one or multiple appropriate APs to setup connection.

In a mesh network, access points are categorized to two types:

  • CAP (Central Access Point): this is an access point that has an uplink connection to the wired network.
  • RE (Range Extender): This is an access point that participate on the mesh network topology and has a wireless uplink connection to the central network.

In order to deploy mesh access points (RE), users/installers can follow below steps:

  1. Make sure to have the master and CAPs access points already deployed (sometimes the CAPs access points can be the master controller of the network).
  2. Next, we need to pair the REs access points to the master. This can be done in two ways:
  3. Connect all REs to the same wired LAN as the master then perform the normal process of discovery/pairing process, and after successfully pairing the APs they can be deployed on the field.
  4. REs can also be discovered wirelessly when powered via PSU or PoE Injector, and administrators can configure them after discovery. This requires that the REs must be within the range of the Master or CAP Slave’s signals coverage.

Note: If there are other GWN APs broadcasting in the same field with different subnet, RE may be wirelessly connected to those networks and cannot be discovered and paired by your Master. Therefore, it is recommended to use the first method of wired pairing and then deploy those REs.

  1. After that all slave access points have been deployed and paired to the master, you can directly manage them to operate the mesh network. Mesh service configuration is the same as transitional GWN WLAN.
  2. Log into the master page, and under Access Points page you can see the information, for example the AP in the “Online Wireless” state is the RE (Range Extender) with a wireless uplink to the CAP. The APs showing “Online” state are either a wired master or CAP.
Access Points Status

For Global mesh network settings, on GWN76XX, navigate to the menu “System🡪 Settings 🡪 Mesh”

for setting up the following parameters described below:

Mesh settings for GWN76XX

The following table down below describes the Mesh configuration settings for the GWN76XX:

FiledDescription
Enable MeshWhen checked the Mesh feature will be activated. Default is disabled.
Scan IntervalInterval in seconds to scan for available Mesh neighbors. Must be less than or equal to 300 seconds.
Interface5GHz band. Note: Mesh does not support 2.4GHz, due to the channel interference.
Wireless CascadesDefine how many AP can be cascaded wirelessly with the AP. The minimum value is 1 and maximum value is 3.
Mesh configuration on GWN76XX

For more detailed information about GWN Mesh network feature, you may refer to the following technical document: Mesh Network Guide.

Important notes:

1. The RE should be set with DHCP Mode for a Client device connected to NET PORT to acquire an IP Address.

2. If RE is set with static IP, then using a PoE injector is recommended as any Network activity detected by the AP will cause the Mesh to fail. Otherwise, user will only need to make sure that there is no DHCP Server in the network connected to the AP’s Ethernet port.

Schedule

Users can use the schedule configuration menu to set specific schedule for GWN features while giving the flexibility to specify the date and time to turn ON/OFF the selected feature.

The Schedule can be used for setting up specific time for Wi-Fi where the service will be active or for LED schedule or bandwidth rules …etc.

To configure a new schedule, follow below steps:

  1. Go under System 🡪 Schedule and click on Create New Schedule.
Create New Schedule
  1. Select the periods on each day that will be included on the schedule and enter a name for the schedule (ex: office hours).
  2. Users can choose to set weekly schedule or absolute schedule (for specific days for example), and if both weekly schedule and absolute schedules are configured on the same day then the absolute schedule will take effect and the weekly program will be cancelled for that specific date.
  3. Once the schedule periods are selected, click on Save to save the schedule.

The list of created schedules will be displayed as shown on the figure below. With the possibility to edit or delete each schedule:

Schedules List

Maintenance

Upgrade

The Upgrade Web page allows upgrade related configuration.

Upgrade

Syslog

On the GWN76XX, users could dump the syslog information to a remote server under Web GUISystemMaintenanceSyslog Tab. Enter the syslog server hostname or IP address and select the level for the syslog information. Eight levels of syslog are available: Emergency, Alert, Critical, Error, Warning, Notice, Information and Debug.

Note:

The device name is added to syslog messages. To configure the device name please navigate to Web UI → Access Points → Configuration select the device and click on “Configure” button.

Here is an example of the device name shown in Wireshark capture, please refer to the figure below:

Wireshark GWN76xx AP
Syslog

Field

Description

Syslog Server

Enter the IP address or URL of Syslog server.

Syslog Level

Select the level of Syslog, 8 levels are available:
Emergency, Alert, Critical, Error, Warning, Notice, Information and Debug.

Protocol

The protocol type sent to Syslog Server.

Log DNS Queries

Check to log DNS Queries.

Client MAC Address

Please configure the client MAC address for the log query.

