DrayTek
AP-900 Dual-Band Managed Wireless Access Point
  • Business-class wireless access point
  • Simultaneous dual-band (2.4/5Ghz) - New
  • 802.11a, 802.11b, 802.11g, 802.11n - New
  • Gigabit Ethernet Switch (4+1 Ports) - New
  • Centrally managed or standalone operation  - New
  • Central Management supports mobility, load-balancing, monitoring, status, upgrade and configuration - New
  • Local temperature monitoring/logging - New
    (Optional thermometer accessory required)
  • PoE (Power-over-Ethernet) as standard
  • Detatchable Antennae - Can be replaced
    with optional uni-directional or higher-gain
  • WPA2 Wireless Encryption 
  • Repeater/Bridge/Access Point
  • Time-Scheduled Operation (multiple schedules) - New
  • Wireless Client Isolation
  • Bandwidth management per SSID
  • 802.1q VLAN Tagging
  • Four SSIDs for each band (for VLANs)
  • MAC Address Filtering
  • Radius / WPA User Authentication
  • 802.1x User Authentication
  • WDS (Wireless Distribution System)
  • WMM (Wireless MultiMedia)
  • WPS - WiFi Protected Setup
  • LEDs can be disabled or scheduled off - New
  • Built-in Site Surveyor
  • Wall Mountable
 

Vigor AP-900 Managed Dual-Band Wireless Access Point

 

The DrayTek Vigor AP-900 is a wireless access point which can be operated in standalone or centrally managed/monitored mode (by use of a central DrayTek management product - feature due later in 2014 as a free firmware upgrade).  The AP-900 is a high specification professional access point providing reliable and flexible coverage to all manner of applications.  A vast array of security and management features helps the AP-900 to improve and protect flexibility and integrity of your wireless LAN.  The Vigor AP-900 is ideal for adding wireless connectivity to an existing LAN, or for expanding the range of an existing wireless LAN by using the WDS repeater features.

 

Simultaneous Dual-Band Operation

The Vigor AP-900 supports simultaneous operation of the common 2.4Ghz band and the new 5Ghz band. The 5Ghz band is far less congested so if your PCs or other devices support the 5Ghz band, you can use that. The Vigor AP-900 operates both bands at the same time, so your devices can use either band and each has its own bandwidth so overall wireless capacity is also increased. If you want to add 5Ghz band support to your PC/laptop (assuming it doesn't already support it), you can use the DrayTek N65 USB adaptor.

 

Gigabit Ethernet Ports

The AP-900 has five wired Ethernet ports (separated into two distinct separated LANs). LAN A and LAN B can be fed separately and in turn broadcast on independent and isolated SSIDs.  As the ports are all Gigabit, you can be sure that the AP-900 is fed at the maximum speed in order to fully satisfy the full speed of both 2/4 and 5Ghz bands simultaneously.  The four ports on LAN A are particularly of use if you are using the AP-900 as a wireless bridge as you can then connect wired PCs or devices to it.  LAN Port 1 on LAN-A is also used as the PoE input if you're powering the AP-900 by PoE.

Vigor AP-900 Ports View

 

Central Management


The AP-900 can operate in standalone autonomous mode, but can also form part of a centrally managed wireless installation by adding a compatible DrayTek wireless controller (a Vigor2860 or 2925). This enables you to centrally control, manage and administer multiple AP-900 devices installed around your building/campus.  Management also enables efficient usage of your wireless access point through load-balancing, whereby wireless clients are distributed across several access points to reduce congestion.

For further details of the central management feature, click here.

 

Wireless Security & VLANs

The AP-900 features multiple levels of wireless security. Encryption using WEP, WPA, WPA2 (802.11i) is available you can also use the access control list (ACL) to specify the hardware addresses of clients which are permitted to connect (by MAC hardware address). Any unauthorised hardware is refused access.

