This article describes how you can install the Engage Controller application (see Step 4), access the controller for the first time, set up your default site, and onboard devices (see Step 5). After you do so, you can also onboard additional devices (see optional Step 6).
However, we highly recommend that you first follow the optional Steps 1, 2, and 3, which allow you to enhance your understanding about the settings that you must define when you install and onboard the controller.
Before you start the Engage Controller onboarding process, consider the following:
- What is the default site name and site password that you want to use?
The site that you set up during the controller onboarding process is referred to as the default site. Later, you can add more sites and change the default site. - For each site, how can the computer on which the controller is installed reach the devices?
Does the computer receive an IP address from a DHCP server in your network or does the computer require a static IP address? - The controller can function as a DHCP server for the devices in the network.
Is a DHCP server present in the network or does the controller need to function as a DHCP server? - What is the local device password for each device that you want to add to the default site?
This information is required for each device so that the controller can onboard and manage the device. - If you plan to let the controller manage one or more access points, are these devices in factory default state, which is a requirement for onboarding?
- Do you want to set up a global WiFi network (SSID) for a site?
If so, what must be the WiFi network name and WiFi password (passphrase) and to which VLAN must the WiFi network be assigned? - Which network profiles do you need for the default site?
- The controller and NETGEAR Insight are mutually exclusive.
You cannot let the controller onboard a device that is managed by Insight, and the other way around. If you want to let the controller onboard a device that is managed by Insight, remove the device from the Insight network location, and then remove the device from Insight. After you do so, we recommend that you reset the device to factory default settings (this a requirement for an access point).
How the Engage Controller performs device discovery depends on your network configuration. The controller and each device must have a unique IP address in the network. A unique IP address can be a static IP address or an IP address that is dynamically assigned by a DHCP server in the network.
Note: The controller IP address must be in the same subnet as the devices that the controller must be able to discover.
If a DHCP server is not present in the network, the controller itself can function as a DHCP server, if it can reach the devices on the network. The devices can be in factory default state or already operating in the network, except for access points, which must be in factory default state.
- DHCP server in the network:
- The network can include a dedicated DHCP server (such as a router) that assigns IP addresses to the controller and the devices that the controller is supposed to control.
- One of the devices can function as a DHCP server that assigns IP addresses to the controller and the other switches.
- Static IP addresses: If devices are configured with static IP addresses in a subnet, you can configure the controller with a static IP address in the same subnet.
- No DHCP server in the network: The controller itself can function as a DHCP server and assign IP addresses to the devices in the network. If the controller does not receive an IP address from a DHCP server, it uses its default IP address of 192.168.0.100, and can assign IP addresses in that range to the devices in the network.
The following table provides an overview of the IP address options for switch discovery.
| Network IP Address Assignment |
Controller IP Address |
Device IP Address |
Result or Action |
|---|---|---|---|
| Network DHCP server | Dynamic | DHCP pool | The controller and devices receive a dynamic IP address from the network DHCP server. |
| Static IP addresses | Static | Static | Configure the controller IP address in the same subnet as the devices. |
| The controller is the DHCP server | Default (192.168.0.100) |
DHCP pool: 192.168.0.101 - 192.168.0.254 |
The devices receive a dynamic IP address from the controller. |
Note: The device IP addresses in a single network can also consist of a mixture of DHCP-assigned IP addresses and static IP addresses, but they must be in the same subnet, and the IP address of the controller must also be in the same subnet.
When you access the Engage Controller for the first time to set up a site, you must specify the following settings:
- Admin Password: The password an administrator uses for future access to the controller.
- Default site: A name, description, and password for the default site. (The site that you set up during the controller onboarding process is referred to as the default site.)
- Network interface: The interface that lets the controller connect to the default site.