Syslog Parameters

Alert

The Alert page allows the administrator to select a predefined set of system events and to send notifications upon the change of the set events via email.

Email

FieldDescription
Enable Email NotificationSet whether to enable Email notification.
Email configuration

Alert Configure

Alert Configure

The following table describes the notifications configuration settings:

FiledDescription
Memory UsageConfigure whether to send notification if memory usage is greater than the configured threshold.
AP ThroughputOnce enabled, master will generate an Alert when AP throughput reaches the configured threshold.
SSID ThroughputOnce enabled, master will generate an Alert when SSID throughput reaches the configured threshold.
Admin Password ChangeConfigure whether to send notification on admin password change.
Firmware upgradeConfigure whether to send notification on firmware upgrade.
Rogue APOnce enabled, system will generate an Alert when there is a Rogue AP detected.
AP OfflineConfigure whether to send notification when AP going offline.
Email Events

UPGRADING AND BACKUP/RESTORE

Upgrading Firmware

The GWN76XX can be upgraded to a new firmware version remotely or locally. This section describes how to upgrade your GWN76XX.

Upgrading via Web GUI

The GWN76XX can be upgraded via TFTP/HTTP/HTTPS by configuring the URL/IP Address for the TFTP/HTTP/HTTPS server and selecting a download method. Configure a valid URL for TFTP, HTTP or HTTPS; the server name can be FQDN or IP address.

Examples of valid URLs:

  • firmware.grandstream.com/BETA
  • 192.168.5.87

The upgrading configuration can be accessed via:

Web GUI🡪System Settings🡪Maintenance🡺Upgrade

Network Upgrade Configuration

Upgrading Slave Access Points

When the GWN76XX is being paired as slave using another GWN76XX Access Point acting as Controller, users can upgrade their paired access points from the GWN76XX Master Controller.

To upgrade a slave access point, log in to the GWN76XX acting as Master Controller and go to Access Points.

Access Points

Make sure that firmware server path is set correctly under Maintenance, check the desired APs to upgrade, and click on to upgrade the selected paired access points.

Sequential Upgrade

If you choose multiple slave devices to upgrade their firmware, two options are available: “All-at-Once” and “Sequential”. “All-at-Once” will use the default method, all checked slaves will upgrade their firmware at the same time, while using the “Sequential” upgrade method, the slaves will upgrade their firmware one by one to:

  • Avoid entire Wi-Fi service interruption by full system firmware upgrade.
  • Reduce network bandwidth consumption caused by firmware downloading.
Choosing multiple devices
https://lh3.googleusercontent.com/-L4VWApfoM8c/WnMok0J60LI/AAAAAAAADt0/65j3UrFyswkHv-cTYRH--io63AgF4VBQACL0BGAYYCw/h381/2018-02-01.png
All at Once and Sequential Upgrade

Once you choose sequential upgrade, the following icon will update you about the number of upgraded slaves out of the selected slaves.

Configuration Backup and Restore

The GWN76XX configuration can be backed up locally. The backup file will be used to restore the configuration on GWN76XX when necessary.

Download Configuration

Users can download the GWN76XX configuration for restore purposes under Web GUI🡪System Settings🡪Maintenance🡪Upgrade.

Click on to download the configuration file locally.

Upload Configuration

Users can upload configuration file to the GWN76XX under Web GUI 🡪 System Settings 🡪 Maintenance 🡪 Upgrade.

Click on to browse for the configuration to upload.

Note:

Please note that the GWN76XX will reboot after the configuration file is restored successfully.

Reset and reboot

  • Users can reboot the device under Web GUI 🡪 System Settings 🡪 Maintenance 🡪 Upgrade by clicking on button.
  • The button will restore all the GWN76XX options to factory settings.

EXPERIENCING THE GWN76xx Wi-Fi ACCESS POINTS

Please visit our website: https://www.grandstream.com to receive the most up-to-date updates on firmware releases, additional features, FAQs, documentation, and news on new products.

We encourage you to browse our product-related documentation, FAQs, and User and Developer Forum for answers to your general questions.  If you have purchased our products through a Grandstream Certified Partner or Reseller, please contact them directly for immediate support.

Our technical support staff is trained and ready to answer all your questions. Contact a technical support member or submit a trouble ticket online to receive in-depth support. Thank you again for purchasing the Grandstream GWN76XX Wi-Fi Access Point, it will be sure to bring convenience and color to both your business and personal life

Thank you again for purchasing the Grandstream GWN76XX Wi-Fi Access Point, it will be sure to bring convenience and color to both your business and personal life

CHANGE LOG

This section documents significant changes from previous versions of the GWN76xx user manuals. Only major new features or major document updates are listed here. Minor updates for corrections or editing are not documented here.

Firmware Version 1.0.25.33

Product Name: GWN7600 / GWN7600LR / GWN7610

  • Added new LED Pattern for uplink down/no network [LED Patterns]
  • Added WP series device fast configuration support [WP device fast configuration]
  • Added support for multi-VLAN Wi-Fi roaming [SSID]
  • Added support for MAC-based RADIUS authentication [SSID]
  • Added support of OS filtering [SSID]
  • Increased the number of MAC addresses which can be added in the Client isolation [SSID]
  • Increased Whitelist/Blacklist limit to 1024. [Access List]
  • Added LLDP protocol support.

Firmware Version 1.0.25.19

Product Name: GWN7600 / GWN7600LR / GWN7610

  • No major changes

Firmware Version 1.0.25.10

Product Name: GWN7600 / GWN7600LR / GWN7610

Firmware Version 1.0.25.7

Product Name: GWN7610 / GWN7600 / GWN7600LR

  • Increased PPSK accounts. [PPSK]
  • Increased the client expiration time to 30 days. [Captive Portal]
  • Added device name in Syslog messages. [Syslog]
  • Added support for custom Channel on 2.4G band. [Radio]

Firmware Version 1.0.25.3

Product Name: GWN7610 / GWN7600 / GWN7600LR

  • No major changes

Firmware Version 1.0.25.1

Product Name: GWN7610 / GWN7600 / GWN7600LR

  • Added support of ARP defense [ARP Attack Defense]
  • Added support of IPv6 ND defense [ND Attack Defense]
  • Added support for disabling Ethernet port [configure access points]
  • Added support of DHCP relay and option82 [DHCP Relay]
  • Added support of trunk/access mode for NET/PoE port [configure access points]
  • Added support of External syslog protocol selection [Syslog]
  • Added support for collecting logs by MAC [Syslog]
  • Added support of Captive Portal – Active Directory Auth (LDAP) [Captive Portal]
  • Added support of Captive Portal – kick out timeout unauthenticated clients [Captive Portal]
  • Added support of Captive Portal – Daily access limit by auth method [Internal Splash page]
  • Added support for switching RF timer [Radio]

Firmware Version 1.0.23.24

Product Name: GWN7610 / GWN7600 / GWN7600LR

  • No major changes

Firmware Version 1.0.23.22

Product Name: GWN7610 / GWN7600 / GWN7600LR

  • Added support for GWN Cloud v1.1.23.27 and GWN Manager v1.1.23.27

Firmware Version 1.0.23.6

Product Name: GWN7600 / GWN7600LR / GWN7610

  • No major changes

Firmware Version 1.0.23.3

Product Name: GWN7600 / GWN7600LR / GWN7610

  • No major changes

Firmware Version 1.0.21.7

Product Name: GWN7600 / GWN7600LR / GWN7610

  • No major changes

Firmware Version 1.0.19.32

Product Name: GWN7600 / GWN7600LR / GWN7610

  • No major changes.

Firmware Version 1.0.19.25

Product Name: GWN7600 / GWN7600LR / GWN7610

  • No major changes

Firmware Version 1.0.19.23

Product Name: GWN7610 / GWN7600 / GWN7600LR

  • Added support for Secondary RADIUS Server. [Secondary RADIUS Server]
  • Added support for Rogue AP Alert. [Alert Configure]

Firmware Version 1.0.19.15

  • No major changes

Firmware Version 1.0.19.9

  • Added support of Rogue AP Detection. [Rogue AP]
  • Added support of 802.11w. [802.11w]
  • Added support of AutoTX Power. [RADIO]
  • Added Captive Portal Enhancement. [CAPTIVE PORTAL]
  • Added support of SNMP. [SNMP]
  • Added support of more DFS Channels. [Scene]
  • Added support of NAT. [NAT]
  • Added support of Firewall. [Firewall]
  • Added support of Hotspot 2.0 Beta. [Hotspot 2.0]
  • Added support of Multicast/Broadcast Suppression. [Multicast/Broadcast Suppression]
  • Extended support of RRM to GWN Cloud and remaining AP models. [Transmit Power Control][Coverage Hole Detection][Dynamic Channel Assignment]
  • Added support of Active IGMP for the feature Convert IP multicast to unicast enhancement. [Convert IP multicast to unicast]
  • Allow DHCP Option43 to override GWN Manager Address. [Allow DHCP Option 43 to override GWN Manager Address]

Firmware Version 1.0.15.20

Product Name: GWN7610 / GWN7600 / GWN7600LR

  • Added support for more DFS channels [Scene]