For additional user authentication, you can activate 802.1x RADIUS (Remote Authentication Dial-in User Service) which allows you to centrally manage and store user names and passwords either within the AP-900 setup itself (thus not needing any external server) on an external radius server which can permit time limited, temporary or continuous access to your clients as required.

The Vigor AP-900 supports the 802.1q VLAN protocol so that if it is connected to an 802.1q enabled LAN, it can split tagged data (whether its different subnets or intended for different users) and broadcast each on its own SSID. This means, for example, that your guest WiFi access is provided on a separate isolated SSID with no access to your company data.

Local Temperature Logging and Alarm

Local Temperature Logging and AlarmAs your AP-900 unit(s) will be distributed around your building, it's an ideal opportunity to also gather environmental information about those locations.  By the addtition of an optional USB temperature sensor, your AP-900 can report real-time local temperature information, show the previous 24 hour's chart and also set high/low alarms to alert/log if the temperature falls above or below your set levels.   This facility is ideal for detecting if any part of your building is over or under-heated or if heating/cooling has been left on overnight and therefore helping to make more efficient use of your heating or cooling energy consumption, potentially saving cost.

USB Printer Port

The AP-900 has a USB interface into which you can connect a regular printer. That printer is then accessible from any wireless or wired PC which connects to the AP-900, or a PC anywhere else on the network. This is ideal to provide printer access to wireless laptops but could also be used for installing a printer elsewhere in your home/office by using a pair of AP-900s to make a bridge.  

WMM - WiFi Multimedia

The AP-900 implements intelligent wireless traffic prioritization for the most efficient management of wireless traffic by using the Wi-Fi Multimedia standard (WMM). WMM defines Quality of Service (QoS) in Wi-Fi networks. It is a precursor to the upcoming IEEE 802.11e WLAN QoS standard, intended to improve timing critical applications such as audio, video and voice applications over WiFi. WMM adds prioritized capabilities to Wi-Fi networks and optimizes their performance when multiple concurrent applications, each with different latency and throughput requirements, compete for network resources.

WPS - WiFi Protected Setup

Wireless LAN Enable & WDS

Wireless Security (encryption) is important to protect your data (privacy) but also to prevent unauthorised people from accessing your network or your Internet connection. The WPS system means that instead of having to create and enter long encryption keys, you can activate WPS registration. To activate, you press and hold the WPS button, then activate the WPS function on your PC; the two devices then automatically exchange encryption keys.

The same button on the AP-900 also serves as a physical on/off switch for the Wireless LAN if you wish to quickly disable it at any time, whilst still leaving your wired ports active.

Dual-LAN

The AP-900 can support two completely independent LANs. Each is connected via its own independent RJ45 Ethernet interface. There are Ethernet RJ45 interfaces for LAN A (4 ports) and LAN B (one port). These networks remain completely isolated from each other. Each LAN can be assigned its own separate Wireless SSID so they remain separated even on the Wireless LAN. This is the equivalent of having two completely separate access points and ideal for public and private networks in the same location or wireless LANs for two separate companies.

Having two physical LAN interfaces provides a much simpler alternative to using tagged VLANs and/or a Radius server for authentication. It is also much easier/quicker to set up (that said, the AP-900 can also support tagged VLANs and Radius).

Power-over-Ethernet

The AP-900 supports PoE (802.3af Power over Ethernet) as standard (built-in) so if the AP-900 is connected to a PoE-enabled Ethernet switch or PoE injector, you don't need any local power to the unit (power supply) - the AP900 will take its power from the Ethernet cable.  The AP-900 supports Gigabit PoE (if you have a Gigabit PoE switch/injector) such as our VigorSwitch P2261 or P-1090 models (or any other 802.3af device). PoE is ideal for situations where you do not have mains power available in the exact location where you want to install the AP-800 or just for general aesthetic neatness, perhaps where the AP-900 is installed somewhere prominent. 

AP900 POE

The AP-900 is also supplied with an AC/DC mains PSU for installations where you are not using PoE.

WDS & Repeater Modes

The DrayTek AP-900 can act as a standalone wireless access point, ideal for adding wireless connectivity to an existing LAN but also operates in several other wireless modes to provide enlarged wireless coverage or wireless bridges to other parts of your LAN. Many different configurations are possible:

Bridge Mode

This mode joins two parts of the same logical network which cannot be otherwise connected by cables, for example between two adjacent buildings. As the AP-900 has a built-in 4-Port switch, you can then connect up to 4 wired devices/PCs directly to it:

AP900 WDS Bridge 1


Universal Repeater Mode

As a repeater, the AP-900 can extend the wireless coverage of a network. You can add multiple units to extend the range in multiple directions or multiple hops (for best performance, more than two is not recommended due to latency and channel congestion which can result).

AP900 WDS Repeater 1

In the diagram below, there are two AP-900's to extend the range in different directions:

AP900 WDS Repeater 2


Station Mode *

In 'Station Mode' a remote station (computer or other device) can connect to the AP-900 using a regular ethernet cable, but the AP-800 connects to the remote LAN over wireless. The AP-900 has a built-in 4-port Ethernet switch so you can connect up to 4 client devices directly by wired Ethernet (100BaseT RJ45):

AP900 WDS Station 1

Station mode can also be used for games consoles or other Multimedia devices:

AP900 WDS Station 2

 

 

* Not currently available. Planned to be added in a future firmware update

Central Wireless Management

 

 

The AP-900 can operate in standalone mode; connected to your LAN and providing wireless access. If you have several AP-900 units, you can centrally manage and monitor them individually as a group.  

 

Central management makes security, efficiency, control and monitoring of your company-wide wireless access easier to manage.  Supported management features includes mobility, load-balancing and client monitoring/reporting.

 

For central management, you require a Vigor 2925 or Vigor 2860 series router; there is no per-node licencing or subscription required.

For further details on Wireless Management of the AP-900, click here.

 

 

 

 

 

 

 

AP-900 User Interface Screenshots

Screenshot 1

AP-900 Wireless Configuration

Screenshot 2

AP-900 - List of Connection Stations (clients) and diagnostics

Screenshot 3

Scanning & Discovery of other nearby Access Points

Screenshot 4

Access & Event Schedules - You can schedule wireless on/off, reboots or
turn off all of the unit's LED's (lights) at different times (e.g. night).

 

Screenshot 5

Limiting Bandwidth for connected clients

 

Screenshot 6

Built-in or external Radius Server for Client Authentication

 

Vigor2860 (Wireless management) Screenshots

The screenshots below show the web interface the Vigor2860 (or other DrayTek controller device) when centrally managing an estate of multiple Vigor AP-900 or other compatible units. Feature available later in 2014.

 

Screenshot 7

Vigor 2860 Rogue Access Point Detection

Screenshot 8

Vigor 2860 Firmware Upgrade Status of multiple AP-900

Image 9

Vigor 2860 managed upgrade of Vigor AP-900 units

Screenshot 10

Vigor 2860 AP-900 Management - Wireless Load Balance Policy


Note : The above screenshots are provided as a guide only. Exact operation and screen appearance will vary depending on firmware version and will change as features and functionality evolve. In some cases, the screenshots above may have been modified, resized, cropped or merged in order to best illustrate the features available.

Access Control / User Authentication

For additional security, wireless access can be restricted to authorised users only by use of a unique username and password for each user. This is in addition the encryption provided by WEP/WPA etc. When the user first opens their wireless connection, the AP-800 will request their username/password and not permit access to the LAN or Internet without it.

The AP-900 can use an external radius server to hold user credentials but also has its own built-in radius server to store up to 96 users. The AP-900's built-in Radius server can also act as a server to additional devices (such as another AP-900, meaning that you don't need to set up the same users up on several units).