- (Optional) WiFi network: The global WiFi network (SSID) for the default site. By default, the WiFi security for the global is SSID is WPA2-MPSK (Multi PSK, in short, MPSK), which lets you segregate a single WiFi network into different VLANs, each accessible with a unique passphrase. You cannot change the WiFi security for the global SSID, but you can expand the MPSK configuration. (For more information about MPSK, see the "Set up a WiFi network with Multi PSK" section in the Engage Controller user manual.)
After you have set up the global site SSID, you can add additional SSIDs, but you cannot make another SSID the global site SSID. By default, the global SSID broadcasts on the 2.4 GHz and 5 GHz radio bands and is assigned to VLAN 1. You can change the 2.4 GHz and 5 GHz radio bands, change the VLAN ID, and disable the WLAN status for the global site SSID entirely. - Devices: The devices that the controller discovers at the default site and that you can manage by letting the controller onboard the devices.
- Network profiles: The network profiles that are available for the default site. (The network profiles are pulled from the onboarded fully managed switches, but you can also add a network profile.)
Note: For each device that you want to onboard, you must know the local device password. After the controller onboards the device, the controller replaces the local device password with the default site password. Access points must be in factory default state, which means that they are using the device default password.
Caution: The firmware that devices are running before being onboarded by the controller does not support the controller functions. When you let the controller onboard a device, the controller pushes the latest firmware with controller functions to the device. This process might take up to 10 minutes. This firmware update is necessary because the controller cannot manage the device without the firmware update.
You can install the Engage Controller on your Windows-based computer or launch the app directly from a USB thumb drive, and save all configuration data to the same USB thumb drive.
If you are using a Mac, see the "Download and install the controller software application on a Mac" section in the Engage Controller user manual.
To download and install the controller software application on a Windows-based computer:
- Visit netgear.com/support/product/engage-controller.
The NETGEAR Engage Controller Support page displays. - Download the zipped installation file to a location on your computer.
An example of the name of the installation file is Netgear-Engage-x.x.x.x.exe. - Note: Before you proceed, you might need to temporarily disable your firewall and anti-virus program, or both. Or you might need to set up an exception in your firewall so that the installer program is not blocked by your firewall. Make sure the application has read, write, and modify permissions at the installation location.
- Go to the location where you downloaded the zipped installation file and extract the files to a destination folder.
- In the destination folder, double-click the .exe file (the application file name includes Netgear-Engage) and follow the prompts of the installer program to install the controller software.
The default installation location is C:\Users\your-username\Netgear. However, you can select another location.
After installation, the executable file that opens the controller is Engage.exe, and an executable icon is placed on your desktop.
Step 5: Access the Engage Controller for the first time, set up your default site, and onboard devices
- On your computer, in the folder in which you installed the Engage Controller application, click the Engage.exe application icon, or if you created a shortcut, click the Engage shortcut.
The initial login page displays. The first time that you log in, no password is required. However, you then must specify a controller password to use each subsequent time that you log in. - In the Login Name field, enter admin, and click the Login button.
The Engage Password page displays. - In the New Password field, set an admin password, repeat the password in the Confirm Password field, and click the Next button.
The password must be 8 to 64 characters in length and must contain at least one uppercase letter, one lowercase letter, and one number. The following special characters are allowed: ! @ # $ % ^ & * ( ). To make the password visible, click the eye icon. - Click the Next button.
The Site Setup page display. - Keep the Default Site Configuration radio button selected (it is selected by default) and set the following information for the default site:
- Site Name: A name for identification purposes.
- Site Description: A description for identification purposes.
- New Site Admin Password: The password must be 8 to 64 characters in length and must contain at least one uppercase letter, one lowercase letter, and one number. The following special characters are allowed:
! @ # $ % ^ & * ( ).
To make the password visible, click the eye icon.
The controller pushes this password to each device that it onboards and replaces the device local device password with the site password. - Confirm Site Admin Password: Repeat the password.
- Click the Next button.
