Calix 844G UserGuide
Calix 844G UserGuide
Calix 844G UserGuide
User's Guide
August, 2015
#220-00771, Rev 11
Contents
Related Documentation............................................................................................. 6
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
4
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
5
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
6
Note: This guide is intended to educate users in setup and configuration of the 800G
GigaCenter gateway for use in the home network. This guide does not address the
provisioning of network access services on the GigaCenters themselves. For information on
services provisioning, refer to the appropriate platform documentation.
Intended Audience
This guide is intended for use by consumers. Cursory knowledge of Internet Protocol (IP)
and GPON based systems as well as a general understanding of IP addressing, routing
principles, and internet security are also highly desired. This document assumes that the
subscriber's laptop or PC is equipped with a supported web browser (Internet Explorer or
Firefox) and that the user is familiar with its use. Familiarity with datacom, telecom, and
standards-based Ethernet technologies and conventions is also recommended.
Note: For the purposes of this guide, it is assumed your service provider has already
activated your GigaCenter on the GPON network and is being managed remotely.
Related Documentation
You can access all Calix product documentation from the Calix Resource Center online at
support.calix.com.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
7
Site Conventions
The following elements and controls are used consistently throughout the 800G GigaCenter
EWI:
System Defaults
Fields that carry a pre-defined default values are marked with an "‡" symbol in the last
column of each table.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
8
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Chapter 1
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
10
Supports the latest 802.11ac standard for the 5GHz radio. Some basic 802.11ac
enhancements include:
Dynamic beamforming for high performance and longer reaches.
80Mhz channels for greater speeds,
QoS support allowing prioritization of Video SSID over lower priority best effort
HSI data SSIDs.
Dual band concurrent radios allows the use of legacy 2.4 GHz clients while accessing
seven times the spectrum of 2.4 GHz using the 5 GHz band.
GigaCenters support the E7-2 and E7-20 Ethernet Service Access Platforms (ESAP)
GPON. The 844G and 854G are GPON only devices.
In conjunction with the Calix Compass software, a rich set of tools is supported for
provisioning, maintaining, and troubleshooting the Wi-Fi home network. Compass’s
ability to store vast amounts of performance management data allows service providers
the ability to troubleshoot issues that are time of day based along with the ability to
generate trend analysis to predict congestion issues
GigaCenters are designed to help service providers generate new revenue streams such as
smart home applications through the continued release of software features. To support
these features GigaCenters supports a high performance CPU and larger memory than
other products on the market
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
11
Wireless Functionality
2.4GHz and 5GHz, simultaneous dual-band
5GHz 802.11ac certified, 802.11a/g/n compatible
2.4GHz 802.11n certified, 802.11b/g compatible
WPA/WPA2
WPS push-button
WEP 64/128 bit encryption
Airtime Fairness on 2.4 GHz and 5 GHz radios
Eight SSID per band with factory default SSIDs
Two SSID assigned to Primary/Guest and six operator defined SSIDs
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
12
5 GHz radio support of 64 clients (assigned to Primary/Guest with maximum 102 clients
per radio
64 Clients supported per band with 38 reserved for operator defined SSIDs
MAC filtering
USB port
USB 2.0 - Type A configured as a host controller device
System Features
Supports multiple data service profiles
Traffic management and Quality of Service (QoS):
802.1Q VLANs
802.1p service prioritization
Q-in-Q tagging
Multiple VLANs
Rate limiting
DiffServ
Pre-defined QoS on service type
IPTV, IGMPv2, IGMPv3
IGMP Snooping and Proxy
IGMP Fast Leaves
OAM&P support via Calix Management System (CMS)
Gateway Management:
TR-069
TR-98
TR-104
Local Home Gateway GUI, access provisionable
Remote WAN side GUI access
Default username/password
Set-up persistence, factory reboot option
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
13
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
14
IPv4 addresses are 32 bits, written in dot-decimal notation. IPv6 addresses are 128 bits long,
written in colons-hexadecimal notation with eight groups of four digits. Direct connectivity
of IPv6 negates the need for Network Address Translation (NAT) with each device having a
unique IP address, and includes special addressing features and a significantly larger subnet
space.
To help in the transition and implementation of IPv6 from IPv4 there are a number of
different strategies to help operators depending on the network infrastructure and
environment:
Single or Dual-stack IPv4/IPv6
DS-Lite
6rd
All GigaCenters supporting Home Gateway Layer 3 services support Single or Dual-stack
IPv4/IPv6. GigaCenters also support DS-Lite for IPv6 carriage (tunneling of IPv4) or 6rd
for IPv4 carriage (tunneling of IPv6).
The Home Gateway support of IPv6 only supports IPv6 for High Speed Internet (HSI) data
services. The release does not support IPv6 for IPTV multicast video, voice services and TR-
069 management.
Note: Only one variant of IPv6 support can be applied to a gateway, and only one service
WAN interface can support the IPv6 variant which will be constrained to HSI only.
Note: The IPv6 interface can support IPoE Dynamicv6, IPoE Staticv6 and PPPoEv6.
Note: Support and provisioning of IPv6 is not supported using Native mode.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
15
Dual stack IPv4/IPv6 is the most desirable variant of IPv6 support since it facilitates direct
connections of both IPv4 and IPv6 devices and avoids complexities of tunneling, security,
and timing delays that are introduced when translating between protocols required when
using Carrier Grade NAT.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
16
When supporting IPv6, the Home Gateway EWI has separate display of IPv6 statistics and
packet performance. It does include support of firewall for IPv6 in same way it supports
firewall for IPv4 with a general option of off/low/medium/high and ability to change traffic
in/traffic out settings for protocols and ports. The firewall settings for IPv6 are managed
separately from IPv4.
For additional information on configuring IPv6 services, refer to IPv6 Parameters and Options
later on in this guide.
DS-Lite
With the depletion of IPv4 public addresses some operators have had to discontinue support
of IPv4 in their networks and solely deploy IPv6 network infrastructure. Because not all
subscriber devices support IPv6 it requires tunneling and translation of IPv4 addresses to the
gateway.
The GigaCenter supporting Home Gateway continues to distribute private IPv4 addresses on
the LAN and wireless interfaces. DS-Lite encapsulates IPv4 packet inside a IPv6 packet with
network termination to an Address Family Translation Router (AFTR) supporting Carrier
Grade NAT with global IPv6 connection. At the AFTR the IPv6 packet is decapsulated,
restored to IPv4, and routed to the public IPv4 Internet.
The DS-Lite implementation is shown in the below figure:
To facilitate the tunneling of IPv4 packets the AFTR uniquely marks each traffic flow using
the Gateway IPv6 address, the private IPv4 address and port number. The gateway obtains
the URL of the AFTR via DHCPv6 (RFC 6334) or it can be provisioned manually with the
AFTR URL via EWI, TR-069 or RG configuration file.
On its WAN side, Network Area and Port Translation (NAPT) is disabled and the IPv4
tunnel becomes the default IPv4 route. Via DHCPv4, the gateway can either advertise itself
as the DNSv4 server or advertise DNSv4 servers provisioned via EWI or TR-069 or RG
configuration file. In the former case the gateway proxies "A" record queries from IPv4 to a
WAN-side DHCPv6 server.
The GigaCenter supporting Home Gateway only supports a single instance of DS-Lite on a
routed WAN interface. The WAN interface is assumed to be supporting HSI services.
Support of DS-Lite for HSI is independent of IPTV services and is not supported for TR-
069 management.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
17
6rd
For service providers with networks that do not have IPv6 infrastructure the GigaCenter
supporting Home Gateway will support dual stack 6rd. The variant of 6rd allows IPv6
service to be deployed over a pure IPv4 access network. The core network is not aware of
IPv6, it does not require IPv6 infrastructure such as core routers, DHCP or DNS servers
The 6rd mechanism encapsulates IPv6 inside IPv4 between the Border Router (BR) and
Customer Edge (CE). It follows all of the same IPv4 routing functions. On the GigaCenter
supporting Home Gateway the LAN interfaces appear as Dual-Stack IPv4/IPv6 to the LAN
interfaces and subscriber.
At the subscriber location the gateway operates in a ‘hub-and-spoke’ mode with IPv6
tunneled traffic flows between the BR and gateway. The gateway can be provisioned to
support 6rd by obtaining network data via DHCPv4 Option 212 or via EWI, TR69 or RG
configuration file. The specific 6rd provisioning data consists of:
IPv4 Mask Length
6rd Prefix
6rd Prefix Length
BR IPv4 address
Provisioning of 6rd includes configuring the necessary parameters via EWI, TR-069 and
DHCPv4, creation of the prefix, using the created prefix as a "delegated prefix" for purpose
of including one of its /64s in RA messages, and modifying the IP header for traffic that
goes between the WAN and LAN devices. Once configured for dual stack 6rd, the gateway
advertises DNSv6 servers provisioned via EWI, TR-069 or RG configuration file.
As noted previously, the GigaCenter and supporting Home Gateway only support a single
instance of 6rd on a routed WAN interface. The WAN interface is assumed to be supporting
HSI services. Dual stack 6rd is not supported for IPTV multicast over routed interface and
TR-069.
For additional information on configuring 6rd services, refer to 6rd Parameters and Options later
on in this guide.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
18
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Chapter 2
Wireless Networking
The operative data rate for Wireless LANs is based on the IEEE 802.11 standards.
Proponents of the 5 GHz spectrum claim data rates up to 1733 Mbps when associated with
an 802.11ac access point using 80 MHz channels and 4x4 MIMO (supported by
GigaCenters). These reflect the standard physical layer rate (PHY rate) of a link. Proponents
of the 2.4 GHz spectrum using 2x2 MIMO claim rates up to 300Mbps using 40 MHz
channels. These claims do not reflect the actual data throughput expected when
communicating over a wireless interface. Some of the main differences between PHY rate
and actual payload data throughput are:
1. Higher overhead and packet headers required for wireless connections
2. Data re-transmission necessary because of temporary changes in a wireless links
3. Varying number of clients being supported over a common radio channel
Whereas overhead and re-transmission are inherent features that reduce the data throughput
of all wireless networks, there are wireless propagation factors that significantly affect Wi-Fi
coverage and throughput. These range from the design and placement of the Access Point
(AP) and its antennas, orientation of the antennas, and constant changes in the level of radio
signal interference. Variables that affect wireless network performance generally fall into the
following categories:
Design and performance characteristics of the wireless Access Point
Operating mode of 802.11 design standard: a/b/g/n/ac
Support of spatial multiplexing
Single Input, Single Output (SISO) vs Multiple Input, Multiple Output (MIMO)
2.4 GHz vs. 5 GHz frequency band selection
20 MHz, 40 MHz and 80 MHz bandwidth selection
Transmit power
Receive sensitivity
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
21
The standard transmission rates vary for each of the Wi-Fi protocols. Within each protocol
there are a number of "standard" transmission rates beginning with a rate that is
approximately 1/10th of the maximum link bit rate per stream. The support of MIMO
technology represents Multiple Input, Multiple Output. The column titled "Allowable MIMO
Streams" indicates if multiple data streams can be used to provide MIMO spatial
multiplexing. With 2x2 MIMO on a 5 GHz 802.11n system that would equate to a speed of
300MHz (2*150).
As noted there are a number of factors that influence the expected GigaCenter coverage and
throughput data rate as wireless signals propagate over an open air interface. Moving a
connected Wi-Fi client away from the AP causes a progressive degradation of the data stream
until it can no longer receive or transfer data due to low or poor signal quality.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
22
With ONT Release 11.1, the concept of Air-Time Fairness was introduced for both the 2.4
GHz and 5 GHz radios. With this technology, devices capable of transmitting at peak
wireless modes or data rates are never limited by other older wireless devices connected to
the same radio. In other words, air-time is allocated evenly to all clients on the network,
regardless of the wireless technology being used.
Note: Support for the new Wave 2 802.11ac standard is not supported in this release. Calix
plans to support this standard in a future release and will allow the GigaCenter to send
separate and simultaneous streams to multiple mobile clients at a time.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
23
The 2.4 GHz spectrum supports 11 overlapping 20 MHz channels with center frequencies
separated by 5 MHz. In reality, this creates only 3 non-overlapping 20 MHz channels.
Conversely, the 5 GHz spectrum supports 23 non-overlapping 20 MHz channels that, when
combined, support (11) 40 MHz and (5) 80 MHz non overlapping channels. One of the
main benefits of 802.11ac (which only supports the 5 GHz spectrum) is to get subscribers off
the slower and crowded 2.4 GHz spectrum and onto the quicker, less utilized 5 GHz
spectrum.
In addition, some of the 5 GHz radio channels have special requirements placed on their
usage. These channels can be used by radar systems and there are FCC standards for the Wi-
Fi equipment to sense if radar is present and if so, to hop to a different channel. This ability
to sense radar and jump to a different channel is called Dynamic Frequency Selection (DFS)
and requires equipment vendors to certify their equipment as being DFS compliant. Some
vendors have chosen to not support DFS which reduces the amount of capacity in 5 GHz
systems.
The DFS channels comprise 60% of the 5 GHz channels. These may be considered the
"beach front property" for in home Wi-Fi networks. Many commercial routers sold by
retailers are not certified so this frequency band is mostly empty. If there is no radar in the
vicinity of the home, the DFS channels will generally have minimal traffic. This allows
operators who deploy GigaCenter products to leverage DFS channels to ensure high
performance Wi-Fi for their end users and/or for the delivery of IPTV Video to their Wi-Fi
capable set top boxes.
Not all current generations of Video Access Point (VAP) or Wi-Fi enabled Set top boxes
support DFS. Also, not all data clients support DFS and therefore they cannot take
advantage of the GigaCenters DFS capabilities. To support the needs of the service provider,
GigaCenters allows the service provider to enable or disable the usage of the DFS specific
channels. Below is a picture of how the 2.4 GHz and 5 GHz radio spectrum is broken down.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
24
Operational Notes
To increase data throughput, the 802.11n standard allows for bonding wireless channels to
increase usable spectrum. With the 2.4 GHz model, band bonding channels to 40 MHz
bandwidths is not practical because of channel overlap and interference. The 5 GHz band
allows you to configure 20 MHz or 40 MHz of channel bandwidth enabling support of
greater throughput by utilizing a larger portion of spectrum.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
25
Note: Air Time Fairness is enabled on both the 2.4 GHz and the 5 GHz radio by default.
GigaCenters are designed to support both IPTV and HSI applications over 802.11ac at 5
GHz, as well as HSI over 2.4 GHz with the pre-ac standards. GigaCenter supports QoS
prioritization by SSID provisioning. The initial release dedicates an SSID in the 5 GHz band
specific for video IPTV applications with higher quality of service. This ensures that the
service providers IPTV content will always be prioritized higher than the consumers HSI
Data or the Guest SSID.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
26
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Chapter 3
Turning up a GigaCenter
Note: It is assumed your service provider has already activated your GigaCenter on the
GPON network and is able to manage all functions of the device remotely.
GIGACENTER TOOLS
Subscriber EWI
Local Access
Manage Home Gateway Web Browser via IP 192.168.0.2 Subscriber
Administrator
account
For most GigaCenter deployments that involve data-only use cases, or access modes that
require a single VLAN service, the default RG profile that is created when the GigaCenter
becomes operational is adequate.
For more advanced access models that require multiple VLANs associated with the routed
WAN interface, set-up of PPPoE or Static IPoE connections, or enabling IPTV and other
services on separate VLANs, an RG configuration must be applied to set up the gateway
partition. In these use cases, RG configuration may include setting up multiple routed WAN
interfaces, static routes and other network defined attributes.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
28
1. Attach an Ethernet cable to any of the Ethernet ports on the back of the GigaCenter to
an Ethernet port on your PC.
2. From your browser, enter the IP address 192.168.1.1.
3. At the login prompt, enter the credentials found on the adhesive back label shipped
inside the carton of the GigaCenter. credentials as follows:
a. Login: admin
b. password: Enter character string on label
4. You now have access to Internet and Wi-Fi services on your GigaCenter.
GigaCenter Inventory
Inserted inside the shipping carton of each GigaCenter, the inventory label provides
necessary product information for use in your inventory management system:
Serial Number of the GigaCenter
FSAN/SSID used for identifying the RSG on the Wi-Fi network.
MAC Address of the unit needed by the Management VLAN.
Default Wi-Fi security type and encryption scheme used by the Home Gateway
A Default Wi-Fi WPA key such that other devices can "associate" with the Wi-Fi circuit
on the GigaCenter.
IP Address of the Unit (LAN side).
User Name/Password credentials needed to login to the Web Interface on the LAN side
of the unit
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
29
QR Code providing links to support documentation for all Calix products. This same QR
code is also printed on the product label affixed to the GigaCenter.
The QR code printed on the inventory label above and the product label below provides
useful information about the GigaCenter as follows:
Scan Description
Segment
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
30
Utilities Menu Restore Default GigaCenter Since control is available to home subscriber, restoring defaults
Reboots. are limited to controls that the subscriber can modify.
Residential
Gateway values
are reset to factory
default.*
Rear of Labeled RESET GigaCenter IMPORTANT: The RESET button must be pressed and held until
GigaCenter Reboots. the GigaCenter LEDs flash (about 5 seconds). Pressing the
Residential RESET button momentarily (less than 5 seconds executes a
simple reboot of the GigaCenter (Home Gateway values
Gateway values
are reset to factory persisted).
default.* Note: Pressing Utilities > Restore Defaults above and clicking the
manual reset on the back of the GigaCenter yields identical
results.
* - Examples include security credentials, SSID Names, Wi-Fi radio behaviors, and the like.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Chapter 4
In the following pages, a high level overview of the EWI is presented. Links are also
provided that will allow you to drill more deeply into each item with specific field definitions
for all displayed options.
The Home Gateway partition of the GigaCenter is managed through the GigaCenter
Embedded Web Interface (EWI) and includes the following deployment options presented
as menu items in the top navigation bar:
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
32
Status Menu
Sub-Menu Description
Item
Connections (on The Connections page provides network status/details for the GigaCenter network. The
page 35) table below reflects the current state of the WAN, Local Internet, and the IP Gateway
connections.
Devices (on page The devices table displays a list of devices currently connected to the Local Area
Error! Bookmark Network. Devices can be edited from the Edit Device table.
not defined.)
Internet (on page Current Internet status of the Internet Service Provider is viewable. Basic connection
Error! Bookmark status, ISP statistics, and IPv4/IPv6 Addressing parameters are available.
not defined.)
Ethernet (on page The table reflects the Ethernet port connection status including connection speeds and
Error! Bookmark current packet statistics.
not defined.)
Wireless (on page The table displays a summary of the settings for each wireless network (by device).
Error! Bookmark
not defined.)
NAT (on page This dynamic table reflects the current state of the Network Address Translation (NAT).
Error! Bookmark As IP addresses are resolved against the NAT table, contents of this screen are updated
not defined.) in real time.
Routing (on page The table displays the current routing assignments for Internet traffic on the network.
Error! Bookmark
not defined.)
Security (on page The table displays all modified security settings from the factory default values.
Error! Bookmark
not defined.)
Sub-Menu Description
Item
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
33
Wireless Menu
Sub-Menu Description
Item
2.4G Network (on Provides settings for enabling the radio, SSID set-up, wireless security, MAC Authentication, and
page 53) WMM.
5G Network (on Provides settings for enabling the radio, SSID set-up, wireless security, and MAC Authentication.
page 53)
Advanced Radio Various countries will allow or block certain Wi-Fi channels and as such, you can specify what
Set-up (on page country the radio is being deployed in. In addition, these countries may have varying Wi-Fi signal
Error! Bookmark power levels which are also selectable by country.
not defined.)
WPS (on page WPS provides a secure way to establish a wireless network by sharing the wireless key between
Error! Bookmark the device and wireless client.
not defined.)
Utilities Menu
Sub-Menu Description
Item
Configuration Save Configuration Backup is used to save the gateway device configuration information to a file on
(on page 62) your PC. Configuration Restore reloads the file from your PC to restore your gateway device back
to the same settings as when the backup file was last saved.
Restore Defaults Select the restore button to restore the gateway device to the default settings
(on page Error!
Bookmark not
defined.)
Reboot (on page Select the Reboot button to reboot the gateway device.
Error! Bookmark
not defined.)
Web Activity Log Web Activity Log displays a list of the most recently accessed websites. This table displays URL's
(on page Error! accessed by the CPE on the LAN side of the RSG.
Bookmark not
defined.)
Ping Test (on page Test your internet connectivity to a specific host using the ping test below. Results of completed
Error! Bookmark ping tests are displayed with detailed statistics.
not defined.)
Traceroute (on Traceroute is used to determine the route taken by packets across a network. Each test reports
page Error! the round trip times for 3 ICMP packets. Each response shows the maximum number of hops
Bookmark not displayed in the first column. The test repeats until the host is reached or the maximum hop count
defined.) of 30 is reached. The times for each ICMP packet are displayed in the table. An asterisk (*) in a
field means that no-response was received for the ICMP packet request.
System Log (on The system log provides an accounting of significant gateway device events.
page Error!
Bookmark not
defined.)
Firewall Log (on The Firewall Log page provides a table of the most recently dropped packets by the firewall.
page Error!
Bookmark not
defined.)
Advanced Menu
Sub-Menu Description
Item
Scheduling and Scheduling and Blocking allows for the configuration of network access, service blocking, and
Blocking (on page website blocking.
74)
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
34
IP Addressing (on IP Addressing settings allow for the configuration of WAN, DHCP, and DNS settings across the
page 82) network.
Static Routing (on Routing settings allow for the configuration of dynamic (RIP) or static routing across the network.
page Error!
Bookmark not
defined.)
Quality of Service Quality of Service settings allow for the configuration of QoS prioritization rules across the
(on page 90) network.
Security (on page The Calix GigaCenter incorporates various features that ensure overall network security.
92)
Remote Remote Management settings allow for the configuration of a secure connection to the GigaCenter
Management (on network from a remote location.
page 104)
Status Menu
The Status Menu provides information on the status of GigaCenter network settings.
Ethernet - Displays the GigaCenters Ethernet ports and provides connection status with
packet statistics.
Wireless - Provides state and status of any of four possible Wi-Fi networks (selectable)
provisioned on the GigaCenter.
NAT - Provides a dynamic display of the Network Address Translation table including
Source/Destination IP info, protocol used, and source/destination port.
Routing - Provides a table of IPv4 routing assignments including Destination IP,
Network Mask, and Gateway IP address information.
Security - Provides a table of security features that have customized "rules" applied that
deviate from the default behavior
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
36
Connections
The Connections page provides network status/details for the GigaCenter network. The
table below reflects the current state of the WAN, Local Internet, and the IPv4/IPv6
Gateway connections.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
37
Wide Area Network Connection status of the GigaCenter to the N Connected‡, Not Connected
Info Only
(WAN) WAN
IPv4 Internet Access Displays the current connection state of N Unconfigured, Connecting, Connected,
Info Only
the GigaCenter Disconnecting, Disconnected, Blank‡
IPv6 Internet Access Displays the current connection state of N Unconfigured, Connecting, Connected,
Info Only
the GigaCenter Disconnecting, Disconnected, Blank‡
To edit the above settings, go to Advanced > IP Addressing > WAN Settings
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
38
Devices
The table below displays a list of devices currently connected to the Local Area Network.
Devices can be edited from the Edit Device table.
Show inactive Selecting this box displays or hides the list Check Box Yes N/A - For Inactive devices, text is
devices of inactive devices connected to the displayed as "grayed out" if check box
GigaCenter is selected.
Icon Graphical depiction of the device Info Only To edit an Available icons include: Camera, Cell
connected to the GigaCenter icon, see Phone, Computer, Gaming Console,
section iPhone, IPTV STB, Phone, Printer, PS-
below. 3, Router, Satellite Receiver, Server,
Video Camera, Wii, X-Box 360.
Device Name assigned to device connected to the Info Only To edit a Alphanumeric String - 16 characters
GigaCenter device name, maximum
see section
below.
IP Address IP address of the device connected to the Info Only No Auto-populate. When device connects
GigaCenter and is recognized, IP address is
displayed in this field.
MAC Address MAC address of the device connected to Info Only No Auto-populate. When device connects
the GigaCenter and is recognized, MAC address is
displayed in this field.
Connection Type Type of connection between GigaCenter Info Only No Auto-populate. Wi-Fi or Ethernet.
and this device
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
39
Select the LAN Choose the LAN device connected to the Drop-down No, list
device GigaCenter from the pull down menu List reflects The device’s IP Address is the default
connected device name.
device’s
name (name
can be
changed in
"Enter the
new device
name" field
below)
Enter the new device Change the selected LAN device's name Alpha-text Yes Alpha-numeric string
name Box Note: Spaces are not allowed in this
string.
Select a device icon Choose the graphical element to be Drop-down Yes Available icons include: Camera, Cell
displayed that represents this device List Phone, Computer, Gaming Console,
iPhone, IPTV STB, Phone, Printer, PS-
3, Router, Satellite Receiver, Server,
Video Camera, Wii, X-Box 360.
NOTE: Static Devices are not displayed in this table.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
40
Internet
Current Internet status of the Internet Service Provider is viewable. Basic connection status,
ISP statistics, and IPv4/IPv6 Addressing parameters are available.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
41
Device IPv4 Address IPv4 address for the GigaCenter Info Only No Dot delimited, xx.xx.xx.xx
Device IPv4 Subnet Internet Protocol v4 Subnet Mask is Info Only No Dot delimited, xx.xx.xx.xx
Mask used to split and confine traffic to one Default: 255.255.255.0
network. A subnet mask keeps all local
network traffic local and only routes
Internet traffic to the Internet preserving
network resources
DNS Address #1 The Domain Name Server (DNS) Info Only No Dot delimited, xx.xx.xx.xx
Addresses #1 and #2 are the IP
addresses of the primary and secondary
servers that provide the URL to IP
address translation for a specific site on
the Internet. When a URL is entered into
the address bar of a browser, the
DNS Address #2 Info Only No Dot delimited, xx.xx.xx.xx
designated DNS translates the domain
to an IP address to find the site on the
Internet
Remote Gateway Remote Gateway IP Address for the Info Only No Dot delimited, xx.xx.xx.xx
Address device
IPv4 Packets Sent Number of IPv4 packets sent by the Info Only No Numeric
GigaCenter
IPv4 Packets Received Number of IPv4 packets received by the Info Only No Numeric
GigaCenter
Link Uptime Elapsed time since last loss of Info Only No Days/Hours/Minutes/Seconds format
connection to the gateway of the Example: 6D 17H 26M 15S
GigaCenter
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
42
Device IPv6 Address IPv6 address for the GigaCenter Info Only No colon-hexadecimal notation
DNS Address # 1 The Domain Name Server (DNS)
Addresses #1 and #2 are the IP
addresses of the primary and secondary Info Only No colon-hexadecimal notation
servers that provide the URL to IP
address translation for a specific site on
the Internet. When a URL is entered into
DNS Address # 2 the address bar of a browser, the
designated DNS translates the domain
to an IP address to find the site on the Info Only No colon-hexadecimal notation
Internet
IPv6 Gateway Address IPv6 Gateway Address for this device Info Only No Numeric
Number of IPv6 packets sent by the
IPv6 Packets Sent Info Only No Numeric
GigaCenter
Number of IPv6 packets received by the
IPv6 Packets Received Info Only No Numeric
GigaCenter
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
43
Ethernet
The table below reflects the Ethernet port connection status including connection speeds
and current packet statistics.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
44
Wireless
The table below displays a summary of the settings for each wireless network (by device).
Network Name (SSID) Pull down list of wireless network names Drop-down Yes List of Network Names created in the
(SSID) List system. Up to 4 networks are allowed.
Network State State of the selected wireless network Info Only No Enabled‡/Disabled
Network Name Wireless broadcast of wireless network Info Only No Enabled‡/Disabled
Broadcast name
Wireless Radio Wireless Radio State Info Only No On‡/Off
Wireless Mode List of wireless modes supported Info Only No 802.11b, 802.11g, and 802.11n
Frequency Wireless radio broadcast frequency Info Only No x.x GHz
Default: 2.4 GHz
Operating Channel Number of active wireless radio Info Only No Number of active channels
broadcast channels
Channel Mode Defines whether the current channel Info Only No Auto‡ or Manual
displayed was dynamically assigned
(Auto Select) or manually selected
(Manual)
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
45
Connected Devices
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
46
Protocol Type of protocol used to manage Internet Info Only No Alphanumeric protocol name. TCP,
data streams on this device UDP
Timeout Number of seconds remaining for this Info Only No 1-120 seconds
table entry. Note: Entry of 431999 indicates an
entry that has just expired.
Source IP Data stream source device IP address Info Only No Dot delimited, xx.xx.xx.xx
Source Port Data stream source device port number Info Only No Numeric (1-65535)
Destination IP IP Address of the GigaCenter Info Only No Dot delimited, xx.xx.xx.xx
Destination Port Destination Port for the GigaCenter Info Only No Numeric port Number, 5 digit
maximum
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
47
Routing
The table below displays the current routing assignments for Internet traffic on the network.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
48
Security
The table below displays all modified security settings from the factory default values.
Security Feature WAN and Lan security feature Info Only No Applications, DMZ Hosting, Firewall
descriptions Settings, NAT, UpNp
LAN IP The IP address of the LAN interface Info Only No Dot delimited, xx.xx.xx.xx. If no LAN is
configured, undefined is displayed.
Applied Rule Description of applied rule when Info Only No Displays currently assigned rule for
deviating from default security settings security features shown above
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
49
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
50
Connect to Internet
Gateway device connection settings are provisioned here.
Note: Since the DHCP server handles IP address functionality, no additional information is
needed.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
51
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
52
The displayed timezone setting for the GigaCenter is controlled by the NTP server setting
that is pre-provisioned in the GigaCenter configuration file.
Current Time Zone Displays time zone based on location of Drop-down View Only Default: Pacific Time (US and
GigaCenter List Canada)
Important: Time displayed is in UTC Time.
Note: In a GPON environment, Timing is
derived from the OLT's timing source and
will over-ride any settings made here.
Automatically adjust Determine whether the NTP Server time Check box View Only Default: Unchecked (No adjustment
clock for Daylight makes adjustment for Daylight Saving for daylight savings time)
Saving Time Time.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
53
Wireless Menu
Under the Wireless menu, Wi-Fi, security, WPS, and MAC authentication parameters are
provisioned.
Note: For purposes of this guide, definitions for both 2.4 GHz and 5.0 GHz wireless radios
are combined and shown as one screen. Differences between the two protocols are noted.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
55
Radio Setup
Radio Setup provides the ability to customize the wireless radio settings. Both 2.4 GHz and
5.0 GHz radios can be configured separately.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
56
SSID Setup
Service Set Identifier (SSID) is used to identify this gateway device for connection to other
wireless devices. The SSID may be broadcast to publish its value to aid in connecting this
device to other wireless devices or it may be hidden to prevent unauthorized access. The
factory-defined SSID values may be redefined to a user-specified name.
SSID (Network Name) The name of the GigaCenter (needed for Drop-down Yes Alphanumeric
identifying the GigaCenter when List Default: SSID on GigaCenter product
connecting to other wireless devices) label
Broadcast SSID Allows or restricts the wireless broadcast Radio Yes Enabled ‡ or Disabled
of the SSID (GigaCenter network name) Button
so networked and non-networked
wireless devices are aware of the
wireless network
Rename SSID Rename the selected SSID (Network Alpha-text Yes Alphanumeric - 32 characters
Name) Box Default: Initially populated with SSID
Network Name
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
57
Wireless Security
Secure your wireless traffic from security threats since wireless traffic transmits unprotected.
SSID (Network A list of the SSID names for the Drop-down Yes Listed names
Name) GigaCenter wireless network List Default: SSID from GigaCenter
product label
Security Type A list of security types and options. WPA- Drop-down Yes Listed security types: WPA-WPA2-
WPA2-Personal and WEP types require List Personal ‡, WEP, Security Off
different types of "Encryption" and
"Authentication"
Encryption Type A list of encryption types and options Drop-down Yes AES ‡, TKIP, or Both
List
Security key/passphrase used for WPA- Radio Yes Alphanumerical string, 63 characters
WPA2 secured network type (from above) Button max.
Default: Security Key/Passphrase
listed on GigaCenter product label
Security
Key/Passphrase
Security key/passphrase used for WEP Radio Yes Numeric hexadecimal or decimal
secured network type (from above) Button for string (12 characters maximum for
each SSID 128 bit security, 10 characters
with Alpha- maximum for 64 bit security)
text Box for Default: 123456789012
changing
security key
Apply Button used to apply above settings Action Yes Apply and save changes
Button
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
58
MAC Authentication
Limit access to your GigaCenter by using the MAC address of specific wireless devices. A
device list is also provided.
SSID (Network A list of up to four SSIDs (Network Names) Drop-down Yes Up to 4 network names are displayed
Name) List Default: SSID name from GigaCenter
product label
MAC Authentication MAC Authentication limits network access Radio Yes Enable or Disable
State by using the MAC address of specific Button Default: Enabled
wireless device as a key for network
access
Apply Applies changes to MAC Authentication Action Yes Click to Apply
Button
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
59
WMM state Enables or disables Wi-Fi Multimedia Radio Yes Enabled ‡ or Disabled
functionality button
Power Save Enables or disables Power Save Radio Yes Enabled ‡ or Disabled
functionality button
Apply Button used to apply above settings Action No Apply and save above changes
Button
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
60
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
61
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
62
Utilities Menu
The Utilities menu provides controls for executing routine network tasks as well as providing
links to various system troubleshooting routines.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
63
Configuration Save
Configuration Backup is used to save the gateway device configuration information to a file
on your PC. Configuration Restore reloads the file from your PC to restore your gateway
device back to the same settings as when the backup file was last saved.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
64
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
65
Restore Defaults
Select the restore button to restore the gateway device to the default settings Upon selecting
this option, the GigaCenter will be restored to factory default settings.
Important: Any changes to the configuration since the last time this command was executed
will be lost.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
66
Reboot
Select the Reboot button to reboot the gateway device.
Reboot Press the Reboot button to reboot the Action No Reboot the GigaCenter
GigaCenter Button
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
67
Logging "Enabled" and "Disabled" buttons used Radio Yes Enabled ‡ or Disabled
to activate and deactivate the logging of Button
Web activity.
When logging is disabled, the Refresh
option and table are not displayed.
Refresh Allows the Web Activity Log, displayed "Manual" Yes Manual ‡ or Auto with Refresh Rate
on the Web and "Auto" setting.
Activity Log page, to be refreshed Radio Auto refresh intervals: Realtime, 10,
manually or automatically as well as Button 20, 30, or 60 seconds
setting the auto-refresh intervals
If Auto is chosen, a drop-down list of
auto refresh intervals is displayed. If
Manual is chosen, a "Refresh" action
button is displayed
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
68
Ping Test
Test your internet connectivity to a specific host using the ping test below. Results of
completed ping tests are displayed with detailed statistics.
Note: When executing the ping test, 4 packets (32 bytes) are sent consecutively for statistical
purposes.
Version Define whether IPv4 or IPv6 IP Addresses Radio Button Yes IPv4‡, IPv6
are pinged.
URL or IP Address IPv4 or IPv6 address of specific Web host Alpha-text Box Yes URL or IP Address syntax
to be tested or url for specific IP address.
Packet size in bytes Specific packet size to be sent Numeric-text Yes In bytes
Box
Source IP Address IP Address of GigaCenter initiating ping Numeric-text Yes Dot delimited: xx.xx.xx.xx or colon-
(Optional) Box hexadecimal delimited
Test Click "Test" to commence ping test Action Button Yes Performs ping test
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
69
Reply From URL or IP address of host being tested Info Only No Recognizable URL or IP Address
Bytes Bytes received from the pinged host Info Only No Number of bytes
Time Time ping reply was received from host Info Only No Date and time
TTL Total router "hops" before packet times Info Only No Numeric
out.
Ping Statistics
Packets Sent Number of packets sent to the host Info Only No Total number of packets sent per
ping request.
Packets Received Number of packets received back from the Info Only No Total number of packets received
host per ping request.
Packets Loss Number of test packets sent by the Info Only No Percentage of total packets versus
GigaCenter minus the number of packets packets lost.
received back by the GigaCenter
Round Trip Min Minimum elapsed time for a ping-test Info Only No Round trip minimum time in milli-
packet to be sent by the GigaCenter and seconds.
received back from the host by the
GigaCenter
Round Trip Max Maximum elapsed time for a ping-test Info Only No Round trip maximum time in milli-
packet to be sent by the GigaCenter and seconds.
received back from the host by the
GigaCenter
Round Trip Average Average amount of elapsed time for a Info Only No Average round trip time for all 4
ping-test packet to be sent by the packets sent.
GigaCenter and received back from the
host by the GigaCenter
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
70
Traceroute
Traceroute is used to determine the route taken by packets across a network. Each test
reports the round trip times for 3 ICMP packets. Each response shows the maximum
number of hops displayed in the first column. The test repeats until the host is reached or the
maximum hop count of 30 is reached. The times for each ICMP packet are displayed in the
table. An asterisk (*) in a field means that no-response was received for the ICMP packet
request.
Version Specify whether the traceroute command is Radio Yes IPv4‡, IPv6
applied to an IPv4 or IPv6 IP address. Button
Enter a URL or IP Enter the URL or IP address of the Alpha-text Yes Recognizable URL or IP Address
Address destination host Box
Mode Select the Traceroute protocol Radio Yes ICMP, UDP
Button
Enable Reverse Enable or Disable reverse DNS execution. Radio Yes Enable/Disable
DNS With reverse DNS enabled, an IP address Button
search provides domain name registry and
registry table information. You may be able
to identify spammers or malicious attacks
on your firewall by using reverse DNS
lookup. Also useful in determining the ISP
name for a particular IP address.
Start Trace Initiate the traceroute request Action Yes Initiate traceroute
Button
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
71
Traceroute Results
This site performs a reverse DNS lookup of an IP address by searching domain name
registry and registrar tables. IP addresses are four numbers in the range of 0 to 255 separated
by periods.
You may be able to identify the domain name of a spammer sending you spam email or the
domain name of a computer trying to break into your firewall or someone trying to hack
your system.
You may also be able to use this information to determine the name of the internet service
provider assigned to a particular IP address.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
72
System Log
The system log provides an accounting of significant gateway device events.
Refresh Interval - Allows the System Log to be refreshed Radio Yes See options directly below
Manual Refresh manually or automatically as well as Button with
setting the auto-refresh intervals Action
Button
Manual Refresh Allows for on-demand refresh of the "Manual Yes Manual Refresh ‡ Action Radio
System Log Refresh" Button with Refresh Action Button
button and
a "Refresh"
radio button
for manual
refresh
Auto Refresh Allows and schedules auto-refresh of the "Auto Yes Auto Refresh Radio Button with
System Log Refresh" Refresh Action Button
button along Auto refresh intervals list: Real time,
with a pull- 10, 20, 30 seconds, or 1 minute ‡
down list of
auto refresh Manual "Refresh" Radio Button
intervals
Reboot Behavior Controls System Log reboot behavior for N/A N/A N/A
clearing or saving the System Log
information
Clear on Reboot When chosen, clears the System Log on Clear on Yes Clear on Reboot
reboot Reboot
action
button
Save on Reboot When chosen, saves the System Log on Save on Yes Save on Reboot
reboot Reboot
action
button
Save Log Click button to save SystemLog to your PC Action No Save Log action button
Button
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
73
Date Date of significant GigaCenter event Info Only No Date format: mm/dd/yy
Time Time of significant RSG event Info Only No Time format: hh:mm:ss AM/PM
System GigaCenter system that experienced the Info Only No System event Name
event
Action GigaCenter response to the event Info Only No System Response
Firewall Log
The Firewall Log page provides a table of the most recently dropped packets by the firewall.
The output includes information on:
Source MAC Address
Destination MAC Address
Source IP Address
Destination IP Address
Packet protocol
Source Port Assignment
Destination Port Assignment
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
74
Time Displays the date and time the log was Display No date format: mm/dd/yy
captured Only time format: hh:mm:ss AM/PM
Details Displays MAC Address, IP Address, Display No N/A
Packet Protocol, and Port Assignment Only
information.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
75
Advanced Menu
The Advanced Menu provides controls for:
Scheduling/blocking access to specific sites or services
Customization of all IP Addressing protocols
Dynamic vs. Static Routing controls
QoS settings
Additional Security settings
Remote EWI settings
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
76
Note: Features listed below can be customized under the Advanced > Scheduling and
Blocking tab of the EWI.
Scheduling Access - Limits can be applied to LAN devices as to the time and day these
devices can access the Internet. Configurable by device name or MAC address.
Service Blocking - Service blocking prevents specific devices from accessing internet
applications. Blocking is accomplished by creating an association between a service and
device name or IP address.
Website Blocking - Website blocking prevents specific internet sites from being
accessible. Blocking is accomplished by associating a specific URL with a device name or
IP address.
Scheduling Access
Access Scheduler sets Internet access rules for LAN devices. Scheduled devices are displayed
in the Device Access List.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
77
Device If Device Radio Button is chosen, Drop- Radio Yes Alphanumeric Names
down List of device names is displayed Button and Default: Connected LAN devices
Drop-down
List
MAC Address If MAC Address is chosen, Alpha-text box Radio Yes Colon delimited (xx:xx:xx:xx:xx:xx)
is displayed Button and
Alpha-text
Box
Days of the week to Check days of week to allow LAN Check Box Yes Selectable by day of week
allow Internet Access devices Internet access
Time of day ranges Set the hours of the day devices are Drop-down Yes Select pre-defined start and stop times
allowed Internet access List for schedule range
Add Add the chosen device’s Internet access Action Yes Click to apply and save changes
schedule Button
Device Name List of LAN devices that are controlled by Info Only Yes - see List of days allowed (Mon, Tue, Wed,
Internet access list "Create Schedule" above Thur, Fri, Sat, Sun)
MAC Address MAC address of LAN devices that are Info Only Yes - see Alpha-numeric colon delimited MAC
controlled by Internet access list "Create above address
Schedule"
Allowed Days Days Internet access is allowed for each Info Only Yes - see Drop-down List
device above
Allowed Time Starting and Stopping times to allow Info Only Yes - see Drop-down List
Internet access to the device or service above
Remove Remove device from "Create Schedule". Action Yes Remove scheduling restrictions on
Note - removed devices have no Button chosen device
restrictions unless specified otherwise in
Service Blocking or Website Blocking
Service Blocking
Service blocking provides the ability to block specific Internet services per device. From the
Service Blocking tab, a new association can be created between a service and a device. Newly
created association details are displayed in the Service Blocking List.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
78
New Select the "New" button to set up Action Yes Select the New button to open the
blocking of an Internet service per device. Button "Create New Association Dialog shown
above"
Device Name List of "Device Names" set up with Info Only No Alphanumeric name of the device where
service blocking service blocking is desired.
IP Address "IP Address" list of devices set up with Info Only No Dot delimited IP address of the device.
service blocking (xx.xx.xx.xx)
Service Blocked Name of "Service Blocked" Info Only No Alphanumeric name of the type of
service to be blocked.
Remove Button to "Remove" the LAN device from Action Yes Remove Service Blocking between this
service blocking Button device and the listed service.
By clicking the New action button on the Service Blocking List screen, an association can be
created between a specific service and a specific device.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
79
Service A list of service rules previously Drop-down Yes - see Previously configured service blocking rules
configured for service blocking List below appear in this drop-down list.
View Button to "View" an info only chart Action Button Yes View only
listing: "Service Rule", "Protocol"
type, "Port Start", "Port End", and
"Port Map" for the chosen
"Service" pull down menu
New Reveals the "Create New Service Action Button Yes See next section below.
Rule" page used to create a new
service to be added to the
"Service" pull down list. "Create a
New Service Rule" consists of
"Name" field, "Protocol" pull down
list, "Clear Fields" radio button,
"Port Start" field, "Port End" field,
"Port Map" field and "Apply" and
"Cancel" radio buttons - See
Create New Service Rule below
Associate "Device" button used to associate Action Button Yes Device button with alphanumeric list of devices -
Service with selected name on pull down with Device or IP Address
Device the above listed "Service"
Associate "IP Address" button used to reveal Action Button Yes Device button with alphanumeric list of devices -
Service with IP a field for entering the IP Address Device or IP Address
Address of a device to be associated with
the above listed "Service"
Apply/Cancel "Apply" radio button applies and Action Button Yes Apply and Save changes or Cancel
Button saves the "Create New Rule"
settings into the Service Rule
Chart and pull down "Services "
list
"Cancel" radio button cancels
application of the service rule
setting on the "Create New
Service Rule" page and exits the
page
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
80
By clicking the New Service action button in the Create New Association screen, rules can be
configured for specific services.
Name Name of the new service blocking Drop-down List Yes Alpha-numeric name
rule to create
Protocol Packet protocol to be used for the Drop-down List No TCP, UDP, or Both
service rule Default: TCP
Clear Fields Use the "Clear Fields" radio button to Action Button Yes Clear fields radio button.
clear the "Name", "Port Start", "Port
End" and "Port Map" fields in the
"Create New Service Rule" section
Port Start Starting TCP or UDP port number to Alpha-numeric Yes Port 1 through 65535
that is affected by the blocking rule. Text
Port End Ending TCP or UDP port number to Alpha-numeric Yes Port 1 through 65535
that is affected by the blocking rule. Text
Port Map Alpha-numeric Yes Port 1 through 65535
Text
Apply/Canc Apply and Save or Cancel the Action Button Yes Apply or Cancel radio button
el changes to the service rule
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
81
Website Blocking
Website blocking provides the ability to block specific websites per device or IP address.
New Select the "New" button to set up Action Yes Create Blocking for a website.
blocking of a specific website per device Button
or IP address
Device Name Specific Device or List of all devices Info Only No Static Table
tagged for blocking Default: All Devices
IP Address Specific IP Address or all IP addresses Info Only No Static Table
associated with a particular device Default: Device Button Selected
Website Blocked Specific website to be blocked Info Only No URL of website to be blocked (dot
delimited format)
Remove Button to Remove the network device Action Yes Remove radio button
from website blocking Button
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
82
Choosing New from the screen above opens the "Create New Association" window where
specific websites, devices, or IP addresses may be blocked.
New Select the "New" button to set up blocking Action Button Yes Create Blocking for a website.
of a specific website per device or IP
address
Website Address Input a website address that is to be Alpha-numeric Yes Alpha-numeric text in URL format
blocked Text
Associate Website Choose a currently connected network Radio Button Yes Default: Device Button Selected
with Device device to block the URL input above with Drop-down Default: Drop-down List "All
List Devices"
Associate Website Choose a currently connected network Radio Button Yes Dot-delimited IP address
with IP Address device by inputting its IP address with Numeric Default: Radio Button Not Selected
Text
Default: All IP addresses
Apply/Cancel Apply creates an association as Action Button Yes Apply and Save changes.
provisioned above and saves the
association. Cancel discards all changes
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
83
IP Address Overview
IP Addressing settings allow for the configuration of WAN, DHCP, and DNS settings across
the network.
Note: Features listed below can be customized under the Advanced > IP Addressing tab of
the GUI.
WAN Settings - Sets ISP requirements and parameters for internet access.
IPv6 LAN Settings - Sets up parameters for IPv6 addressing.
DHCP Settings - DHCP server configuration, IP addressing reservations, server lease
times, as well as DNS server parameters are configured here.
DHCP Reservation - DHCP reservations allow for the permanent allocation of a
DHCP address to a client, even after a reboot.
DNS Host Mapping - DNS Host Mapping creates a static host name for a specific IP
address at the router. Both WAN and LAN IP addresses can be mapped here.
Dynamic DNS - Dynamic DNS associates a WAN IP address with a specific host name
and updates the DNS server when the WAN IP address changes.
Note: The Dynamic DNS service is hosted through www.dyndns.com (http://www.dyndns.com)
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
84
DHCP Settings
DHCP Settings define the LAN addressing parameters for your device to allocate IP
addresses to LAN devices.
DHCP Host Name Defined host name for the DHCP service. Alpha text box Yes Alpha-numeric string.
Domain Name Assigned Domain Name for the IP Address Alpha text box Yes Alpha-numeric string.
associated with this GigaCenter
DHCP server state Set the "Enabled" or "Disabled" state of the Radio Button Yes Enable or Disable the DHCP
GigaCenter to allocate IP addresses to Server
attached LAN devices
Device IP Address The IP Address of the GigaCenter device Numeric Yes Dot delimited, xx.xx.xx.xx
Beginning IP Address The first assignable IP address for LAN Numeric Yes Dot delimited, xx.xx.xx.xx
devices
Ending IP Address The last assignable IP address for LAN Numeric Yes Dot delimited, xx.xx.xx.xx
devices
Subnet Mask The assigned "Subnet Mask" is used to split Numeric Yes Dot delimited, xxx.xxx.xxx.xxx
and confine traffic to one network. A subnet Default: 255.255.255.0
mask keeps all local network traffic local
and only routes Internet traffic to the
Internet preserving network resources
DHCP Server Lease The length of time the DHCP server lease Alpha-numeric Yes Enter lease time in Days,
Time remains active without renewing Text Hours, and Minutes
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
85
DHCP Reservation Sticky: Once the router initially assigns a Radio Button Yes Sticky‡ or Permanent
particular IP address to a client (laptop,
tablet, smart phone, etc.) the client keeps
that same address until the router is
rebooted. Upon reboot, the router attempts
to restore the existing DHCP address. This
is the default behavior. In this mode, leases
expire and are re-issued using the same IP
address if possible.
Permanent: Once the router assigns a
particular address to a client, the client
always gets that address until the router is
rebooted. Upon reboot, a different address
is assigned to the client however the
previous lease/IP address are retained.
Note: Usage of "permanent" may result in
exhaustion of the IP address pool and
should be used only in rare circumstances.
Please contact your operator before using
permanent.
Note: Performing a factory reset restores
the default behavior (Sticky).
Servers allocated with If Default Servers are selected, assigned Radio Button Yes Default Servers ‡ or Custom
DHCP requests - DNS server (192.168.1.1) is passed to LAN- Servers
DHCP DNS Type side DHCP clients during Offer/ACK Note: If you enable Dynamic
messaging . If Custom Servers is selected, Routing (RIP) without disabling
the primary and secondary DNS servers NAT, an error message
provide the URL to IP translation for a
appears reminding you to
specific site (the ISP assigns DNS server disable NAT before
addresses). proceeding.
Note: This behavior is dependent on NAT
settings as well. With NAT enabled, whether
custom or default servers are chosen, the
GigaCenter always acts as the DNS proxy
agent to LAN side clients, behaving as the
default server (192.168.1.1). If NAT is
disabled, Custom server information from
the ISPs DHCP offers will be sent (when
this field is set to Custom Servers).
Apply Apply and Save changes to DHCP settings Action Button Yes Apply and save changes
This field defines the DNS-Server IP addresses that will be passed to LAN-side DHCP-clients in the Offer/Ack messages.
- If "Default" is selected, the GigaCenter local LAN host (192.168.1.1) will be sent.
- If "Custom" is selected, there is a complication with this that Randy will need to explain. Something to do with NAT….
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
86
IPv6 LAN settings determine whether IPv6 addressing will be supported on this GigaCenter
and now it functions.
Select LAN Select the LAN type. Drop-down Yes Primary Bridge
In this release, only Primary Bridge is List
available.
IPv6 Status Enable or Disable IPv6 address support Radio Yes Enabled, Disabled
Button
DHCPv6 Server Enable or Disable a DHCPv6 capable Radio Yes Enabled (Stateful), Enable (Stateless),
server. Enabled (Stateful) specifies a Button Disabled
standard DHCPv6 server while Enable
(Stateless) uses the Stateless Address
Auto-Configuration (SLAAC) method to
obtain IPv6 addresses.
Name Server Mode Select whether the default Name Server Radio Yes Default, custom
mode is used (DNS servers used by the Button
WAN) or a custom DNS server is
available.
For custom mode, you must enter a
Primary and Secondary DNS server IP
address.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
87
DHCP Reservations
DHCP reservation leases a permanent DHCP allocated address to a client and displays a list
of these reservations.
Select Device or Select the type of LAN device identifier, Radio Yes Choose Device ‡ or MAC Address. If
manually enter a MAC "Device" or a "MAC Address", to Button Device is chosen, select a device from
address associate with an IP Address the drop-down list.
Choosing the "Device" button reveals a If MAC address is chosen, default is
pull down list used to select the LAN Null.
device to be associated with an "IP
Address"
Choosing the "MAC Address" button
reveals a field used to identify the LAN
device to be associated with an "IP
Address"
Select an IP address Select the "IP Address" from the pull Drop-down Yes IP Addresses from the drop-down list.
to associate with a down range of IP Addresses to be List Range: 192.168.1.2 through
MAC address associated with the "Devices" and "MAC 192.168.1.254
Addresses" connected to the GigaCenter Default: 192.168.1.2
Apply "Apply" radio button applies and saves Action Yes Applies and saves changes
the "DHCP Reservation" settings Button
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
88
Device Name Device Name selected from above Info Only No Alpha-numeric
MAC Address MAC Address input above Info Only No Numeric - MAC address format:
xx:xx:xx:xx:xx:xx
IP Address IP Address selected from the drop-down Info Only No Dot delimited IP Address
list above xx.xx.xx.xx
Remove Remove the LAN device specified from Action Yes Remove the device
the DHCP Reservation List Button
DNS host mapping creates a static host name for the specified IP address in the DSL router.
WAN and LAN IP addresses are supported. A list of DNS Host mappings is also displayed.
DNS Host Name DNS Host Name to be associated with the Alpha-numeric Text Yes Alphanumeric
DNS IP Address Default: Null
DNS IP Address DNS IP Address to be associated with the Alpha-numeric Text Yes Dot delimited IP Address
above DNS Host Name (xx.xx.xx.xx)
Default: Null
Apply "Apply" radio button applies and saves the Action Button Yes Click to apply and save DNS
"DNS Host Mapping List" Host Mapping
IP Address IP Address for the WAN or LAN Static Info Only No Dot delimited IP Address
Host (xx.xx.xx.xx)
DNS Name DNS Name of the Static Host Info Only No Alpha-numeric text
Remove Click to remove the DNS Host IP Address Action Button Yes Click to remove mapping
from the Host Mapping table
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
89
Dynamic DNS
Dynamic DNS associates the WAN IP address of your router with a host name. Dynamic
DNS automatically updates DNS servers upon WAN IP address change. Dynamic DNS
(DDNS) is provided through www.dyndns.com.
Dynamic DNS state Select "Enabled" or "Disabled" Dynamic Radio Button Yes Enabled or Disabled ‡
DNS state
If DDNS is set to Disabled, the credential
options are not displayed.
Username Enter "Username" in field to access data Alpha-numeric Text Yes AlphaNumeric
base that associates WAN IP address of Default: Null
RSG with a host name
Password Enter "Password" in field to access data Alpha-numeric Text Yes AlphaNumeric
base that associates WAN IP address of Default: Null
RSG with a host name
Show Show the password Radio Button Yes If selected, actual password is
displayed. If not checked,
password is masked (all
"bullets")
Default: Values are masked
Dynamic DNS Enter the DNS host name. The dynamic Alpha-numeric Text Yes AlphaNumeric
hostname DNS service will automatically update Default: Null
DNS servers with any WAN IP address
change to the RSG
Apply "Apply" radio button applies and saves Action Button Yes Apply and Save Dynamic
the "Dynamic DNS host name" DNS security information
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
90
Static Routing
Adding routes manually to the routing table is considered static routing. If a change or a
failure occurs between two statically defined nodes, traffic will not be rerouted and must wait
for the failure to be resolved by the administrator. A list of assigned static routes is also
provided.
Destination IP Manually add the IP address of a Numeric Yes Dot delimited xx.xx.xx.xx
connected device to the gateway routing Default: 0.0.0.0
table
Subnet Mask Manually add the Subnet Mask of the Numeric Yes Dot delimited xx.xx.xx.xx
connected device to the gateway routing Default: 255.0.0.0
table
Gateway IP Manually add the Gateway IP address to Numeric Yes Dot delimited xx.xx.xx.xx
the gateway routing table Default: 0.0.0.0
Apply "Apply" radio button applies and saves Action Yes Click to apply and save changes.
the "Static Routing" settings Button
Static Routes
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
91
Note: Features listed below can be customized under the Advanced > Quality of Service tab
of the EWI.
QoS - Quality of Service helps prioritize LAN to WAN packet movement in and out of a
router. Options exist for classifying traffic type (video, voip, custom), traffic direction
(upstream or down), and DSCP class. Can be applied to all traffic of a given type or only
traffic from a given IPv4 or IPv6 address.
QoS (IPv4)
QoS prioritizes traffic types coming from the Upstream (LAN ports) or Downstream (WAN
port) before standard data traffic. Traffic comes from or to specific applications or devices
such as video players, game consoles, or voice adapters supporting Voice over IP (VoIP). By
applying QoS to your network it can increase performance and prevent your network from
becoming overloaded.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
92
QoS State Sets the "Enabled" or "Disabled" state for Radio Button Yes "Enabled" ‡ or "Disabled"
prioritizing the Quality of Service
New "New" radio button for creating a QoS Radio Button Yes Create a new rule
rule
QoS Type Select or create a QoS type from the pull Drop-down List Yes Choose Video, VOIP, VOIP
down list: Video, VOIP, VOIP Signaling, Signaling, Custom‡ to create rule.
Custom
Rule Name (Custom If QoS Type = Custom, then enter a Alpha-numeric Yes Alpha-numeric Text
only) name for the rule. Select or create a QoS Text Default: Null
type from the pull down list: Video, VOIP,
VOIP Signaling, Custom
QoS Direction Choose whether QoS is enforced on the Radio Button Yes Upstream ‡ or Downstream
upstream or downstream traffic
DSCP Class If QoS Type = Custom, Differentiated Drop-down List Yes Selectable options from pull down list
(Custom only) Services Code Point (DSCP) for coding of 7 classes of service as well as
QoS rule in IP packet to define "Class" of "Best Effort" ‡ and "Expedited
service Forwarding"
Queue Priority Queue Priority of "Custom" QoS Type: Drop-down List Yes Selectable options from pull down list
(Custom only) High, Medium, Low, Best Effort of: High ‡, Medium, Low, Best Effort
IP Addresses IP Addresses affected by the "QoS Rule": Radio Button Yes Choose either All IP Addresses ‡ or
(Custom only) All or Defined specific IP Addresses that need to
abide by QoS Rules.
Source IP (Define Apply QoS rule to the source IP address Info only No N/A
Only)
IP Apply QoS rule to this source IP address Numeric Yes Dot delimited xx.xx.xx.xx
Network Mask Apply QoS rule to this source Netmask Numeric Yes Dot delimited xx.xx.xx.xx
Default: 255.255.255.0
Port Range to Apply QoS rule to this source Port Range (2) Numeric Yes Alphanumeric range, xxxx.... to xxx....
Fields (to-from)
Destination IP Apply QoS rule to the destination IP Info Only No N/A
Address
IP Apply QoS rule to this destination IP Numeric Yes Dot delimited xx.xx.xx.xx
Address
Network Mask Apply QoS rule to this destination Numeric Yes Dot delimited xx.xx.xx.xx
Netmask Default: 255.255.255.0
Port Range to Apply QoS rule to this destination Port (2) Numeric Yes Alphanumeric range, xxx. . . to xxx. . .
Range Fields (to-from) Default: Null
Apply "Apply" radio button applies and saves Radio Button Yes Click to apply and save changes
the "QoS Rule" settings
Cancel "Cancel" radio button cancels the "QoS Radio Button Yes Click to cancel QoS Rule settings
Rule" settings
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
93
Name Name of QoS rule Info Only "Edit" mode Info Only
only
Direction Data flow direction to which QoS rule is Info Only "Edit" mode Info Only
applied only
DSCP Differentiated Services Code Point Info Only "Edit" mode Info Only
(DSCP) QoS class of service applied only
Priority Priority of service applied Info Only "Edit" mode Info Only
only
Source Source of data to which QoS rule is Info Only "Edit" mode Info Only
applied only
Destination Destination of data to which QoS rule is Info Only "Edit" mode Info Only
applied only
Edit Edit this QoS rule Radio Button Yes Click Edit to change QoS Rule
settings
Remove Remove this QoS rule Radio Button Yes Click Remove to discard this QoS
Rule
Security Overview
The Calix GigaCenter incorporates various features that ensure overall network security.
Note: Features listed below can be customized under the Advanced > Security tab of the
EWI.
Administrator Credentials - Administrator credentials prevent outsiders from accessing
the gateway device's firmware settings.
Application Forwarding - The Application Forwarding feature allows a LAN device to
receive incoming WAN traffic on a "per-application" basis. All traffic into the device
associated with a given application is forwarded to the defined device. Associations are
made between an application and a device name (or IP Address).
Port Forwarding - Similar to Application Forwarding, Port Forwarding allows a LAN
device to received traffic on a port range basis. Traffic from a specific local port (or range
of ports) and a specific remote port (or range) are specified.
Firewall - The Firewall blocks incoming IPv4 or IPv6 traffic based on the level of
security desired. Pre-programmed services can be manipulated to allow or ban incoming
or outgoing traffic based on the security level chosen.
DMZ Hosting - Digital Media Zone Hosting allows for the placement of any LAN
device outside the firewall. Since this device, by definition, is now being hosted
elsewhere, it can now be accessed using the WAN IP address (Connection Status page).
UPnP - UPnP (Universal Plug and Play) capable devices simplify the connection and
implementation of devices into your network.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
94
Administrator Credentials
Administrator credentials prevent outsiders from accessing the gateway device's firmware
settings. After creating a username and password, you will need to enter them before you can
access the gateway device's configuration settings.
Credentials Determines whether credentials are Radio Button Yes Required ‡ or Not Required
required to gain access to the gateway Note: If Not Required is chosen,
device's configuration settings
Login and Password fields are not
displayed
Administrator - Login If credentials are required, the login name Alpha-numeric Yes See the topic entitled Passwords
is entered here. Text for a list of allowable characters
Default: admin
Administrator - If credentials are required, the password is Alpha-numeric Yes See the topic entitled Passwords
Password entered here. Text for a list of allowable characters.
Default: See label shipped with
GigaCenter
Show When checkbox is checked, displays the Checkbox Yes When unchecked, the password is
un-masked password not displayed (masked with a string
of bullets)
Apply Click to apply and save login and Action Button Yes Click to apply and save changes
password
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
95
Application Forwarding
Application Forwarding forwards the application's specified ports to the selected device or IP
address. The subscriber can forward traffic from the WAN source to a local LAN device on
a per-port basis.
Create New Create a new association between an Drop-down Yes Choose from a previously defined
Association - application’s specified port and a device List application from the drop-down list. If
Application or IP address. Applications are defined none exists, create one using the New
using the New Association radio button radio button. To view previously
to the right. created associations, click the View
radio button.
Default: Null
View This button allows the application rules Radio Button Yes View Radio Button (see description
for the selected application to be viewed above)
New This button allows a new application Radio Button Yes New Radio Button (see description
rule to be created above)
Device Name Name of device to be associated with Info Only No Listing device name
an application
IP Address Name of IP address to be associated Info Only No IP Address of device to be forwarded
with an application
Application Forwarded Name of application being forwarded to Info Only No Application name being forwarded
device or IP address
Remove Eliminate the application forwarding Action Button Yes Click Remove to discard application
association forwarding rule
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
96
Upon clicking the New radio button described above, the Create New application Rule screen is displayed:
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
97
Protocol Protocol used for application Info Only No unless in edit Info Only
forwarding mode
Port Start The number of the application’s Info Only No unless in edit Info Only
specified start port mode
Port End The number of the application’s Info Only No unless in edit Info Only
specified end port mode
Port Map The number of the application’s Info Only No unless in edit Info Only
specified port map mode
Edit Edit the application rule Radio Button Yes Click radio button to edit
the rule
Remove Eliminate the application rule Radio Button Yes Click radio button to
remove rule
Associate Associate an application with a Info Only N/A N/A
Application device or IP address
With
Device Select "Device" button to reveal a "Device" button for selecting Selectable button "Device" button and
pull down list of defined devices for category and pull down list for and selectable pull alphanumeric selectable
association with an application selecting device down list pull down list
Default: "Device" button
Default:
Wireless_Router
IP Address Select "IP Address" to reveal a "IP Address" button for Selectable button "IP Address" button and
field to enter an IP address for selecting category and numeric and editable a dot delimited numeric
association with an application field for entering IP address numeric field entry field
Default: 0.0.0.0
Apply "Apply" radio button applies and Radio Button Yes Apply and Save the
saves the "Create New Application Rule
Association" settings
Cancel "Cancel" radio button cancels the Radio Button Yes Cancel changes to the
"Create New Association" settings Application Rule
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
98
Port Forwarding
Port forwarding allows a remote device to connect to a local LAN device through a specific
port or port range. Subscribers can forward traffic from the WAN source to a local LAN
device based on a port or range of port addresses.
New Create a new association between a Radio Yes Click to create a new port association
remote device and a local LAN device Button
through a specified port or port range
Local LAN Ports Number or range of numbers for the local Info Only No N/A
LAN port
Local LAN IP Address IP address of the local device Info Only No N/A
Protocol Protocol used to connect between local Info Only No N/A
and remote devices
Remote Ports Number or range of numbers for remote Info Only No N/A
port
Remote IP Address Remote IP address or all IP addresses Info only No N/A
associated with the remote port
Remove Remove the port forwarding association Radio Yes Click Remove to discard the association
Button
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
99
Clear Fields Clears the Local Port and IP fields to Action Button Yes Click to clear previously entered data
allow a new association to be created
Device Select the local LAN device to be "Device" Yes Radio button with drop-down list of
connected to the remote device. button with a currently connected local devices.
drop-down Default: Device is selected but drop-
list of devices down list is blank until devices are
added.
IP Address Select "IP Address" to display a field to Radio Button Yes Click to enter IP Address (dot delimited
enter an IP address for association with with numeric xx.xx.xx.xx)
the local device IP Address Default: Not selected
field
Protocol Protocol used to connect between local Drop-down Yes TCP, UDP, TCP/UDP
and remote devices list Default: TCP
Port Start Enter the number of the local port Numeric Yes 1-65535
association’s specified start port Default: Null
Port End Enter the number of the local port Numeric Yes 1-65535
association’s specified end port Default: Null
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
100
Clear Fields Clears the Remote Port and IP fields to Action Button Yes Click to clear previously entered data
allow a new association to be created
All IP Addresses Select "All IP Addresses" to associate all Radio Button Yes Choose between associating all IP
remote IP addresses with a specified port addresses or a specific IP address for
or range of ports creating a port forwarding rule
(association)
Default: Selected
IP Address Select "IP Address" to display a field to Radio Button Yes Click radio button to enter an IP
enter an IP address for association with with numeric address (dot delimited xx.xx.xx.xx)
the local device IP Address Default: Not Selected
field
Port Start Enter the number of the remote port Numeric Yes 1-65535
association’s specified start port Default: Null
Port End Enter the number of the remote port Numeric Yes 1-65535
association’s specified end port Default: Null
Apply/Cancel "Apply" radio button applies and saves Action Yes Click Apply to apply and save
the "Create New Association" settings or Buttons changes. Click Cancel to remove port
"Cancel" radio button cancels the "Create association.
New Association" settings
Firewall
Activating the firewall is optional. When the firewall is activated, security is enhanced, but
some network functionality will be lost.
Note: For additional information on system security settings, refer to the topic entitled System
Security (on page Error! Bookmark not defined.) presented earlier in this guide.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
101
Security Level
Security Off No filtering of incoming or outgoing traffic Radio Button Yes Turn security off
Default: Selected (Security Off)
Low Security Block pre-defined traffic in per the Radio Button Yes Apply Low Security Settings
"Blocked Services" settings. No blocking Default: Not Selected
of outgoing traffic
Medium Security Block pre-defined traffic in per the Radio Button Yes Apply Medium Security Settings
"Blocked Services" settings. No blocking Default: Not Selected
of outgoing traffic
High Security Block pre-defined traffic in per the Radio Button Yes Apply High Security Settings
"Blocked Services" settings. Block pre- Default: Not Selected
defined traffic out per the "Blocked
Services" settings including DNS
Stealth Mode
Stealth Mode With "Stealth Mode" enabled, the Radio Button Yes Enable or Disable Stealth Mode
GigaCenter device will not respond to all Default: Disabled
unsolicited WAN traffic including pings
Apply "Apply" radio button applies and saves Action Button Yes Click Apply to apply and save
the "Firewall" settings security settings.
If the security level above is set to Low, Medium, or High, the following table is displayed.
Note: Depending on the security level chosen, blocked services will change as it pertains to
traffic in, traffic out, and ports affected.
Note: Blocked Services are disabled and are not displayed when the firewall security level is
set to off.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
102
DMZ Hosting
DMZ hosting enables a LAN device to use the device WAN IP address as its own. DMZ
places the LAN device outside the firewall.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
103
DMZ State Enable or Disable DMZ hosting Radio Button Yes Select Enable or Disable
Default: Disabled
Device (If DMZ = Select the LAN device to be hosted Radio Button Yes Device Default: Not Selected
Enabled) outside the firewall with Drop-down Drop-down list is alpha-numeric
list of Device
names Default: Null field
IP Addressed (If DMZ Select an IP address of a device to be Radio button Yes Default: IP Address radio button is
= Enabled) hosted outside the firewall with numeric selected
field for IP IP address numeric field (dot
address
delimited xx.xx.xx.xx)
Default: Null field
Apply Apply button applies and saves the Action Button Yes Apply to apply and save changes
DMZ Host settings
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
104
UPnP
Universal Plug n Play is a network protocol whose general purpose is to enable zero-
configuration, automatic discovery, and simple configuration of network services on a LAN.
It was developed in 1998 by a consortium led by Microsoft. It allows devices to join a
network, obtain an IP address, announce itself and its services, and learn about the presence
and availability of other UPnP devices and services. UPnP devices are divided into 2
categories: Control Points (CP’s) and Controlled Devices (CD’s).
The most common use cases at present time are for printer discovery and installation, media
server/player discovery and control, and Internet router control. UPnP can allow PC’s to
discover and automatically identify and install drivers for network accessible printers. It
allows network media players such as DLNA clients to automatically locate DLNA servers
on the LAN. Internet routers can be discovered and various elements of control can be
exerted upon them. Each of these functionalities is governed by a particular schema that fits
within the UPnP protocol and those schemas are defined by individual UPnP Working
Groups.
Universal Plug and Play (UPnP) can be Radio Yes Enabled ‡ or Disabled
UPnP state enabled or disabled by selecting the Button
appropriate buttons
When "Enabled" the UPnP Network Radio Yes Enabled ‡ or Disabled
Address Translator (NAT-T) masks the IP Button
UPnP NAT-T state
addresses of devices on the LAN behind
the Home Gateway
Applies and saves the UPnP settings Action Yes Apply and save changes
Apply
Button
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
105
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
106
Note: Features listed below can be customized under the Advanced > Remote Management
tab of the EWI.
Remote EWI - Provides added security when accessing the GigaCenter EWI from a remote
location.
Remote EWI
Remote EWI enables access into the router from a WAN connection. To access your device
remotely you will need to use http:// followed by the device IP address and the remote EWI
port. For example: http://10.10.200.157:8080
Remote EWI state When "Enabled" the feature provides Radio Button Yes Select Enable or Disable
remote EWI access to the router from a Default: Disabled
WAN connection
Credentials
Username User name used to remotely access the Alpha-numeric Yes Alphanumeric string
Home Gateway's EWI text Default: Null field
Password Password used to remotely access the Alpha-numeric Yes Alpha-numeric string
EWI text Default: Null field
Show Selecting this option displays the Checkbox Yes Check box
password (not masked) Default: Not checked
Remote EWI port Port on the Home Gateway for remote Numeric Yes Numeric string
EWI access Default: 8080
Apply Applies and saves the Remote EWI Action Button Yes Click to apply and save changes
security settings
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Appendix A
Appendix
For data services, WPS is enabled upon pressing the WPS a single time. The WPS LED
begins to flash (green) and continues to do so for up to 180 seconds. During this time, other
Wi-Fi capable devices can be paired to the GigaCenters Wi-Fi radios (either the 2.4 GHz or
the 5.0 GHz band) by initializing a similar WPS function on the remote device, thereby
creating an association with the primary SSID of the GigaCenter and the other device. WPS
LED behavior for pairing to the primary SSID (either 2.4 GHz or 5.0 GHz) is as follows:
Press WPS button a single time.
WPS LED illuminates green and flashes for up to 120 seconds.
Wi-Fi 5.0 GHz LED begins flashing after approximately 10 seconds indicating the
pairing process has begun.
If another device is found, the GigaCenter pairs with the device, the Wi-Fi 5.0 GHz LED
remains on continuously, and the WPS LED goes out.
If no device is found, the WPS LED turns red after the initial 120 second time-out and
remains red for another 120 seconds.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
108
For IPTV services, WPS is enabled upon pressing the WPS three times in approximately 1
second intervals. After a short delay, the WPS LED begins to flash (amber) and continues to
do so for up to 180 seconds. During this time, other Wi-Fi capable devices can be paired to
the GigaCenters 5 GHz Wi-Fi radio by initializing a similar WPS function on the remote
device, thereby creating an association with the reserved IPTV SSID (5GHz_IPTV_SSID) of
the GigaCenter and the other device. WPS LED behavior for pairing to the IPTV SSID (5.0
GHz) is as follows:
Press WPS button exactly three times, at one second intervals. WPS LED turns green
and begins flashing after the 3rd press.
WPS LED illuminates amber after approximately 10 seconds and flashes for up to 120
seconds. The GigaCenter has entered IPTV SSID pairing mode.
If another device is found, the GigaCenter pairs with the device and the WPS LED turns
green and remains on for approximately 120 seconds.
If no device is found, the LED turns red after the 120 second time-out and remains red
for 120 seconds.
A properly installed and functional GigaCenter exhibits the following LED behavior:
When power is initially applied, the power LED behaves differently based on the
state/status of the UPS:
If no UPS is present or if a UPS is present and is not currently providing primary
power, the power LED illuminates and remains lit.
If a UPS is present and a battery alarm condition exists, the power LED blinks to
indicate an alarm status.
If LED does not light, power is off or the UPS power supply is not functional.
During initial power-up, all remaining LED's come on momentarily (lamp test).
If the SC-APC pigtail is not connected, the Phone 1 LED will begin to blink when Voice
Smart Activate is activated.
If the SC-APC pigtail is connected, the Broadband LED begins flashing once
downstream synchronization has been completed. The LED switches to solid green if
the GigaCenter has been provisioned.
As Ethernet ports are initialized, the corresponding LED illuminates provided an
Ethernet device is connected to the port.
Note: Phone service is not available until the Broadband LED lights and remains on.
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
109
Note: The integrated WPS feature allows for the sync'ing of remote WIFI capable products
with the GigaCenter. When in WPS mode (pressing the WPS button), the WIFI LED blinks
rapidly for 120 seconds, indicating the remote device is attempting to pair with the
GigaCenter.
Note: By default, the Wi-Fi radio is disabled upon start-up. Once initialized (via graphical
user interface), the Wi-Fi LED assumes normal functionality).
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
110
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
111
Acronyms
Acronyms
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
112
Acronyms
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
113
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.