 

Vigor AP-900 User Authentication / Radius

DrayTek Wireless Access Point Comparison
 Vigor AP-700 Wireless Access PointVigor AP-800 Wireless Access PointVigor AP-900 Wireless Access Point
 AP-700AP-810AP-900
Dual-LAN-YesYes
Wired LAN Ports1 x
10/100Mb/s
1+4 x
10/100Mb/s
1+4 x Gigabit
(1000Mb/s)
Wall Mountable-YesYes
Built-in PoE-YesYes
WLAN Disable Button-YesYes
WPS-YesYes
USB Printer Port-YesYes
802.1q VLAN-YesYes
Bandwidth Control-YesYes
Simultaneous Dual-Band
2.4Ghz & 5Ghz Concurrent
--Yes
Central Management features
Traffic Graph*-YesYes
AP Status*-YesYes
Station List*-YesYes
Auto-Provisioning*-YesYes
AP Maintenance*-YesYes
Load-Balancing*-YesYes
Rogue AP Detection*-YesYes
*Note: Central management requires a Vigor 2860 or Vigor 2925.

 

Vigor AP-900 Specification

 

  • Physical Interfaces/Controls:
    • LAN A : 4 x Gigabit Ethernet
      Port 1 accepts PoE Power
    • LAN B : 1 x Gigabit Ethernet
    • USB 2.0 Interface (for printer or thermometer)
    • Power On/Off Button
    • Wireless On / Off / WDS Button
      WDS Operation/button can be disabled
    • Factory Reset Button (recessed)
    • DC Power Socket
    • Two antennae (aerial) connectors - RSMA-Female type
    • Two Antennae (Removable, 2dB, both TX/RX dual-band)
  • Wireless LAN Compatibility:
    • IEEE 802.11a / b / g / n
    • Frequency Band 2.4 GHz & 5.8Ghz - Simultaneous Operation
    • 300Mb/s Total wireless bandwidth per band
  • Security Features:
    • Wireless Encryption : WPA2 (802.11i) Encryption
      Also supports WPA/WEP (Not recommended)
    • User Authentication : 802.1x (uses built-in or external Radius Server) (MD5/PEAP Modes)
    • Wireless Client Isolation
    • Hidden SSIDs (Selectable)
    • WPS - WiFi Protected Setup
    • MAC Address Filtering (ACL)
  • Operational Modes (2.4Ghz band)
    • 802.11b, 802.11g, 802.11n
    • Access Point
    • Station Infrastructure
    • AP Bridge Point-to-Point
    • AP Bridge Point-to-Multipoint
    • AP Bridge WDS
    • Universal Repeater
  • Operational Modes (5.8Ghz band)
    • 802.11a / 802.11n
    • Access Point
    • Universal Repeater
  • Wireless Control Features:
    • Wireless Client Status List in WUI
    • Up to four distinct SSIDs (for VLANs) for each frequency band (2.4/5Ghz)
    • WMM (Wireless MultiMedia)
    • MAC Cloning
    • Built-in DHCP server & client
    • 802.1q VLAN
    • VLAN Grouping & mapping for LAN A & LAN B
  • Management:
    • Web Interface (HTTP/HTTPS*)
    • TR-069 Control (For Vigor-ACS-SI or other TR-069 platform)
    • CLI (Command Line Interface) - Telnet
    • Firmware upgrade by TR-069/HTTP
    • SNMP V2 / 2c / 3*
    • Central AP Management (from compatible DrayTek router/controller)
    • Management VLAN for LAN A & LAN B
  • Power, environmental & Physical:
    • Temperature Operation : 0° C to 40° C
    • Humidity Requirements: 10% to 90 % (Non-condensing)
    • Physical Dimensions: mm
    • Weight : 0.kg (main unit, including Aerials)
    • Wall Mountable
    • Pack Contents : AP-900 main unit, two aerials, PSU (220-240VAC), quick start guide, manual on CD-Rom
    • Power : 12VDC via AC/DC PSU (supplied) or 802.3af PoE
    • Warranty : 2 Years RTB

*Planned for later firmware upgrade