The Network Setup page display. - Specify how the computer on which the controller is installed can connect to the AV network at the site by selecting a radio button:
- Dynamic IP Address: From the Engage Network Interface menu, select the computer’s network interface so that it can receive a dynamic IP address from a DHCP server (or router that functions as a DHCP server) in the network.
- Static IP Address: The computer requires a static IP address to connect to the site. Do the following:
- Assign a static IP address to the computer on which you installed the controller. The Network Setup page shows how to assign a static IP address to the computer. You can display these steps for a Windows-based computer and a Mac.
- From the Engage Network Interface menu, select the static IP address.
- Static IP Address + DHCP Server: The computer uses a static IP address and lets the controller function as a DHCP server. Do the following:
- Assign a static IP address to the computer on which you installed the controller and configure the computer as a DHCP server. The Network Setup page shows both how to assign a static IP address to the computer and how to let the computer function as a DHCP server. You can display these steps for a Windows-based computer and a Mac.
- From the Engage Network Interface menu, select the static IP address.
- In the Start Client IP Address field, enter the start IP address for the DHCP server address range.
- In the End Client IP Address field, enter the end IP address for the DHCP server address range.
Note: We recommend that you restart all NETGEAR devices at the site for fastest IP address assignment by the controller’s DHCP server.
- Click the Next button.
The Wireless Setup page displays. - Either click the Skip >> link to skip this step, or if your network includes access points, set up the global WiFi network (SSID) for the default site:
- In the SSID Name field, enter the name for the WiFi network (SSID).
- In the Passphrase field, enter the password for access to the WiFi network, which uses WPA-MPSK security.
(For more information, see Optional Step 3: Consider the controller settings that you must define.) - From the Region menu, select the region for the country in which the default site is located.
After setup, you cannot change the region. - From the Country menu, select the country in which the default site is located.
After setup, you cannot change the country
- Click the Next button.
The Device Setup page displays. The Discovered Devices table displays the devices that the controller detects in the network.
You can onboard devices now, or later, after you have set up the controller. - To let the controller onboard a device so that it can take control of the device, click the Onboard button for the device.
The Add Device window displays for the device. Specify the following information:- Device Admin User: Enter admin as the user name for the device.
- Device Password: Enter the local device password for the device.
Note: You are granted five attempts to enter the correct password. After a fifth failed attempt, you are locked out of the device for five minutes. The controller also provides the option to enter the device default password or controller site password:- To enter the device default password: Turn on the Use device default password toggle so that it displays blue and is positioned to the right
For a new device or a device that was reset to factory default settings, the device default password is password.
Access points must be in factory default state, which means that they are using the device default password. - To enter the controller site password: Turn on the Use controller site password toggle so that it displays blue and is positioned to the right.
You defined the controller site password in Step 5.
- To enter the device default password: Turn on the Use device default password toggle so that it displays blue and is positioned to the right
- Click the Add button.
Your settings are saved. The device is moved to the Managed Devices table, and the onboarding process is now in progress.
Note: At the end of this procedure, the controller pushes the site password to the device (which replaces the local device password or default password). If any device does not yet support the controller, the controller pushes a firmware update with controller functions to the device, after which the device restarts. This process might take up to 10 minutes. The firmware update is necessary because the controller cannot manage the device without the firmware update. Only after these processes are complete does the device become a managed device and moves to the Online state.
Caution: During the onboarding process, do not restart the device or change any cables. Wait until the onboarding process is finished.
- Repeat the previous step for each device that you want to let the controller onboard.
- Click the Next button.
The Profile Setup page displays.
During the device onboarding process (see Step 11 and Step 12), the controller does the following:- Pulls all network profiles that are configured on the devices at the site.
- Pushes these profiles to all onboarded devices.
- Review the network profiles that are available for the site, and as an option, set up a new profile.
The page shows the following network profiles:- The Default network profile, which uses the Data profile template and VLAN 1.
- The network profiles that were pulled from onboarded devices, if any.
- Click the Create Network Profile link.