Firmware Version 1.0.15.4

Product Name: GWN7610 / GWN7600 / GWN7600LR

  • Added support of GWM Manager. [GWN Manager]
  • Added LED pattern of yellow to indicate Mesh disconnection. [LED Patterns]
  • Upgraded TLS to version 1.2

Firmware Version 1.0.11.8

Product Name: GWN7610 / GWN7600 / GWN7600LR

  • Added support for Client Steering. [Client Steering]
  • Added support for Minimum Rate Control. [RADIO]
  • Added support for batch operations for Takeover. [Takeover Feature]
  • Added support for Client inactivity timeout. [SSID]
  • Enhanced Voucher feature by displaying remaining bytes. [Vouchers]
  • Changed LED Pattern. [LED Patterns]
  • Changed Local Master External Portal Configuration. [External Splash Page]
  • Changed the default setting of Mesh to OFF. [Mesh]

Firmware Version 1.0.8.18

Product Name: GWN7610 / GWN7600 / GWN7600LR

  • Added support of ARP Proxy. [ARP Proxy]
  • Enhanced Bandwidth Rules by adding an option to limit bandwidth per user. [Range Constraint]

Firmware Version 1.0.8.9

Product Name: GWN7610 / GWN7600 / GWN7600LR

  • No major changes

Firmware Version 1.0.7.13

Product Name: GWN7610 / GWN7600 / GWN7600LR

  • Added support of Radio Resource Management (RRM). [Dynamic Channel Assignment] [Transmit Power Control] [Coverage Hole Detection]

Firmware Version 1.0.4.22

Product Name: GWN7610

  • Included patch for WPA2 4-way handshake vulnerability [VU#228519]

Firmware Version 1.0.4.20

Product Name: GWN7610

  • Added support for Timed Client Disconnect and Enhanced Client Blocking [CLIENTS]
  • Added support for Client Bridge [Client Bridge]
  • Added support for Syslog server [Syslog]
  • Added support for Configurable Web UI access port. [Web HTTPS Port]
  • Added support for E-mail notifications [Email]

Firmware Version 1.0.4.12

Product Name: GWN7600 / GWN7600LR

  • Added support for Timed Client Disconnect and Enhanced Client Blocking [CLIENTS]
  • Added support for Client Bridge [Client Bridge]
  • Added support for Syslog server [Syslog]
  • Added support for Configurable Web UI access port. [Web HTTPS Port]
  • Included patch for WPA2 4-way handshake vulnerability [VU#228519]

Firmware Version 1.0.3.25

Product Name: GWN7600 / GWN7600LR

  • No major changes.

Firmware Version 1.0.3.21

Product Name: GWN7610

  • No major changes.

Firmware Version 1.0.3.19

Product Name: GWN7610 / GWN7600 / GWN7600LR

  • Added support for captive portal [CAPTIVE PORTAL]
  • Added support for 802.11k/r/v [Enable Voice Enterprise]
  • Added support for failover master [Failover Master]
  • Added support for VLAN assignment via RADIUS [SSID][Enable Dynamic VLAN (beta)]
  • Added support for Select SSID Band [SSID Band]
  • Added support for Exact Radio Power Configuration in dBm [Custom Wireless Power]
  • Added support for AP Location [AP Location]
  • Added support for Per-Client/Per-SSID bandwidth rules [Bandwidth R]
  • Added support for Wi-Fi Schedule [S]
  • Added support for LED control [L]
  • Added option to enable/disable DHCP option 66 & 43 override [Allow DHCP options 66 and 43 override]

Firmware Version 1.0.2.108

Product Name: GWN7610

  • Added Controller protocol security enhancement. [Controller Protocol Security Enhancement]
  • Added support for LED control. [LED control]
  • Added support for Captive Portal. [CAPTIVE PORTAL]
  • Added support for Wi-Fi schedule. [Wi-Fi Schedule]
  • Added Client Isolation enhancement. [SSID]
  • Added support to store Syslog locally on the unit and display it on Web GUI. [Syslog]

Firmware Version 1.0.2.15

Product Name: GWN7610

  • Added New Overview Page.
  • Added Web UI enhancement.
  • Added support for Password change on first boot.
  • Added Country code selection into the setup wizard.

Firmware Version 1.0.1.31

Product Name: GWN7600 / GWN7600LR

  • This is the initial version.

Firmware Version 1.0.1.27

Product Name: GWN7610

  • This is the initial version.

Certificates

COPYRIGHT

©2024 Grandstream Networks, Inc. https://www.grandstream.com
All rights reserved. Information in this document is subject to change without notice. Reproduction or
transmittal of the entire or any part, in any form or by any means, electronic or print, for any purpose
without the express written permission of Grandstream Networks, Inc. is not permitted.
The latest electronic version of this guide is available for download here:
https://www.grandstream.com/support
Grandstream is a registered trademark and the Grandstream logo is a trademark of Grandstream Networks, Inc. in the United States, Europe, and other countries

CAUTION

Changes or modifications to this product not expressly approved by Grandstream, or the operation of this
product in any way other than as detailed by this guide, could void your manufacturer warranty.

WARNING

Please do not use a different power adapter with devices as it may cause damage to the products and
void the manufacturer’s warranty.

FCC Caution

Any changes or modifications to this unit not expressly approved by the party responsible for compliance could void the user’s authority to operate the equipment.

This device complies with 15 of the FCC Rules. Operation is subject to the following two conditions: (1) This device may not cause harmful interference, and (2) this device must accept any interference
received, including interference that may cause undesired operation.

Note:

This equipment has been tested and found to comply with the limits for a Class B digital device, pursuant to Part 15 of the FCC Rules. This equipment generates, uses, and can radiate radio frequency energy and, if not installed and used in accordance with the instructions, may cause harmful interference to radio communications. However, there is no guarantee that interference will not occur in a particular installation. If this equipment does cause harmful interference to radio or television reception, which can be determined by turning the equipment off and on, the user is encouraged to try to correct the interference by one or more of the following measures:

  • Reorient or relocate the receiving antenna.
  • Increase the separation between the equipment and receiver.
  • Connect the equipment into an outlet on a circuit different from that to which the receiver is connected.
  • Consult the dealer or an experienced radio/TV technician for help.

This equipment complies with FCC radiation exposure limits set forth for an uncontrolled environment.
This equipment should be installed and operated with minimum distance 20cm between the radiator&
your body.
This transmitter must not be co-located or operating in conjunction with any other antenna transmitter.

ISEDC Warning

This device complies with Innovation, Science, and Economic Development Canada licence-exempt RSS standard(s). Operation is subject to the following two conditions: 1) this device may not cause interference, and (2) this device must accept any interference, including interference that may cause undesired operation of the device.

Le présent appareil est conforme aux CNR d’Innovation, Sciences et Développement économique Canada applicables aux appareils radio exempts de licence. L’exploitation est autorisée aux deux conditions suivantes: (1) l’appareil ne doit pas produire de brouillage, et (2) l’utilisateur de l’appareil doit accepter tout brouillage radio électrique subi, même si le brouillage est susceptible d’en compromettre le fonctionnement.

ISEDC Warning

This equipment complies with ISEDC radiation exposure limits set forth for an uncontrolled environment. This equipment should be installed and operated with minimum distance 20cm between the radiator & your body.
This transmitter must not be co-located or operating in conjunction with any other antenna or transmitter. Cet équipement est conforme aux ISEDC RF limites d’exposition aux radiations dans un environnement non contrôlé. Cet émetteur ne doit pas être situé ou opérant en conjonction avec une autre antenne ou émetteur.

CE Authentication

EU Regulatory Information

GWN7610

GWN7600

TX/RX Frequency

TX/RX Frequency

2.4G Wi-Fi: 2412-2472MHz;

2.4G Wi-Fi: 2412-2472MHz

5G Wi-Fi: 5150-5250MHz

5G Wi-Fi:  5150-5250MHz

Output power

Output power

WLAN 2.4G < 20dBm;

WLAN 2.4G < 20dBm

WLAN 5150-5250MHz< 23dBm

WLAN 5150-5250MHz< 23dBm

Modulation

Modulation

DSSS, OFDM

DSSS, OFDM

The simplified EU declaration of conformity referred to in Article 10(9) shall be provided as follows:
Hereby, [Grandstream Networks, Inc.] declares that the radio equipment type [GWN7610/GWN7600/GWN7600LR] are in compliance with Directive 2014/53/EU.

The full text of the EU declaration of conformity is available at the following internet address:
https://www.grandstream.com

GNU GPL INFORMATION

GWN76xx firmware contains third-party software licensed under the GNU General Public License (GPL).
Grandstream uses software under the specific terms of the GPL. Please see the GNU General Public
License (GPL) for the exact terms and conditions of the license.
Grandstream GNU GPL related source code can be downloaded from Grandstream web site:
https://www.grandstream.com/support/faq/gnu-general-public-license

Was this article helpful?

Need Support?
Can’t find the answer you’re looking for? Don’t worry we’re here to help!
Contact Support