- Set up the network profile.
For more information, see the "Manage Network Profiles" chapter in the Engage Controller user manual and the information about network profiles in the "Configuration Example Guide for ProAV Installations." (The manual and guide are referenced in the "For more information" section below.)
- Click the Finish button.
Your settings are saved.
The devices are being onboarded. Because of the firmware update, this process might take up to 10 minutes, after which the page displays the Onboarding Finished message.
Caution: During the onboarding process, do not restart the devices or change any cables. Wait until the onboarding process is finished.
Note: If device settings are incompatible with the network settings, for example, onboarding might fail. If this situation occurs, you can onboard the device by adding it to the site through the Devices page. - Click the Go to Devices button.
The Devices page displays. The page shows the following tables:- Managed Devices: The table lists all onboarded devices that you can configure using the controller.
- Discovered Devices: The table lists all Engaged-manageable devices that the controller discovered in the network but that the controller did not onboard and that you therefore cannot yet configure using the controller.
- To save the settings to the running configuration, at the top right of the page, click the Save button.
Devices that the Engage Controller discovers are listed in the Discovered Devices table for a site. If a device does not display in the Discovered Devices table for a site, you can manually add the device as a managed device to the site by specifying the device IP address and access credentials. You can also add multiple devices of the same model if the devices are listed in the Discovered Devices table for a site and are in factory default state or all have the same password.
These are the requirements for adding multiple discovered devices to a site simultaneously:
- The devices must be of the same model, for example, the same model switch.
- The devices must have the same default password or custom password.
If the controller does not discover a device that is part of your network, you can manually add the device as a managed device to the site by specifying the device IP address and access credentials. For more information, see the "Add an undiscovered device to a site" section in the Engage Controller user manual.
Note: The following procedure uses the plural devices; If you are adding a single device, the procedure applies to the single device.
To onboard one or more devices:
Note: If you are already logged in to the controller, skip Steps 1, 2, and 3.
- On your computer, in the folder in which you installed the controller application, double-click the Engage application icon, or double-click the Engage shortcut.
The controller application opens and displays a login page. - In the Login Name field, enter admin as the user name, in the Password field, enter the controller password that you set up the first time that you logged in, and click the Login button.
The Managed Devices page displays. - If you set up more than one site, from the Site menu, select the site.
The Edit Network Setup pop-up window displays.
Do one of the following:- Make no changes to the network setup for the site: Click the Apply button.
- Change the network setup for the site: See the information in the "Edit the network setup of a site" section in the Engage Controller user manual. When you are done, click the Apply button.
- Click the Onboard button for a single device, even if you want to add multiple devices of the same model.
A warning pop-up window displays. - Click the Continue button.
The Add Device pop-up window displays. - To let the controller onboard the devices so that it can take control of the devices, specify one of the following options for password of the devices:
- Custom device password: If the devices use a custom device password, enter it.
- Default device password: To automatically enter the default device password, turn on the Use device default password toggle so that it displays blue or green and is positioned to the right. The devices must be in factory default state.
If you are adding one or more APs, select this option. An AP must be in factory default state. - Site password: To automatically enter the controller site password, turn on the Use controller site password toggle so that it displays blue or green and is positioned to the right.
- Do one of the following:
- You are adding a single device: Click the Single button.
- You are adding multiple devices: Click the Multiple button.
The devices are moved to the Managed Devices table, and the onboarding process is now in progress.
Note: At the end of this procedure, the controller pushes the site password to the devices (which replaces the local device password or default password). If the firmware version on the devices does not support the controller, the controller automatically updates the firmware, after which the devices restart. When these processes are complete, the devices become managed devices and move to the Online state. This process might take up to 10 minutes. - To save the settings to the running configuration, at the top right of the page, click the Save button.
For more information about configuration and management with the Engage Controller, see the following manual and guide, which you can download by visiting NETGEAR Download Center or by clicking on the following links: