Beijing InHand Networks Technology IP30 Industrial Communication Server User Manual

Beijing InHand Networks Technology Co., Ltd. Industrial Communication Server

User Manual

IP3012LIndustrialCommunicationServer
User’sManual

©2015InHandNetworks.Allrightsreserved.
Republicationwithoutpermissionisprohibited.

IP3012LUser’sManual
CopyrightNotice
Copyright©2015InHandNetworks
Allrightsreserved.
Reproductionwithoutpermissionisprohibited.
Trademarks
InHandisaregisteredtrademarkofInHandNetworks.Otherregisteredmarkscitedinthis
manualrepresentedtheirrespectivecompanies.
Disclaimer
Informationinthisdocumentissubjecttochangewithoutnoticeanddoesnotrepresentan
obligationonthepartofInHandNetworks.
Thisusermanualmayincludeintentionaltechnicalortypographicalerrors.Changesare
periodicallymadetothemanualtocorrectsucherrors,andthesechangesarenotinformedin
neweditions.
TechnicalSupportContactInformation
InHandNetworks
support@inhandnetworks.com
TableofContents
IP3012LUSER’SMANUAL..........................................................................................................2
1.IP3012LINTRODUCTION................................................................................................................6
1.1Overview.............................................................................................................................6
1.2Features...............................................................................................................................6
2.ESTABLISHNETWORKCONNECTION...................................................................................................9
2.1EstablishNetworkConnection............................................................................................9
2.1.1AutomaticacquisitionofIPaddress(recommended)..................................................9
2.1.2SetastaticIPaddress.................................................................................................12
2.2ConfirmthatthenetworkbetweenthesupervisoryPCandrouterisconnected............13
2.3CanceltheProxyServer....................................................................................................15
3.WEBCONFIGURATION..................................................................................................................17
3.1LogintheWebSettingPageofRouter..............................................................................17
3.2Management.....................................................................................................................18
3.2.1System........................................................................................................................18
3.2.1.1SystemStatus......................................................................................................18
3.2.1.2BasicSettings.......................................................................................................19
3.2.2SystemTime...............................................................................................................19
3.2.2.1SystemTime........................................................................................................20
3.2.2.2SNTPClientPort..................................................................................................20
3.2.3AdminAccess.............................................................................................................
22
3.2.3.1Createauser.......................................................................................................22
3.2.3.2ModifyaUser......................................................................................................23
3.2.3.3RemoveUsers......................................................................................................23
3.2.3.4ManagementService..........................................................................................24
3.2.4AAA.............................................................................................................................26
3.2.4.1Radius..................................................................................................................27
3.2.4.2Tacacs+................................................................................................................28
3.2.4.3LDAP....................................................................................................................29
3.2.4.4AAASettings........................................................................................................30
3.2.5ConfigurationManagement.......................................................................................32
3.2.6SNMP..........................................................................................................................33
3.2.6.1SNMP...................................................................................................................35
3.2.6.2SnmpTrap............................................................................................................37
3.2.7Alarm..........................................................................................................................37
3.2.7.1AlarmStatus........................................................................................................38
3.2.7.2AlarmInput.........................................................................................................39
3.2.7.3AlarmOutput......................................................................................................39
3.2.7.4AlarmMap...........................................................................................................41
3.2.8SystemLog.................................................................................................................41
3.2.8.1SystemLog..........................................................................................................41
3.2.8.2SystemLogSettings.............................................................................................42
3.2.8.3KiwiSyslogDaemon............................................................................................43
3.2.9SystemUpgrading.......................................................................................................43
3.2.10Reboot......................................................................................................................44
3.2.11CloudPlatform.........................................................................................................44
3.2.11.1CloudPlatform..................................................................................................44
3.2.11.2MOTTClient......................................................................................................45
3.2.12ScheduledTasks........................................................................................................46
3.3Network.............................................................................................................................47
3.3.1Cellular.......................................................................................................................47
3.3.1.1Status...................................................................................................................47
3.3.1.2Cellular................................................................................................................47
3.3.2WLANInterface2.4G...........................................................................................50
3.3.2.1Status...................................................................................................................50
3.3.2.2WLAN(2.4G).......................................................................................................51
3.3.2.3IPSetup...............................................................................................................53
3.3.2.4SSIDScan.............................................................................................................53
3.3.3WLANInterface5.8G...........................................................................................54
3.3.3.1Status...................................................................................................................54
3.3.3.2WLAN5.8G...................................................................................................54
3.3.3.3IPSetup...............................................................................................................57
3.3.3.4SSIDScan.............................................................................................................57
3.3.4CaptivePortal.............................................................................................................57
3.3.5DHCPservice..............................................................................................................59
3.3.5.1Status...................................................................................................................60
3.3.5.2DHCPServer........................................................................................................60
3.3.5.3DHCPRelay..........................................................................................................62
3.3.5.4DHCPClient.........................................................................................................63
3.3.6DNSServices...............................................................................................................63
3.3.6.1DNSServer..........................................................................................................64
3.3.6.2DNSRelay............................................................................................................64
3.3.7SMS............................................................................................................................65
3.3.8VLANInterface...........................................................................................................66
3.3.8.1VLANConfiguration.............................................................................................66
3.3.8.2VLANAggregation...............................................................................................67
3.3.9ADSLDialupPPPoE..............................................................................................68
3.3.10LoopbackInterface...................................................................................................69
3.3.11DynamicDomainName...........................................................................................70
3.3.12BridgeInterface........................................................................................................72
3.4LinkBackup.......................................................................................................................73
3.4.1SLA..............................................................................................................................73
3.4.2TrackModule..............................................................................................................74
3.4.3VRRP...........................................................................................................................76
3.4.4InterfaceBackup.........................................................................................................79
3.5Routing..............................................................................................................................80
3.5.1StaticRoute................................................................................................................80
3.5.1.1RoutingStatus.....................................................................................................81
3.5.1.2StaticRouting......................................................................................................81
3.5.2DynamicRouting........................................................................................................82
3.5.2.1RoutingStatus.....................................................................................................82
3.5.2.2RIP.......................................................................................................................83
3.5.2.3OSPF....................................................................................................................86
3.5.2.4FilteringRoute.....................................................................................................88
3.5.3MulticastRouting.......................................................................................................89
3.5.3.1BasicSettings.......................................................................................................89
3.5.3.2IGMP....................................................................................................................90
3.6Tools..................................................................................................................................
92
3.6.1PING...........................................................................................................................92
3.6.2RoutingDetection......................................................................................................92
3.6.3LinkSpeedTest ...........................................................................................................93
3.7InstallationGuide..............................................................................................................94
3.7.1NewDial.....................................................................................................................94
3.7.2NewIPSecTunnel.......................................................................................................95
3.8PersonalizationFeatures...................................................................................................96
3.8.1NginxServer...............................................................................................................96
3.8.2FileSynchronization...................................................................................................97
3.8.3GPSLocationInformation..........................................................................................98
3.8.4RoamingManagement...............................................................................................99
3.8.4.1RoamingManagement........................................................................................99
3.8.4.2UpgradefromAP.................................................................................................99
3.9Firewall............................................................................................................................100
3.9.1AccessControlACL............................................................................................100
3.9.2NAT...........................................................................................................................102
3.10QoS................................................................................................................................105
3.11VPN................................................................................................................................107
3.11.1IPSec.......................................................................................................................107
3.11.1.1IPSecPhase1...................................................................................................108
3.11.1.2IPSecPhase2...................................................................................................111
3.11.1.3IPSecConfiguration.........................................................................................112
3.11.1.4IPSecVPNConfigurationExample...................................................................114
3.11.2GRE.........................................................................................................................118
3.11.3L2TP........................................................................................................................120
3.11.4OPENVPN...............................................................................................................122
3.11.5CertificateManagement........................................................................................124
3.12ConfigurationWizard....................................................................................................126
4.APPLICATIONSCENARIOS.............................................................................................................128
APPENDIX1TROUBLESHOOTING..........................................................................................130
APPENDIX2INSTRUCTIONOFCOMMANDLINE....................................................................133
1.IP3012LIntroduction
ThisChapterincludes:
Overview
Features
1.1Overview
IP3012LisadedicatedvehicleWiFirouterwithembeddedNGINXwebserverandlocal
storageSSD.WithIP3012LandtheRainbowWiFicloud,motorcoachoperatorsmayeasilysetup
anadvancedWiFioperatingsystemwhichprovidesdevicemanagement,contentmanagement,
vehiclelocationmanagement,visitormanagement,statisticalreports,andotherfeatures.
TravelerssimplyconnecttotheWiFihotspotprovidedbyIP3012LtosurfInternet,andtoenjoy
localservicessuchasVODmoviesandinteractivegamesprovidedbyoperators.Bydeployingthe
RainbowWiFicloud,motorcoachoperatorsmayeasilyremotelymanagethousandsofIP3012L
devices,nomatterchangingvisitorpolicyorupdatingmediacontentdeployedinIP3012L.
TheIP3012Lisaportalintothemobileinternetandastepforwardinprovidingvalueadded
servicestotravelers.
1.2Features
AdvancedWiFi
Supportdualband2.4GHzand5.8GH,fullycompliancewithIEEE802.11ac/a/b/g/n
standards.
With2X2MIMOtechnologyenabled,WiFiconnectionbandwidthcanreachashighas
1.2Gbps,bringsamazingmultiuserperformance.
Highspeed4GAccess
Integratingupto4Gcellularmodule,IP3012providesFDDLTEaccess,with100Mbps
uplinkand50Mbpsdownlink.
QuadBandLTE:700/850/AWS(1700/2100)/1900MHz;FDDBand(17,5,4,2);TriBand
UMTS(WCDMA):850/AWS(1700/2100)/1900MHz;FDDBand(5,4,2)QuadBand
GSM/GPRS/EDGE:850/900/1800/1900MHz
GPS
WithGPSenabled,IP3012providesvehiclelocation,speed/courseovergroundand
trackinformation.
PowerfulWebPortal
WhenvisitorsconnecttotheWiFihotspotprovidedbyIP3012L,agreetingsplashpage
popsup,providinglocalmediaservicesanduserauthentication.
BuiltinWebServer
EmbedreliableNGINXwebserver,enablinglocalmediaservices.
SupportPHP,enablingdynamicpagecontent.
LocalStorage
SupportSSDupto1TB,toleratingvibrationfromvehicle.
Localstoragemaybeusedtostorelocalwebcontent,movies,music,apps,etc.to
acceleratelocalaccessandtosaveinternetbandwidth.
ContentUpdateMechanism
Inremotesynchronizationmode,locallystoredcontentsmaysyncwiththecloud.
Inlocalsynchronizationmode,contentmaybeupdatedviaSDcardorFTP.
Bothmodesmaybehybridtoenableevenmoreflexibleoperation.
VisitorBehaviorManagement
SupportvisitorauthenticationbySMSorsocialaccounts.
SupportQoStolimitperuserbandwidthandtraffic,preventingoveragesand
protectinglatencysensitivetraffic.
Supportwebsitesblacklistandwhitelist.
CloudManagement
SupporttheRainbowWiFicloud,enablingdevicemanagement,contentmanagement,
vehiclelocationmanagement,visitormanagement,statisticalreports,andother
features.
SupportCLI,webUIandSNMPv3.
HighReliability
Withdedicatedvehiclepowermoduleinside,IP3012Ltoleratespowervoltagedips,
overruns,shortandotherfailures.SupportautomaticallypowercontrolwithACC
signaltoprotectSSDandvehiclebattery.
Fanlesscoolingdesigntosimplifyinstallation.
SupportlinkqualityinspectionandautorecoverytoensurereliableLTEaccess.
RobustSecurity
SupportIPSecVPN,DMVPN,L2TP,SSLVPN,andCAcertificationtoensuredata
security.
SupportpowerfulfirewallfunctionssuchasStatefulPacketInspection(SPI),Access
ControlList(ACLs),DoSattackprevention,etc.
SupportAAA,TACACS,Radius,localauthentication,andmultilevelsuserauthorityto
ensuresecuremanagement.

2.EstablishNetworkConnection
Thischaptermainlycontainsthefollowingcontents:
EstablishNetworkConnection
ConfirmthattheconnectionbetweensupervisoryPCandrouter
CanceltheProxyServer
Aftercompletingthehardwareinstallation,beforetologintheWebsetuppage,youneedto
ensurethatthemanagementoftheEthernetcardinstalledonyourcomputer.
2.1EstablishNetworkConnection
2.1.1AutomaticacquisitionofIPaddress(recommended)
Pleasesetthesupervisorycomputerto"automaticacquisitionofIPaddress"and"automatic
acquisitionofDNSserveraddress"(defaultconfigurationofcomputersystem)tolettherouter
automaticallyassignIPaddressforsupervisorycomputer.
1)Open“ControlPanel”,doubleclick“NetworkandInterneticon,enter“NetworkandSharing
Centers”
2)Clickthebutton<LocalConnection>toenterthewindowof"LocalConnectionStatus”
3)Click<Properties>toenterthewindowof"LocalConnectionProperties”,asshownbelow.
4)Select“InternetPortocolVersion4(TCP/IPv4)”,click<Properties>toenter“InternetPortocol
Version4(TCP/IPv4)Properties”page.Select“ObtainanIPaddressautomatically”and“Obtain
DNSServeraddressautomatically,thenclick<OK>tofinishsetting,asshownbelow.
2.1.2SetastaticIPaddress
SetcomputermanagementIPaddressanddevieceFEportIPaddressonthesamenetwork
segment(deviceFEportinitialIPaddress:192.168.2.1,SubnetMask:255.255.255.0).The
followingFE1/1portconnectedtoacomputerandmanagementprovidedinWindowsXPsystem
describedasanexample.
Enter“InternetPortocol(TCP/IP)Properties”page,select“UsethefollowingIPaddress”,typeIP
address(arbitraryvaluebetween192.168.2.2192.168.2.254),SubnetMask(255.255.255.0),
andDefafultGateway(192.168.2.1),thenclick<OK>tofinishsetting,asshownFigure25.
Figure25InternetPortocol(TCP/IP)Properties
2.2ConfirmthatthenetworkbetweenthesupervisoryPCandrouterisconnected
1)Clickthelowerleftcornerofthescreen<Start>buttontoenterthe"Start"menu,select"Run"
popup"Run"dialogbox,showninFigure26.
Figure26Run
2)Enter"ping192.168.2.1(IPaddressofrouter;itisthedefaultIPaddress),andclickthebutton
<OK>.Ifthepopupdialogboxshowstheresponsereturnedfromtherouterside,itindicates
thatthenetworkisconnected;otherwise,checkthenetworkconnection,showninFigure27.
Figure27CommandPrompt
2.3CanceltheProxyServer
IfthecurrentsupervisorycomputerusesaproxyservertoaccesstheInternet,itisrequiredto
canceltheproxyserviceandtheoperatingstepsareasfollows:
1)Select[Tools/InternetOPtions]inthebrowsertoenterthewindowof[InternetOptions],
showninFigure28.
Figure28InternetOPtions
2Selectthetab”Connectandclickthebutton<LANSetting(L)>toenterthepageof“LAN
Setting.Pleaseconfirmiftheoption”UseaProxyServerforLANischecked;ifitis
checked,pleasecancelandclickthebutton<OK>,showninFigure29.
Figure29LANSetting

3.WebConfiguration
Thischapterincludesthefollowingparts:
Login/outWebConfigurationPage
Management
Network
LinkBackup
Routing
Tools
InstallationGuide
PersonalizationFeatures
Firewall
Qos
VPN
3.1LogintheWebSettingPageofRouter
RuntheWebbrowser,enter“http://192.168.2.1:8080”intheaddressbar,andpressEntertoskip
totheWebloginpage,asshowninFigure31.Enterthe“UserName”(default:adm)and
“Password”(default:123456),andclickbutton<OK>ordirectlypressEntertoentertheWeb
settingpage.
Figure31LoginRouter
AfterenteringtheWebSettingpage,clickthe"AdvancedConfiguration"webinterface,the
popupdialogbox,enter"UserName"(default:adm)againand"Password"(default:123456),
thenentertheparameterconfigurationinterfacestartparametersettings.Advanced
configurationisshownin3.2~3.11.
Atthesametime,therouterallowsuptofouruserstomanagethroughtheWebsetting
page.Whenmultiusermanagementisimplementedfortherouter,itissuggestednotto
conductconfigurationoperationfortherouteratthesametime;otherwiseitmayleadto
inconsistentdataconfiguration.
Forsecurity,youaresuggestedtomodifythedefaultloginpasswordafterthefirstlogin
andsafekeepthepasswordinformation.
3.2Management
3.2.1System
3.2.1.1SystemStatus
Fromtheleftnavigationpanel,selectAdministration/System,thenenter“SystemStatus”page.
Onthispageyoucanchecksystemstatusandnetworkstatus,asshowninFigure32.Insystem
status,byclicking<SyncTime>youcanmakethetimeofroutersynchronizedwiththesystem
timeofthehost.Clickthe“Set”onnetworkstatustoenterintotheconfigurationscreendirectly.
Forconfigurationmethods,refertoSection3.3.2.
Figure32SystemStatus
3.2.1.2BasicSettings
SelectAdministration/System,thenenter“BasicSetup”page.YoucansetthelanguageofWeb
ConfigurationPageanddefineRouterName,asshowninFigure33.
Figure33BasicSettings
3.2.2SystemTime
Toensurethecoordinationbetweenthisdeviceandotherdevices,userisrequiredtosetthe
systemtimeinanaccuratewaysincethisfunctionisusedtoconfigureandchecksystemtimeas
wellassystemtimezone.
ThedevicesupportsmanualsettingofsystemtimeandthetimetopassselfsynchronisticSNTP
server.
3.2.2.1SystemTime
Timesynchronizationofrouterwithconnectedhostcouldbesetupmanuallyinsystemtime
configurationpartwhilesystemtimeisallowedtobesetasanyexpectedvalueafterYear2000
manually.
Fromtheleftnavigationpanel,selectAdministration/SystemTime,thenenter“SystemTime
page,asshowninFigure34.
Byclicking<SyncTime>youcanmakethetimeofroutersynchronizedwiththesystemtimeofthe
host.SelecttheexpectedparametersinYear/Month/DateandHour:Min:SecColum,thenclick
<Apply&Save>.Therouterwillimmediatelysetthesystemtimeintoexpectedvalue.
Figure34SystemTime
3.2.2.2SNTPClientPort
SNTP,namelySimpleNetworkTimeProtocol,isasystemforsynchronizingtheclocksof
networkedcomputers.InmostplacesoftheInternettoday,SNTPprovidesaccuraciesof150ms
dependingonthecharacteristicsofthesynchronizationsourceandnetworkpaths.
ThepurposeofusingSNTPistoachievetimesynchronizationofalldevicesequippedwithaclock
onnetworksoastoprovidemultipleapplicationsbasedonuniformtime.
Fromtheleftnavigationpanel,selectAdministration/SystemTime,thenenter“SNTPClient
page,asshowninFigure35.
Figure35SNTPClientPort
PagedescriptionisshowninTable31.
Table31SNTPClientPortPageDescription
ParameterDescriptionDefault
SourceIPThecorrespondingIPofsourceinterfaceNone
SNTPServersList
ServerAddressSNTPserveraddress(domainname/IP),maximumto
set10SNTPserverNone
PortTheserviceportofSNTPserver123
BeforesettingaSNTPserver,shouldensureSNTPserverreachable.EspeciallywhentheIP
addressofSNTPserverisdomain,shouldensureDNSserverhasbeenconfigured
correctly.
Ifyouconfigureasourceinterfaceandthencannotconfigurethesourceaddress.the
oppositeisalsotrue.
WhensettingmultipleSNTPserver,systemwillpollallSNTPserversuntilfindanavailableSNTP
server.
3.2.3AdminAccess
AdminAccessallowsthemanagementofuserswhicharecategorizedintosuperuserand
commonuser.
Superuser:onlyoneautomaticallycreatedbythesystem,allocatedwiththeusername
ofadmandgrantedwithallaccessrightstotherouter.
Commonuser:createdbysuperuserwiththerighttocheckratherthenmodifyrouter
configuration.
3.2.3.1Createauser
Clicknavigationpanel/AdminAccess,enter“Createauserpage,Whereintheuserpermissions
value,thehighertheprivilege,showninFigure36.
Figure36Createauser
3.2.3.2ModifyaUser
Fromtheleftnavigationpanel,selectAdministration/AdminAccess,thenenter“ModifyaUser
page,asshowninFigure37.Presstheuserthatneedstomodifyin“UserSummary”,afterthe
backgroundturnsblue,enternewinformationin“ModifyaUser.
Figure37ModifyaUser
3.2.3.3RemoveUsers
Fromtheleftnavigationpanel,selectAdministration/AdminAccess,thenenter“RemoveUsers
page,asshowninFigure38.
Presstheuserthatneedstoremovein”UserSummary.Afterthebackgroundturnsblue,press
<Delete>toremovetheuser.
Figure38RemoveUsers
Thesuperuser(adm)canneitherbemodifiednordeleted.Butsuperuser’spasswordcanbe
modified.
3.2.3.4ManagementService
HTTP
HTTP,shortenedformofHypertextTransferProtocol,isusedtotransmitWebpageinformation
onInternet.HTTPislocatedastheapplicationlayerinTCP/IPprotocolstack.
ThroughHTTP,usercouldlogonthedevicetoaccessandcontrolitthroughWeb.
HTTPS
HTTPS(HypertextTransferProtocolSecure)supportsHTTPinSSL(SecuritySocketLayer).
HTTPS,dependingonSSL,isabletoimprovethedevice’ssecuritythroughfollowingaspects:
DistinguishlegalclientsfromillegalclientsthroughSSLandDisableillegalclientsto
accessthedevice;
Encryptthedataexchangedbetweenclientanddevicetoguaranteesecurityand
integralityofdatatransmissionsoastoachievethesafemanagementofdevice;
Anaccesscontrolstrategybasedoncertificateattributionsisestablishedforfurther
controlofclientsaccessauthoritysoastofurtheravoidattackforillegalclients.
TELNET
Telnet isanapplicationlayerprotocolinTCP/IPprotocolfamily,providingtelnetandVTfunctions
throughWeb.DependingonServer/Client,Teln etClientcouldsendrequesttoTelnet server
whichprovidesTe lnetservices.ThedevicesupportsTelnetClientandTeln etServer.
SSH
IncomparisonwithTeln et, STelnet(SecureTelnet),basedonSSH2,allowstheClienttonegotiate
withServersoastoestablishsecureconnection.ClientcouldlogonServerjustasoperationof
Telnet .
ThroughfollowingmeasuresSSHwillrealizethesecuretelnetoninsecurenetwork:
SupportRASauthentication.
SupportencryptionalgorithmssuchasDES,3DESandAES128toencrypt
usernamepasswordanddatatransmission.
Localconnection.ASSHchannelcouldbeestablishedbetweenSSHClientandSSH
Servertoachievelocalconnection.Followingisafigureshowingthe
establishmentofaSSHchannelinLAN:
WANconnection.ASSHchannelcouldbeestablishedbetweenSSHClientandSSH
ServertoachieveWANconnection.Followingisafigureshowingtheestablishmentofa
SSHchannelinWAN:
Fromtheleftnavigationpanel,selectAdministration/AdminAccess,thenenter“Management
Service”page,asshowninFigure39.
Figure39ManagementService
3.2.4AAA
AAAaccesscontrolisusedtocontrolvisitorsandcorrespondingservicesavailableaslongas
accessisallowed.Samemethodisadoptedtoconfigurethreeindependentsafetyfunctions.It
providesmodularizationmethodsforfollowingservices:
Authentication:verifywhethertheuserisqualifiedtoaccesstothenetwork.
Authorization:relatedwithservicesavailable.
Charging:recordsoftheutilizationofnetworkresources.
UsermayonlyuseoneortwosafetyservicesprovidedbyAAA.Forexample,thecompanyjust
wantsidentityauthenticationwhenemployeesareaccessingtosomespecifiedresources,then
networkadministratoronlyneedstoconfigureauthenticationserver.Butifrecordingofthe
utilizationofnetworkisrequired,then,achargingservershallbeconfigured.
CommonlyAAAadopts“Client—Serverstructurewhichisfeaturedbyfavorableexpandability
andfacilitatescentralizedmanagementofusers’information,asthefollowingfigureshows:
3.2.4.1Radius
RemoteAuthenticationDialinUserService(RADIUS),aninformationexchangeprotocolwitha
distributiveClient/Serverstructure,couldpreventthenetworkfromanydisturbancefrom
unauthorizedaccessandisgenerallyappliedinvariousnetworkenvironmentswithhigher
requirementsonsecurityandthatpermitremoteuseraccess.Theprotocolhasdefinedthe
RadiusframeformatbasedonUDPandinformationtransmissionmechanism,confirmedUDP
Port1812astheauthenticationport.RadiusServergenerallyrunsoncentralcomputeror
workstation;RadiusClientgenerallyislocatedonNAS.
InitiallyRadiusisdesignedanddevelopedagainstAAAprotocolofdialinusers.Alongwiththe
diversifieddevelopmentofuseraccessways,Radiusalsoadaptsitselftosuchchanges,including
EthernetaccessandADSLaccess.Accessserviceisrenderedthroughauthenticationand
authorization.
MessageflowbetweenRadiusClientandServerisshownasfollows:
UsernameandpassportwillbesenttotheNASwhentheuserlogsonit;
RadiusClientonNASreceivesusernameandpasswordandthensendsan
authenticationrequesttoRadiusServer;
Uponthereceptionoflegalrequest,RadiusServerexecutesauthenticationandfeeds
backrequireduserauthorizationinformationtoClient;Forillegalrequest,Radius
ServerwillfeedbackAuthenticationFailedtoClient.
Fromtheleftnavigationpanel,selectAdministration/AAA,thenenter“Radius”page,asshownin
Figure310.
Figure310Radius
PagedescriptionisshowninTable32.
Table32RadiusDescription
ParameterDescriptionDefault
ServerAddressServeraddress(domainname/IP)None
PortConsistentwiththeserverport1812
KeyConsistentwiththeserverauthenticationkeyNone
3.2.4.2Tacacs+
Tacacs+,orTermi nalAccessControllerAccessControlSystem,similartoRadius,adopts
Client/ServermodetoachievethecommunicationbetweenNASandTacacs+Server.But,Tacacs+
adoptsTCPwhileRadiusadoptsUDP.
Tacacs+ismainlyusedforauthentication,authorizationandchargingofaccessusersandterminal
usersadoptingPPPandVPDN.Itstypicalapplicationisauthentication,authorizationandcharging
forterminalusersrequiringloggingonthedevicetocarryoutoperation.AstheClient,thedevice
willhaveusernameandpasswordsenttoTacacs+Serverforverification.Solongasuser
verificationpassedandauthorizationobtained,loggingandoperationonthedeviceareallowed.
Fromtheleftnavigationpanel,selectAdministration/AAA,thenenterTacacs+”page,asshown
inFigure311.
Figure311Tacacs+
PagedescriptionisshowninTable33.
Table33Tacacs+Description
ParametersDescriptionDefault
ServerAddressServeraddress(domainname/IP)None
PortConsistentwiththeserverport49
KeyConsistentwiththeserverauthenticationkeyNone
3.2.4.3LDAP
OneofthegreatadvantagesofLDAPisrapidresponsetousers’searchingrequest.Forinstance,
usersauthenticationwhichmaygeneralalargeamountofinformationsentasthesametime.If
databaseisadoptedforthispurpose,sinceitisdividedintomanytables,eachtimetomeetsuch
asimplerequirement,thewholedatabasehastobesearched,integratedandfilteredslowlyand
disadvantageously.LDAP,simpleasatable,onlyrequiresusernameandcommandandsomething
else.Authenticationismetfromefficiencyandstructure.
Fromtheleftnavigationpanel,selectAdministration/AAA,thenenter“LDAP”page,asshownin
Figure312.
Figure312LDAP
PagedescriptionisshowninTable34.
Table34LDAPDescription
ParametersDescriptionDefault
Name DefineservernameNone
ServerAddressServeraddress(domainname/IP)None
PortConsistentwiththeserverportNone
BaseDNThetopofLDAPdirectorytreeNone
UsernameUsernameaccessingtheserverNone
PasswordPasswordaccessingtheserverNone
Security Encryptionmod:None,SSL,StartTLSNone
VerifyPeer VerifyPeerUnopened
3.2.4.4AAASettings
AAAsupportsfollowingauthenticationways:
None:withgreatconfidencetousers,legalcheckomitted,generallynotrecommended.
Local:HaveusersinformationstoredonNAS.Advantages:rapidness,costreduction.
Disadvantages:storagecapacitylimitedbyhardware.
Remote:Haveusersinformationstoredonauthenticationserver.Radius,Tacacs+and
LDAPsupportedforremoteauthentication.
AAAsupportsfollowingauthorizationways:
None:authorizationrejected.
Local:authorizationbasedonrelevantattributionsconfiguredbyNASforlocalusers
account.
Tacacs+:authorizationdonebyTacacs+Server.
RadiusAuthenticationBased:authenticationbondedwithauthorization,authorization
onlybyRadiusnotallowed.
LDAPAuthorization.
Fromtheleftnavigationpanel,selectAdministration/AAA,thenenterAAASettingpage,as
showninFigure313.
Figure313AAAauthentication
PagedescriptionisshowninTable35.
Table35AAASettingsKeyItems
KeyItemsDescription
radiusAuthenticationandAuthorizationServer
tacacs+AuthenticationandAuthorizationServer
ldapAuthenticationandAuthorizationServer
local Thelocalusernameandpassword
Authentication1shouldbesetconsistentlywithAuthorization1;Authentication2shouldbe
setconsistentlywithAuthorization2;Authentication3shouldbesetconsistentlywith
Authorization3.
Whenconfigureradius,Tacas+,localatthesametime,priorityorderfollow:1>2>3.
3.2.5ConfigurationManagement
Hereyoucanbackuptheconfigurationparameters,importthedesiredparametersconfiguration
backupandrestorethefactorysettingsoftherouter.
Fromtheleftnavigationpanel,selectAdministration/ConfigManagement,thenenter“Config
Management”page,asshownin314.
Figure314ConfigurationManagement
PagedescriptionisshowninTable36.
Table36ConfigManagementDescription
ParametersDescriptionDefault
BackuprunningconfigBackuprunningconfigfiletohost.None
BackupstartupconfigBackupstartupconfigfiletohost.None
Automaticallysavemodified
configuration
Decidewhethertoautomaticallysave
configurationaftermodifytheconfiguration.
On
RestoreDefault
Configuration
RestorefactoryconfigurationNone
Whenimporttheconfiguration,thesystemwillfilterincorrectconfigurationfiles,andsavethe
correctconfigurationfiles,whensystemrestarts,itwillorderlyexecutethesesconfiguration
files.Iftheconfigurationfilesdidn’tbearrangedaccordingtoeffectiveorder,thesystemwon’t
enterthedesiredstate.
Inordernottoaffectcurrentsystemrunning,whenperformingtheimportconfigurationand
restorethedefaultconfiguration,needtoreboottherouternewconfigurationwilltakeeffect.
3.2.6SNMP
Definition
SNMP,orSimpleNetworkManagementProtocol,isastandardnetworkmanagementprotocol
widelyusedinTCP/IPnetworksandprovidesamethodofmanagingthedevicethroughthe
runningthecentralcomputerofnetworkmanagementsoftware.FeaturesofSNMP:
Simplicity:SNMPadoptspollingmechanism,providesthemostbasicsetsoffeatures
andcouldbeusedinsmallscale,rapid,lowcostenvironments.SNMP,withUDP
messageasthecarrier,issupportedbyagreatmajorityofdevices.
Powerfulness:objectiveofSNMPistoensurethetransmissionofmanagement
informationbetweenanytwopointssoastofacilitateadministratorsretrievalof
informationonanynodeonnetworkandmodificationandtroubleshooting.
Benefits
NetworkadministratorscouldmakeuseofSNMPtoaccomplishtheinformationquery,
modification,troubleshootingandotherjobsonanynodeonnetworktoachieve
higherefficiency.
Shieldingofphysicaldifferencesbetweendevices.SNMPonlyprovidesthemostbasic
setsoffeaturesformutualindependencebetweenadministrationandthephysical
properties,networktypesofdevicesunderadministration;therefore,itcouldrealize
theuniformmanagementofdifferentdevicesatalowercost.
Simpledesign,lowercost.Simplicityisstressedonadditionofsoftware/hardware,
typesandformatsofmessageondevicessoastominimizetheinfluenceandcoston
devicescausedbyrunningSNMP.
Application:managementofdeviceisachievedthroughSNMP
Administratorisrequiredtocarryoutconfigurationandmanagementofalldevicesinthesame
network,whicharescattered,makingonsitedeviceconfigurationimpracticable.Moreover,in
casethatthosenetworkdevicesaresuppliedfromdifferentsourcesandeachsourcehasits
independentmanagementinterfaces(forexample,differentcommandlines),theworkloadof
batchconfigurationofnetworkdeviceswillbeconsiderable.Therefore,undersuchcircumstances,
traditionalmanualwayswillresultinlowerefficiencyathighercost.Atthattime,network
administratorwouldmakeuseofSNMPtocarryoutremotemanagementandconfigurationof
attacheddevicesandachieverealtimemonitoring.Followingisafigureshowinghowtomanage
devicesthroughSNMP:
ToconfigureSNMPinnetworking,NMS,amanagementprogramofSNMP,shallbeconfiguredat
theManager.Meanwhile,Agentshallbeconfiguredaswell.
ThroughSNMP:
NMScouldcollectstatusinformationofdeviceswheneverandwhereverandachieve
remotecontrolofdevicesundermanagementthroughAgent.
AgentcouldtimelysendcurrentstatusinformationtoNMSreportdevice.Incaseofany
problem,NMSwillbenotifiedimmediately.
3.2.6.1SNMP
SNMPagentofdevicesupportsSNMPv1,SNMPv2andSNMPv3atpresent.
SNMPv1andSNMPv2adoptcommunitynametoauthenticate.
SNMPv3adoptusernameandpasswordtoauthenticate.
Fromtheleftnavigationpanel,selectAdministration/SNMP,thenenter“SNMPpage,as
showninFigure315.
Figure31SNMPv1&SNMPv2cSettings
PagedescriptionisshowninTable37.
Table37SNMPKeyItems
ParametersDescriptionDefault
CommunityNameUserdefineCommunityNamePublicandprivate
AccessLimitSelectaccesslimitReadonly
MIBView SelectMIBViewdefaultView
WhenchoosingSNMPv3version,thecorrespondingUseandUserGroupshouldbeconfigured.
TheconfigurationpageisshowninFigure316.
Figure316SNMPv3Setting
PagedescriptionisshowninTable38.
Table38SNMPv3Description
ParametersDescriptionDefault
GroupManagement
GroupnameUserdefine,length:132charatersNone
SecurityLevelIncludesNoAuth/NoPriv,Auth/NoPriv,Auth/privNoAuth/NoPriv
ReadonlyViewOnlysupportdefaultViewatpresentdefaultView
ReadwriteViewOnlysupportdefaultViewatpresentdefaultView
InformViewOnlysupportdefaultViewatpresentdefaultView
UserManagement
UsernameUserdefinedusername,length:132charactersNone
GroupNameSelectusertojoinusergroup,firstdefinedintheusergroup
managementtable,beforethis,selectappropriateusergroupNone
Authentication
Mode
Selectauthenticationmode.MD5andSHAprovidestwo
authenticationmodes,“noidentification"notenable
authentication.
SHA
Authentication
password
Whenonlyauthenticationmodeisnot"noidentification",
authenticationpasswordcanenter.
Length:832characters.
None
EncryptionmodeChoosewhethertouseDESencryptionmodeDES
Encryption
Password
Onlyencryptionmodeisnot"noencryption",encryption
modepasswordcanenter.
Length:832characters.
None
3.2.6.2SnmpTrap
SNMPtrap:AcertainportwheredevicesunderthemanagementofSNMPwillnotifySNMP
managerratherthanwaitingforpollingfromSNMPmanager.InNMS,Agentsinmanageddevices
couldhaveallerrorsreportedtoNMWatanytimeinsteadofwaitingforpollingfromNMWafter
itsreceptionofsucherrorswhich,asamatteroffact,arethewellknownSNMPtraps.
Fromtheleftnavigationpanel,selectAdministration/SNMP,thenenter“SnmpTrap”page,as
showninFigure317.
Figure317SnmpTrap
PagedescriptionisshowninTable39.
Table39SnmpTrapDescription
ParametersDescriptionDefault
HostAddressFillintheNMSIPaddressNone
SecurtiyName
FillinthegroupnamewhenusetheSNMPv1/v2c;Fillinthe
usernamewhenusetheSNMPv3.Length:132characters
None
UDPPort FillinUDPport,thedefaultportrangeis165535162
3.2.7Alarm
Alarmfunctionisawaywhichisprovidedforuserstogetexceptionsofdevice,whichcanmake
theusersfindandsolveexceptionsassoonaspossible.Whenabnormalityhappened,devicewill
sendalarm.Usercanchoosemanykindsofexceptionswhichsystemdefinedandchoose
appropriatenoticewaytogettheseexceptions.Alltheexceptionsshouldberecordedinalarm
logsothatusertroubleshootproblem.
Alarmcanbedivided:
Raise:Indicatesthealarmoccurrencehasnotbeenconfirmed.
Confirm:Alarmindicatesthatausercannottemporarysolve.
All:Indicatesallalarmsoccur.
Alarmlevelcanbedivided:
EMERGDeviceoccurssomefaults,itcouldleadtothesystemrestart.
CRITDeviceoccurssomefaultswhichareunrecoverable.
WARNDeviceoccurssomefaultswhichcouldaffectsystemfunction.
NOTICEDeviceoccurssomefaultswhichcouldaffectsystemproperties.
INFODeviceoccurssomenormalevents.
3.2.7.1AlarmStatus
Fromtheleftnavigationpanel,selectAdministration/Alarm,thenenter“AlarmState”page,as
showninFigure318.Throughthispage,youcancheckallthealrmssincetherouterispowered.
Click<ClearAllAlarms>tosetallthealarmto“clearstate.
Click<ConfirmAllAlarms>tosetallthealarmto“cconfirmstate.
Click<Reload>toreloadallthealarms.
Figure318AlarmStatus
3.2.7.2AlarmInput
Hereusercouldselectalarmtypesincludingsystemalarmandportalarm.Oneormorethanone
typescouldbeselected.
Fromtheleftnavigationpanel,selectAdministration/Alarm,thenenter“AlarmInputpage,as
showninFigure319.
Figure319AlarmInput
3.2.7.3AlarmOutput
Whenanalarmhappens,thesystemconfiguredwiththisfunctionwillsendthealarmcontentto
intendedemailaddressfromthemailaddresswhereanalarmemailissentinaformofemail.
Generallythisfunctionisnotconfigured.
Fromtheleftnavigationpanel,selectAdministration/Alarm,thenenter“AlarmOutputpage,as
showninFigure320.
Figure320AlarmOutput
PagedescriptionisshowninTable310.
Table310AlarmOutputDescription
ParametersDescriptionDefault
MailServerIP/NameSetIPaddressofMailServerthatsendalarmemails None
MailServerPortSetPortofMailServerthatsendalarmemails25
AccountName SetEmailaddressfromwhichalarmemailsaresentNone
AccountPassword SetEmailpassword None
CryptSetthecryptmethodNone
EmailAddressesDestinationaddressofreceivingalarmemail(110)None
Whentheemailparametershadbeenconfigured,youshouldclickthe“sendtestemail”button
sothatensuretheconfigurationiscorrect.Ifthetestemailfailed,itmaythenetwork
configurationormailboxconfigurationisnotcorrect.
3.2.7.4AlarmMap
AlarmMapconsistsoftwomappingways:CLI(consoleinterface)andEmail.Incaseoflatterone
isselected,andthenalarmoutputshallbeactivatedwithanemailaddresswellconfigured.
Fromtheleftnavigationpanel,selectAdministration/Alarm,thenenter“AlarmMap”page,as
showninFigure321.
Figure321AlarmMap
3.2.8SystemLog
SystemLogincludesmassiveinformationaboutnetworkanddevices,includingoperatingstatus,
configurationchangesandsoon,servingasanimportantwayfornetworkadministratorto
monitorandcontroltheoperationofnetworkanddevices.SystemLogcouldprovideinformation
tohelpnetworkadministratortofindnetworkproblemsorsafetyhazardsoastotakemore
targetedmeasures.
3.2.8.1SystemLog
Fromtheleftnavigationpanel,selectAdministration/Log,thenenter“SystemLogpage,as
showninFigure322.
Figure322SystemLog
Whendownloadsystemlog,routersettingswillalsobedownloaded.
3.2.8.2SystemLogSettings
On“SystemLogSettings”,remotelogservercouldbeset.Routerwillhaveallsystemlogssentto
remotelogserverdependingonremotelogsoftware(forexample:KiwiSyslogDaemon).
Fromnavigationpanel,selectAdministration/Log,thenenter“SystemLogpage,asshownin
Figure223.
Figure323SystemLogSettings
PagedescriptionisshowninTable311.
Table311SystemLogSettingsDescription
ParametersDescriptionDefault
LogtoRemoteSystemOpen/closeremotelogfunctionClose
IPAddress/Port(UDP)SetremoteserversIPaddress/PortNone/514
LogtoConsoleOpen/closeconsolelogfunctionOpen
3.2.8.3KiwiSyslogDaemon
KiwiSyslogDaemonisakindoffreelogserversoftwareusedinWindows,whichcouldreceive,
recordanddisplaylogsformedwhenpoweringonthehostofsyslog(forexample,router,
exchangeboard,Unixhost).AfterdownloadingandinstallationofKiwiSyslogDaemon,configure
necessaryparameterson“File>>Setup>>Input>>UDP.
3.2.9SystemUpgrading
Fromnavigationpanel,selectAdministration/Upgrade,thenenter“Upgrade”page,asshownin
Figure324.
Figure324SystemUpgrading
Click<Browse>toupgradedocumentsandthenclick<Upgrade>tostart.Thewholeprocess
takesabout1min,uponthecompletionofwhich,restarttherouterandnewfirmwaretakes
effect.
Softwareupgradetakestime,duringwhich,pleasedonocarryoutanyoperationonWeb,
otherwise,interruptionmaytakeplace.
Upgradeconsistsoftwostages:firststage:readinofupgradedocumentintobackupfirmware
zone,asdescribedinSectionofSystemUpgrade;secondstage:copyofdocumentsinbackup
firmwarezoneintomainfirmwarezone,whichmaybeexecutedinsystemreboot.
3.2.10Reboot
Fromnavigationpanel,selectAdministration/Reboot,thenenter“Rebootpage,asshownin
Figure325.Click<Yes>torebootthesystem.
Figure325Reboot
Pleasesavetheconfigurationsbeforereboot,otherwisetheconfigurationsthatarenotsaved
willbelostafterreboot.
3.2.11CloudPlatform
Cloudplatformisthroughsoftwareplatformtomanagedevices.Afterenablingcloudplatform,it
canoperatethedevicemanagementthroughsoftwareplatformthatenablesnetworkefficient
running.Forexample,queryequipmentrunningstatus,updatethedevicesoftware,rebootthe
device,andsendconfigurationparameterstotheequipment,etc.,mayalsosendcontrolor
querymessagetothedevicethroughthecloudplatform.
3.2.11.1CloudPlatform
Fromnavigationpanel"Administration>>DeviceManagementCloud"menu,enterthe"Cloud
Platform"screen,asshowninFigure326.
Figure326CloudPlatform
PagedescriptionisshowninTable312.
Table312CloudPlatformDescription
ParametersDescriptionDefault
Server SetcloudplatformIPaddress none
PortSettingcloudplatformportnumbernone
3.2.11.2MOTTClient
FromnavigationpanelAdministration>>DeviceManagementCloud"menu,enterthe"MOTT
Client"screen,asshownbelow.
3.2.12ScheduledTasks
Fromnavigationpanel,selectAdministration>>ScheduleManagement,thenenter“Schedule
Management”page,asshowninFigure327.
Figure327ScheduleManagement
3.3Network
3.3.1Cellular
SIMcarddialoutthroughDialInterface,achieverouterWiFicapabilities.
Dialinterfacesupportsthreeconnections:alwayson,ondemanddialingandmanualdialing.
3.3.1.1Status
Fromnavigationpanel,selectNetwork>>Cellular,thenenter“Status”page,asshowninFigure
328.
Figure328Status
3.3.1.2Cellular
Inthe"Cellular"page,youcancompletethewirelessdialconfiguration.
Fromnavigationpanel,selectNetwork>>Cellular,thenenter“Cellularpage,asshowninFigure
3291.
Figure3291Cellular
AdvancedoptionsareshowninFigure3292.
Figure3292CellularAdvancedoptions
PagedescriptionisshowninTable313.
Table313CellularPageDescription
ParametersDescriptionDefault
ProfileDialpolicychoices,donotneedtoconfigurehere1
RoamingSelectroamingEnable
PINCodeSIMcardPINcodeNone
NetworkSelectionModeThreeoptions:Automatic,2Gand3GAuto
StaticIPClickEnable(Enablerequireoperatorstoopen
relatedservices)Off
Connection
Alternativelyalwaysonline,ondemanddial(allows
dataactivation,phoneactivation,SMSactivation),
manualdialing
Always
online
RedialIntervalwhensettingupthelandingfails,redialinginterval10sec
ICMPdetectionserverDetectremoteIPaddressNone
ICMPdetectionintervalSetICMPdetectioninterval30sec
ICMPdetectiontimeoutSetICMPdetectiontimeout5sec
ICMPdetectionmaximum
numberofretries
SetmaximumnumberofretrieswhenICMP
detectionfails(Redialafterreachingthemaximum
number)
5
ICMPstrictdetectionClickEnableOff
Dialparameters
IndexUserdefined,generallyintheorderdefinedby
digital.None
NetworkMobilenetworktypeusedforselectingGSM
APN(CDMA2000series
doesnotsetthis)
Mobileoperatorstoprovidetherelevant
parameters(accordingtolocaloperatorschoose)3gnet
DialNumberMobileoperatorstoprovidetherelevant
parameters(accordingtolocaloperatorschoose)*99***1#
UserNameMobileoperatorstoprovidetherelevant
parameters(accordingtolocaloperatorschoose)gprs
PasswordMobileoperatorstoprovidetherelevant
parameters(accordingtolocaloperatorschoose)******
ClickEnableShowAdvancedOptions(thefollowingaretherelevantparameterstoconfigure
aftertheadvancedoptionsturnon)
InitiaCommandsUsedtosetadvancednetworkparameters,
generallydonotneedtofillinNone
RSSIPollIntervalSetsignalqueryinterval120sec
DialtimeoutSetdialtimeout(afterdialingtimeoutthesystem
willredial)120sec
MTUSetsthemaximumtransmissionunitinbytes1500
MRUSettingmaximumreceivingunitinbytes1500
EnabledefaultasyncmapClickEnabledefaultasyncmapDisable
UseassignedDNSserverClicktoenabletoacceptassignedDNSbymobile
operators.Enable
Connectiondetection
intervalSetconnectiondetectioninterval55sec
ConnectionDetection
maximumnumberof
retries
Setmaximumnumberofretrieswhenconnection
detectionfails(Redialafterreachingthemaximum
number)
5
EnabledebugmodeThesystemcanprintamoredetailedlogEnable
ExpertOptionsProvideadditionalPPPparameters,usersgenerally
donotsetNone
3.3.2WLANInterface2.4G
WLANorWirelessLAN,isquiteconvenientdatatransmissionsystem,whichusesradiofrequency
(RadioFrequency;RF)technology,toreplacetheoldoutofthewayoftwistedcopper(Coaxial)
localareanetworkcomposedofsuchawirelesslocalareanetwork,canbeaccessedusinga
simplearchitectureallowsuserstothroughit,to"carryinformationtechnologytofacilitatetravel
theworld,"theidealstate.
3.3.2.1Status
Fromnavigationpanel,selectNetwork/WLAN(2.4G),enter“Status”page,asshowninFigure
330.
Figure330WLAN(2.4G)Status
3.3.2.2WLAN(2.4G)
WLANinterfacehasaccesspointandclienttwotypes.Fromnavigationpanel,select
"Network/WLAN(2.4G)"menu,enter"WLAN(2.4G)"page.Interfacetypeusingthe"access
point",asshowninFigure331a;interfacetypeusingthe"client",asshowninFigure331b.
Figure331aWLAN(2.4G)‐AccessPoint
PagedescriptionisshowninTable314a.
Table314aAccessPointDescription
ParametersDescriptionDefault
MultipleSSIDClickEnable,enabledreusablecustom3SSIDDisable
SSIDBroadcastOpen"SSIDBroadcast",usercansearchwirelessnetwork
throughSSIDname.Enable
RFType
SixtypesOptional:
802.11g/n,802.11g,802.11n,802.11b,802.11b/g,802.11b/
g/n
802.11g/n
Channel Selectchannel11
SSIDUserdefinedSSIDnameInPortal3000
AuthenticationFourauthenticationmodesavailable:Open,Shared,
WPAPSKandWPA2PSKOpen
EncryptionAccordingtothedifferentauthenticationmethods,
supportNONE,WEP40andWEP104NONE
Wireless
BandwidthTwooptions:20MHzand40MHz20MHz
MaximumNumber
ofClients Userdefined(upto128)None
Figure331bWLAN(2.4G)‐Client
PagedescriptionisshowninTable314b.
Table314bClientInterfaceDescription
ParametersDescriptionDefault
SSIDFillintheSSIDnametoconnectNone
AuthenticationSSIDauthenticationmethodOpen
EncryptionSSIDencryptionmethodNONE
WhentheWLANissetasClientmode,refertothefollowing3steps:
Step1:select"Network/Cellular"menu,enter"Cellular"page,anddisableCellularfunction.If
therouterdoesnothavecelluarmodule,skipthisstepandgotostep2.
Step2:select"Network/WLAN(2.4G)"menu,enter"WLAN(2.4G)"pageandchoose“Clientto
configurerelatedparametersasshowninFigure331b.
Step2:select"Network/WLAN(2.4G)"menu,enter"IPSetup"pagetoconfigureIPparametersas
shownin3.3.2.3IPSetup.
3.3.2.3IPSetup
WLANinterfaceIPaddresssupportmultipleIP,itcanbesetaccordingtodemand,butuptomore
than10.
Fromnavigationpanel,select"Network/WLAN(2.4G)"menu,enter"IPSetup"page,asshownin
Figure332.
Figure332WLAN(2.4G)IPSetup
3.3.2.4SSIDScan
WLANinterfaceselectsclient(Section3.3.2.2WLANInterface(2.4G)),SSIDscanningfunction
starts.Fromnavigationpanel"Network/WLAN(2.4G)"menu,enter"SSIDScan"page,willdisplay
alltheavailableSSIDnames,andthedisplayInportalcanbeconnectedasaclientstate.
3.3.3WLANInterface5.8G
3.3.3.1Status
Fromnavigationpanel,selectNetwork/WLAN(5.8G),enter“Status”page,asshowninFigure
334.
Figure334WLAN(5.8G)Status
3.3.3.2WLAN5.8G
WLANinterfacehasaccesspointandclienttwotypes.Fromnavigationpanel"Network/WLAN
(5.8G)"menu,enter"WLAN(5.8G)"page.Interfacetypeusingthe"accesspoint",asshownin
Figure335a;interfacetypeusingthe"client",asshowninFigure335b.
Figure335aWLANinterface(5.8G)‐AcessPoint
PagedescriptionisshowninTable315a.
Table315aAcessPointDescription
ParametersDescriptionDefault
MultipleSSIDClickEnable,enabledreusablecustom3SSIDDisable
SSIDBroadcastOpen"SSIDBroadcast",usercansearchwirelessnetwork
throughSSIDname.Enable
RFType
SixtypesOptional:
802.11g/n,802.11g,802.11n,802.11b,802.11b/g,802.11b/
g/n
802.11g/n
Channel Selectchannel11
SSIDUserdefinedSSIDnameInPortal3000
AuthenticationFourauthenticationmodesavailable:Open,Shared,
WPAPSKandWPA2PSKOpen
EncryptionAccordingtothedifferentauthenticationmethods,
supportNONE,WEP40andWEP104NONE
Wireless
BandwidthTwooptions:20MHzand40MHz20MHz
MaximumNumber
ofClients Userdefined(upto128)None
Figure335bWLANinterface(5.8G)Client
PagedescriptionisshowninTable315b.
Table315bWLANinterface(5.8G)Description
ParametersDescriptionDefault
5GprioritySelectEnable Disable
SSIDSSIDnametoconnectNone
AuthenticationSSIDauthenticationmethodOpen
EncryptionSSIDencryptionmethodNONE
WhentheWLANissetasClientmode,refertothefollowing3steps:
Step1:select"Network/Cellular"menu,enter"Cellular"page,anddisableCellularfunction.If
therouterdoesnothavecelluarmodule,skipthisstepandgotostep2.
Step2:select"Network/WLAN(5.8G)"menu,enter"WLAN(5.8G)"pageandchoose“Clientto
configurerelatedparametersasshowninFigure335b.
Step2:select"Network/WLAN(5.8G)"menu,enter"IPSetup"pagetoconfigureIPparametersas
shownin3.3.3.3IPSetup.
3.3.3.3IPSetup
WLANinterfaceIPaddresssupportmultipleIP,itcanbesetaccordingtodemand,butuptomore
than10.
Fromnavigationpanel,selectNetwork/WLAN(5.8G),enter"IPSetup"page,asshowninFigure
336.
Figure336WLAN(5.8G)IPSetup
3.3.3.4SSIDScan
WLANinterfaceselectsclient(Section3.3.3.2WLANInterface(5.8G)),SSIDscanningfunction
starts.Fromnavigationpanel"Network/WLANinterface(5.8G)"menu,enter"SSIDScan"page,
willdisplayalltheavailableSSIDnames,andthedisplayInportalcanbeconnectedasaclient
state.
3.3.4CaptivePortal
CaptiveportalisWebpagethatusermustvisitandinteractwithbeforegrantedaccesstopublic
accessnetwork.CaptiveportalusuallyoffersfreeWiFihotspotservicestoInternetusersin
commercialcenters,airports,hotellobbies,cafesandotherpublicplacestouse.
Fromnavigationpanel"Network/captiveportal"menu,enterthe"captiveportal"page.Asshown
inFigure338.
Figure338CaptivePortal
PagedescriptionisshowninTable316.
Table316CaptivePortalDescription
ParametersDescriptionDefault
LANInterfaceCaptiveportallocalinterfacedotllradio1
WANInterfaceExternalnetworkadaptercellular1
SplashedHomePage PushHometocustomerswifi.go
Authentication
Server
UserauthenticationserverIPaddressforuserlogin
authenticationNone:80
ForceReloginPeriod ForceusertoreloginNone
SilentUserUserautomaticlogoffwhennoflow5
AutomaticLogoff
ClientFairnessUsedinconjunctionwiththespeedfunctionEnable
SpeedLimitWificlienttrafficrestrictionsNone
KnownUsersAccess
Control
Authenticateduseraccesscontroltwooptionals:
blacklistandwhitelistmode.Blacklist
TrustedMACAddressesList
IDSerialnumberNone
MACAddressMACaddressauthenticationfreeuserNone
Globalwhitelist
IDSerialnumberNone
Domain/IPaddressorIPthatcanbeaccessedwithout
authentication
None
Authenticatedusersblacklist
IDSerialnumberNone
Domain/IP
Restrictauthenticateduserstoaccessnetwork,thatis
cannotbeaccessedbyauthenticatedusersto
blacklistaddressesorIP
None
3.3.5DHCPservice
Alongwiththecontinuousexpansionofnetworksizeandcomplicationofnetwork,numberof
computersoftenexceedsdistributableIPaddresses.Meanwhile,inpacewiththeextensive
applicationofportabledevicesandwirelessnetwork,positionofcomputerchangesfrequently,
resultingtothefrequentupgradeofIPaddress,leadingtoamoreandmorecomplicatednetwork
configuration.DHCP(DynamicHostConfigurationProtocol)isaproductforsuchdemands.
DHCPadoptsClient/Servercommunicationmode.ClientsendsconfigurationrequesttoServer
whichfeedsbackcorrespondingconfigurationinformation,includingdistributedIPaddresstothe
ClienttoachievethedynamicconfigurationofIPaddressandotherinformation.
IntypicalapplicationsofDHCP,generallyoneDHCPServerandanumberofClients(PCand
PortableDevices)areincluded,asthefollowingfigureshows:
WhenDHCPClientandDHCPServerareindifferentphysicalnetworksegment,Clientcould
communicatewithServerthroughDHCPRelaytoobtainIPaddressandotherconfiguration
information,asthefollowingfigureshows:
3.3.5.1Status
Fromnavigationpanel,selectNetwork/DHCP,thenenter“Status”page,asshowninFigure339.
Figure339DHCPStatus
3.3.5.2DHCPServer
ThedutyofDHCPServeristodistributeIPaddresswhenWorkstationlogsonandensureeach
workstationissuppliedwithdifferentIPaddress.DHCPServerhassimplifiedsomenetwork
managementtasksrequiringmanualoperationsbeforetothelargestextent.
Fromnavigationpanel,selectNetwork>>DHCP,thenenter“DHCPServerpage,asshownin
Figure340.
Figure340DHCPServer
PagedescriptionisshowninTable317.
Table317DHCPServerDescription
ParametersDescriptionDefault
EnableOn/OffOff
Interfacedot11radio1dot11radio1
StartingAddressDynamicaldistributionofstartingIPaddressN/A
EndingAddressDynamicaldistributionofendingIPaddressN/A
LeaseDynamicaldistributionofIPvalidity1440
DNSServerOneortwo,orNoneN/A
WINSSetupofWINS,generallyleftblankN/A
StaticIPSetup
MACAddress
SetupastaticspecifiedDHCP’sMACaddress
(differentfromotherMACstoavoidconfliction)
0000.0000.0000
IPAddress
SetupastaticspecifiedIPaddress(withinthe
scopefromstartIPtoendIP)
N/A
IfthehostconnectedwithrouterchoosestoobtainIPaddressautomatically,thensuch
servicemustbeactivated.StaticIPsetupcouldhelpacertainhosttoobtainspecifiedIP
address.
3.3.5.3DHCPRelay
Generally,DHCPdatapacketisunabletobetransmittedthroughrouter.Thatistosay,DHCP
ServerisunabletoprovideDHCPservicesfortwoormoredevicesconnectedwitharouter
remotely.ThroughDHCPrelay,DHCPrequestsandresponsedatapacketcouldgothroughmany
routers(BroadbandRouter).
Fromnavigationpanel,selectNetwork/DHCP,thenenter“DHCPRelaypage,asshowninFigure
341.
Figure341DHCPRelay
PagedescriptionisshowninTable318.
Table318DHCPRealyDescription
ParametersDescriptionDefault
EnableOn/OffOff
DHCPSeverSetDHCPserver;upto4serverscanbeconfiguredN/A
SourceIPAddressoftheinterfaceconnectedtotheDHCPserverN/A
3.3.5.4DHCPClient
Fromnavigationpanel,selectNetwork/DHCP,thenenter“DHCPClient”page,byclickingto
enable,chooseSSIDinterface,asshowninFigure342.
Figure342DHCPClient
3.3.6DNSServices
DNS(DomainNameSystem)isaDDBusedinTCP/IPapplicationprograms,providingswitch
betweendomainnameandIPaddress.ThroughDNS,usercoulddirectlyusesomemeaningful
domainnamewhichcouldbememorizedeasilyandDNSServerinnetworkcouldresolvethe
domainnameintocorrectIPaddress.
Thedevicesupportstoachievefollowingtwofunctionsthroughdomainnameservice
configuration:
 DNSServer:fordynamicdomainnameresolution.
 DNSrelay:thedevice,asaDNSAgent,relaysDNSrequestandresponsemessagebetween
DNSClientandDNSServertocarryoutdomainnameresolutioninlieuofDNSClient.
3.3.6.1DNSServer
DomainNameServer:DNSstandsforDomainNameSystem.ItisacoreserviceoftheInternet.
AsadistributeddatabasethatcanletthedomainnamesandIPaddressesmappingtoeachother,
itallowspeopletomoreconvenientlyaccesstotheInternetwithouttheneedtomemorizetheIP
stringthatcanbedirectlyreadbythecomputer.
Fromnavigationpanel,selectNetwork/DNS,thenenter“DNSServerpage.Inmanualsetupof
DNSServer,ifitisblank,thendialtoobtainDNS.Generallythisitemisrequiredtobesetwhen
WANportusesstaticIP,asshowninFigure343.
Figure343DNSServer
PagedescriptionisshowninTable319.
Table319DNSServerDescription
ParametersDescriptionDefault
PrimaryDNSUserdefinePrimaryDNSaddress N/A
SecondaryDNSUserdefineSecondaryDNSaddressN/A
3.3.6.2DNSRelay
DNSforwarding:DNSforwardingisopenbydefault.Youcansetthespecified[DomainName<=>
IPAddress]toletIPaddressmatchwiththedomainname,thusallowingaccesstothe
appropriateIPthroughaccessingtothedomainname.
Fromnavigationpanel,selectNetwork/DNS,thenenter“DNSRelaypage,asshownin344.
Figure344DNSRelay
PagedescriptionisshowninTable320.
Table320DNSDelayDescription
ParametersDescriptionDefault
EnableDNSRelay On/OffOn
HostDomainNameN/A
IPAddress1SetIPAddress1N/A
IPAddress2SetIPAddress2N/A
OnceDHCPisturnedon,DNSrelaywillbeturnedonasdefaultandcan’tbeturnedoff;toturn
offDNSrely,DHCPServerhastobeclosedfirstly.
3.3.7SMS
SMSpermitsmessagebasedrebootandmanualdialing.
Fromnavigationpanel,selectNetwork/SMS,thenenter“Basic”page.ConfigurePermitactionto
PhoneNumberandclick<Apply&Save>.Afterthatyoucansend“rebootcommandtorestart
thedeviceorcellular1pppup/down”toredialordisconnectthedevice,asshowninFigure
345.
Figure345SMS
PagedescriptionisshowninTable321.
Table321SMSDescription
ParametersDescriptionDefault
EnableOn/OffOff
ModeTEXTandPDUTEXT
PollInterval UserdefinePollInterval 120
SMSAccessControl
IDUserdefineID1
Action Permitandrefuseareavailable Permit
PhoneNumber TrustingphonenumberN/A
3.3.8VLANInterface
VLAN(VirtualLocalAreaNetwork)dividesLANdevicelogicallyintooneandanothernetwork
segment,enableemergingdataexchangetechnologyofvirtualworkgroups.
3.3.8.1VLANConfiguration
Fromnavigationpanel"Network/VLAN"menu,enter"ConfigureVLANParameters"page,click
<Add>buttontoaddtheVLAN,asshowninFigure346.
Figure346ConfigureVLANParameters
PagedescriptionisshowninTable322.
Table322ConfigureVLANParametersDescription
ParametersDescriptionDefault
VLANIDVLANID,UserdefinedNone
VLANInterface
PrimaryIP
Address
IPaddressUserscanconfigureorchangetheprimaryIP
addressneeded
None
Subnet
Mask
Userscanconfigureorchangethesubnetmaskif
necessary
Secondary
IPAddress
IPaddressInadditiontoprimaryIP,usercanalsoconfigure
10SecondaryIPaddresses
None
Subnet
Mask
Userscanconfigureorchangethesubnetmaskif
necessary
3.3.8.2VLANAggregation
Fromnavigationpanel"Network/VLAN”menu,enter"VLANTrunk"page,setVLANportmodefor
InPortal,themodecanbesettoAccessorTrunk,asshowninFigure347.
Figure347VLANTrunk
3.3.9ADSLDialupPPPoE
PPPoEisPointtoPointProtocoloverEthernet.Usersneedwhilemaintainingtheoriginalaccess,
installaPPPoEclient.ThroughPPPoE,aremoteaccessdevicecanrealizecontrolandaccounting
ofeachaccessuser.
EthernetinterfaceconnectionmodeyouconfigurehereisPPPoE,namelytheinterfaceasPPPoE
client.
Fromnavigationpanel"Network/ADSLDialup(PPPoE)"menu,enter"ADSLDialup(PPPoE)"page,
asshowninFigure348.
Figure348PPPoE
PagedescriptionisshowninTable323.
Table323PPPoEDescription
ParametersDescriptionDefault
DialPoolUserdefined,easytorememberandmanageNone
Interface SelectFastethernet0/1orFastethernet0/2Fastethernet0/1
PPPoEList
IDUserdefined,easytorememberandmanage1
PoolIDDialpoolIndexNone
AuthenticationTypeThreeoptions:Auto,PAP,CHAPAuto
UserNameRelevantparametersprovidedbypeer
operator
None
Password Relevantparametersprovidedbypeer
operator
None
LocalIPAddressAssignedIPaddresstoEthernetinterfaceNone
RemoteIPAddressRemoteIPaddressNone
3.3.10LoopbackInterface
LoopbackisusedtorepresentrouterID,becauseifyouuseactiveinterface,whenactivity
interfaceDOWN,routerIDissubjecttoreselection,thatwouldcauseOSPFconvergencetime
slow,thusloopbackinterfaceisgenerallyusedasarouterID.
Loopbackinterfaceislogicalandvirtualinterfaceonrouters.Nodefaultrouterloopbackinterface.
Youcancreateanynumberofloopbackinterfacesasneeded.Theseinterfacesonroutertreated
likephysicalinterface:Youcanassignthemaddressinginformation,includingtheirchoiceto
updatethenetworknumberinrouters,oreventerminateIPconnectiononthem.
Fromnavigationpanel"Network/LoopbackInterface"menu,enter"loopback"page,shownin
Figure349.
Figure349Loopback
PagedescriptionisshowninTable324.
Table324LoopbackInterfaceDescription
ParametersDescriptionDefault
IPAddressUsercannotchange.127.0.0.1
SubnetMaskUsercannotchange.255.0.0.0
MultiIPsettingsInadditiontotheaboveIP,useralsocanbeequipped
withotherIPaddresses
None
SinceloopbackinterfaceisexclusiveofoneIPaddress,subnetmaskisgenerallyrecommended
to255.255.255.255,tosaveresources.
3.3.11DynamicDomainName
DDNSDynamicDomainNameServiceismappinguserdynamicIPaddresstoafixeddomain
nameresolutionservices,whenuserconnecttothenetwork,clientprogramwillpassdynamicIP
addressofthehostthroughinformationtransfertoserverprogramonthehostofservice
providers,theserverprogramisresponsibleforprovidingDNSserviceandrealizingdynamic
domainnameresolution.Thatis,DDNStocapturechangeableIPaddress,thencorresponding
withdomainname,sothatotherInternetuserscancommunicatethroughthedomainname.
Andallfinalcustomerstoremember,istorememberthedynamicdomainnamegivenby
suppliers,withouthavingtopipehowtheyareimplemented.
DDNSfunctionasDDNSclienttools,weneedtoworkwithDDNSserver.Beforeusingthisfeature,
youneedfirsttofindcorrespondingsitessuchas(www.3322.org)andapplyforregistrationofa
domainname.
DDNSservicetypeinclude:DynAccess,QDNS(3322)Dynamic,QDNS(3322)Static,
DynDNSDynamic,DynDNSStaticandNoIP.
Fromnavigationpanel"Network/DDNS"menu,enter"DDNS"page.Setdynamicbindingdomain.
AsshowninFigure350.
Figure350DynamicDomainName
PagedescriptionisshowninTable325.
Table325DynamicDomainNameDescription
ParametersDescriptionDefault
MethodUserdefinedNone
ServiceTypeSelectdynamicdomainnameserviceprovidersDisable
UserNameApplyregistrationDDNSusernameNone
Password ApplyregistrationDDNSusernameNone
Host ApplyregistrationDDNShostNone
SpecifiedInterface
UpdateMethod
Defineddynamicdomainupdatemethod None
IfIProuterdialobtainaprivateaddress,dynamicDNSfunctionisnotavailable.
3.3.12BridgeInterface
Fromnavigationpanel"Network/Bridge"menu,enter"Bridge1"page,setrelatedparameters,as
showninFigure351.
Figure351Bridge1
PagedescriptionisshowninTable326.
Table326EthernetInterfaceParameterDescription
ParametersDescriptionDefault
BridgeIDBridgenumbercanonlybeassignedto1None
BridgeInterface
IPaddressandsubnetmaskof
primaryaddress
ConfigureorchangetheprimaryIPaddressand
subnetmaskasneeded.None
IPaddressandsubnetmaskof
secondaryaddress
InadditiontoprimaryIPfromoutside,clientsalso
canbeequippedwithsecondaryIPaddressand
subnetmask
None
BridgeMember
ClickenablebridgeinterfaceNone
3.4LinkBackup
3.4.1SLA
BasicConceptsandPrinciples
Undernormalcircumstances,theedgeroutercandetectifthelinklinkedtotheISPisinfault.If
thenetworklinkingtooneISPisinfault,anotherISPwillbeusedtotransmitallthedatastreams.
However,ifthelinkofanISPisnormalandtheinfrastructurefails,theedgerouterwillcontinue
tousethisroute.Then,thedataisnolongerreachable.
Onefeasiblesolutionistousingstaticroutingorpolicybasedroutingtofirsttestthereachability
ofimportantdestination.Ifitisunreachable,thestaticroutingwillbedeleted.
ThereachabilitytestcanbeperformedwithInHandSLAtocontinuouslycheckthereachabilityof
ISPandbeassociatedwithstaticrouting.
BasicprinciplesofInHandSLA:1.Objecttrack:Trackthereachabilityofthespecifiedobject.2.
SLAprobe:TheobjecttrackfunctioncanuseInHandSLAtosenddifferenttypesofdetectionsto
theobject.3.Policybasedroutingusingroutemappingtable:Itassociatesthetrackresultswith
theroutingprocess.4.Usingstaticroutingandtrackoptions.
SLAConfigurationSteps
Step1:DefineoneormoreSLAoperations(detection).
Step2:DefineoneormoretrackobjectstotrackthestatusofSLAoperation.
Step3:Definemeasuresassociatedwithtrackobjects.
Fromnavigationpanel,selectLinkBackup>>SLA,thenenter“SLA”page,asshowninFigure
352.
Figure352SLA
PagedescriptionisshowninTable327.
Table327SLADescription
ParametersDescriptionDefault
IndexSLAindexorID1
TypeDetectiontype,defaultisicmpecho,theusercannotchange icmpecho
IPAddressDetectedIPaddressNone
DataSize Userdefinedatasize 56
Interval Userdefinedetectioninterval 30
Timeout(ms)Userdefine,Timeoutfordetectiontofail5000
ConnecutiveDetectionretries5
LifeDefaultis“forever,usercannotchange forever
StarttimeDetectionStarttime,select“now”orNonenow
3.4.2TrackModule
Trackisdesignedtoachievelinkageconsistingofapplicationmodule,Trackmoduleand
monitoringmodule.Linkagereferstoachievethelinkageamongstdifferentmodulesthroughthe
establishmentoflinkageitems,namely,themonitoringmodulecouldtriggerapplicationmodule
totakeacertainactionthroughTrackmodule.Monitoringmoduleisresponsiblefordetectionof
linkstatus,networkperformanceandnotificationtoapplicationmoduleofdetectionresultsvia
Trackmodule.Oncetheapplicationmodulefindsoutanychangesinnetworkstatus,
correspondingmeasureswillbetakenonatimelybasissoastoavoidinterruptionof
communicationorreductionofservicequality.
Trackmoduleislocatedbetweenapplicationmoduleandmonitoringmodulewithmainfunctions
ofshieldingthedifferencesofdifferentmonitoringmodulesandprovidinguniforminterfacesfor
applicationmodule.
TrackModuleandMonitoringModuleLinkage
Throughconfiguration,thelinkagerelationshipbetweenTrackmoduleandmonitoringmoduleis
established.Monitoringmoduleisresponsiblefordetectionoflinkstatus,networkperformance
andnotificationtoapplicationmoduleofdetectionresultsviaTrackmodulesoastocarryout
timelychangeofthestatusofTrackitem:
Successfuldetection,correspondingtrackitemisPositive
Faileddetection,correspondingtrackitemisNegative
TrackModuleandApplicationModuleLinkage
Throughconfiguration,thelinkagerelationshipbetweenTrackmoduleandapplicationmoduleis
established.Incaseofanychangesintrackitem,anotificationrequiringcorrespondent
treatmentwillbesenttoapplicationmodule.
Currently,applicationmoduleswhichcouldachievelinkagewithtrackmoduleinclude:VRRP,
staticrouting,strategybasedroutingandinterfacebackup.
Undercertaincircumstances,onceanychangesinTrackitemarefounded,ifatimelynotification
issenttoapplicationmodule,thencommunicationmaybeinterruptedduetoroutingsfailurein
timelyrestorationandotherreasons.Forexample,MasterrouterinVRRPbackupgroupcould
monitorthestatusofupstreaminterfacethroughTrack.Incaseofanyfaultinupstreaminterface,
MasterrouterwillbenotifiedtoreduceprioritysothatBackuproutermayascendtothenew
Mastertoberesponsibleforrelayofmessage.Onceupstreaminterfaceisrecovered,solongas
TrackimmediatelysendsamessagetooriginalMasterroutertorecoverpriority,thentherouter
willtakeoverthetaskofmessagerelay.Atthattime,messagerelayfailuremayoccursincethe
routerhasnotrestoredtotheupstreamrouter.Undersuchcircumstances,usertoconfigurethat
onceanychangestakeplaceinTrackitem,delaysaperiodoftimetonotifytheapplication
module.
Fromnavigationpanel,selectLinkBackup/Track,thenenterTrack”page,asshownFigure353.
Figure353TrackM
PagedescriptionisshowninTable328.
Table328TrackDescription
ParametersDescriptionDefault
Index TrackindexorID1
TypeDefault“sla”,Usercannotchangesla
SLAIDDefinedSLAIndexorIDNone
InterfaceDetectinterface’sup/downstatecellular1
NegativeDelay
(m)
Incaseofnegativestatus,switchingcanbedelayedbasedon
thesettime(0representsimmediateswitching),ratherthan
immediateswitching.
0
PositiveDelay
(m)
Incaseoffailurerecovery,switchingcanbedelayedbasedon
thesettime(0representsimmediateswitching),ratherthan
immediateswitching.
0
3.4.3VRRP
Defaultrouteprovidesconvenienceforusersconfigurationoperationsbutalsoimposeshigh
requirementsonstabilityofthedefaultgatewaydevice.Allhostsinthesamenetworksegment
aresetupwithanidenticaldefaultroutewithgatewaybeingthenexthopingeneral.Whenfault
occursongateway,allhostswiththegatewaybeingdefaultrouteinthenetworksegmentcan’t
communicatewithexternalnetwork.
Increasingexitgatewayisacommonmethodforimprovingsystemreliability.Then,theproblem
tobesolvedishowtoselectrouteamongmultipleexits.VRRP(VirtualRouterRedundancy
Protocol)addsasetofroutersthatcanundertakegatewayfunctionintoabackupgrouptoforma
virtualrouter.TheelectionmechanismofVRRPwilldecidewhichroutertoundertakethe
forwardingtaskandthehostinLANisonlyrequiredtoconfigurethedefaultgatewayforthe
virtualrouter.
VRRPwillbringtogetherasetofroutersinLAN.Itconsistsofmultipleroutersandissimilartoa
virtualrouterinrespectoffunction.Accordingtothevlaninterfaceipofdifferentnetwork
segments,itcanbevirtualizedintomultiplevirtualrouters.EachvirtualrouterhasanIDnumber
andupto255canbevirtualized.
VRRPhasthefollowingcharacteristics:
VirtualrouterhasanIPaddress,knownastheVirtualIPaddress.ForthehostinLAN,it
isonlyrequiredtoknowtheIPaddressofvirtualrouter,andsetitastheaddressofthe
nexthopofthedefaultroute.
Hostinthenetworkcommunicateswiththeexternalnetworkthroughthisvirtual
router.
1routerwillbeselectedfromthesetofroutersbasedonprioritytoundertakethe
gatewayfunction.Otherrouterswillbeusedasbackuprouterstoperformthedutiesof
gatewayforthegatewayrouterincaseoffaultofgatewayrouter,thustoguarantee
uninterruptedcommunicationbetweenthehostandexternalnetwork
VRRPNetworkingScheme
AsshowninFigureabove,RouterAandRouterCcomposeavirtualrouter.Thisvirtualrouterhas
itsownIPaddress.ThehostinLANwillsetthevirtualrouterasthedefaultgateway.RouterAor
RouterC,theonewiththehighestpriority,willbeusedasthegatewayroutertoundertakethe
functionofgateway.AnotherrouterwillbeusedasaBackuprouter.
MonitorinterfacefunctionofVRRPbetterexpandsbackupfunction:thebackupfunctioncanbe
offeredwheninterfaceofacertainrouterhasfaultorotherinterfacesoftherouterare
unavailable.
WheninterfaceconnectedwiththeuplinkisatthestateofDownorRemoved,therouteractively
reducesitsprioritysothatthepriorityofotherroutersinthebackupgroupishigherandthusthe
routerwithhighestprioritybecomesthegatewayforthetransmissiontask.
Fromnavigationpanel,selectLinkBackup/VRRP,thenenter“VRRP”page,asshowninFigure
354.
Figure354VRRP
PagedescriptionisshowninTable329.
Table329VRRPDescription
ParametersDescriptionDefault
EnableEnable/DisableEnable
VirtualRouteIDUserdefineVirtualRouteIDNone
InterfaceConfiguretheinterfaceofVirtualRoutevlan1
VirtualIPAddressConfiguretheIPaddressofVirtualRouteNone
Priority
TheVRRPpriorityrangeis0255(alargernumberindicates
ahigherpriority).Therouterwithhigherprioritywillbe
morelikelytobecomethegatewayrouter.
100
Advertisement
Interval
Heartbeatpackagetransmissiontimeintervalbetween
routersinthevirtualipgroup
1
PreemptionMode
Iftherouterworksinthepreemptivemode,onceitfinds
thatitsownpriorityishigherthanthatofthecurrent
gatewayrouter,itwillsendVRRPnotificationpackage,
resultinginreelectionofgatewayrouterandeventually
Enable
replacingtheoriginalgatewayrouter.Accordingly,the
originalgatewayrouterwillbecomeaBackuprouter.
TrackIDTraceDetection,selectthedefinedTrackindexorID None
3.4.4InterfaceBackup
Interfacebackupreferstobackuprelationshipformedbetweenappointedinterfacesinthesame
equipment.Whenservicetransmissioncan’tbecarriedoutnormallyduetofaultofacertain
interfaceorlackofbandwidth,rateofflowcanbeswitchedtobackupinterfacequicklyandthe
backupinterfacewillcarryoutservicetransmissionandsharenetworkflowsoastoraise
reliabilityofcommunicationofdataequipment.
Whenlinkstateofmaininterfaceisswitchedfromuptodown,systemwillwaitforpresetdelay
firstinsteadofswitchingtolinkofbackupinterfaceimmediately.Onlyifthestateofmain
interfacestillkeepsdownafterthedelay,systemwillswitchtolinkofbackupinterface.
Otherwise,systemwillnotswitch.
Afterlinkstateofmaininterfaceisswitchedfromdowntoup,systemwillwaitforpresetdelay
firstinsteadofswitchingbacktomaininterfaceimmediately.Onlyifstateofmaininterfacestill
keepsupafterthedelay,systemwillswitchbacktomaininterface.Otherwise,systemwillnot
switch.
Fromnavigationpanel,selectLinkBackup/InterfaceBackup,thenenter“InterfaceBackup”page,
asshowninFigure355.
Figure355InterfaceBackup
PagedescriptionisshowninTable330.
Table330InterfaceBackupDescription
ParametersDescriptionDefault
PrimaryInterfaceTheinterfacebeingusedcellular1
BackupInterfaceInterfacetobeswitchedcellular1
StartupDelaySethowlongtowaitforthestartuptrackingdetection
policytotakeeffect
60
UpDelay
Whentheprimaryinterfaceswitchesfromfailed
detectiontosuccessfuldetection,switchingcanbe
delayedbasedonthesettime(0representsimmediate
switching),ratherthanimmediateswitching.
0
DownDelay
Whentheprimaryinterfaceswitchesfromsuccessful
detectiontofaileddetection,switchingcanbedelayed
basedonthesettime(0representsimmediate
switching),ratherthanimmediateswitching.
0
TrackIDTraceDetection,selectthedefinedTrackindexorIDNone
3.5Routing
3.5.1StaticRoute
Staticroutingisaspecialroutingthatrequiresyourmanualsetting.Aftersettingstaticrouting,
thepackageforthespecifieddestinationwillbeforwardedaccordingtothepathdesignatedby
you.Inthenetworkwithrelativelysimplenetworkingstructure,itisrequiredtosetstaticrouting
toachievenetworkinterworking.Propersettingandusestaticroutingcanimprovethe
performanceofnetworkandcanguaranteebandwidthforimportantnetworkapplications.
Disadvantagesofstaticrouting:Itcannotautomaticallyadapttothechangesinthenetwork
topology.Thenetworkfailureorchangesintopologymaycausetherouteunreachableand
networkinterrupted.Then,youarerequiredtomanuallymodifythesettingofstaticrouting.
StaticRoutingperformsdifferentpurposesindifferentnetworkenvironments.
Whenthenetworkstructureiscomparativelysimple,thenetworkcanworknormally
onlywithStaticRouting.
Whileincomplexnetworkenvironment,StaticRoutingcanimprovetheperformanceof
networkandensurebandwidthforimportantapplication.
StaticRoutingcanbeusedinVPNexamples,mainlyforthemanagementofVPNroute.
3.5.1.1RoutingStatus
Fromnavigationpanel,selectRouting/StaticRouting,thenenter“RouteTablepage,asshownin
Figure356.
Figure356RoutingStatus
3.5.1.2StaticRouting
Fromnavigationpanel,selectRouting/StaticRouting,thenenter“StaticRouting,”page.
Add/deleteadditionalRouterstaticrouting.Normallyusersdonnotneedtoconfigurethisitem,
asshownin357.
Figure357StaticRouting
PagedescriptionisshowninTable331.
Table331StaticRoutingDescription
ParametersDescriptionDefault
Destinationaddress EnterthedestinationIPaddressneedtobereachedNone
SubnetMaskEnterthesubnetmaskofdestinationaddressneedtobe
reached
None
InterfaceTheinterfacethroughwhichthedatareachesthe
destinationaddress
None
GatewayIPaddressofthenextroutertobepassedbybeforethe
inputdatareachesthedestinationaddress
None
DistancePriority,smallervaluecontributestohigherpriorityNone
TrackIDSelectthedefinedTrackindexorIDNone
3.5.2DynamicRouting
Theroutingtableentryondynamicrouterisobtainedinaccordancewithcertainalgorithm
optimizationthroughtheinformationexchangebetweentheconnectedrouters,whilethe
routinginformationiscontinuouslyupdatingincertaintimeslotsoastoadapttothe
continuouslychangingnetworkandobtaintheoptimizedpathfindingeffectsatanytime.
InordertoachieveefficientpathfindingofIPpacket,IETFhasdevelopedavarietyof
pathfindingprotocols,includingOpenShortestPathFirst(OSPF)andRoutingInformation
Protocol(RIP)forAutonomousSystem(AS)interiorgatewayprotocol.Thesocalledautonomous
systemreferstothecollectionofhosts,routersandothernetworkdevicesunderthe
managementofthesameentity(e.g.schools,businesses,orISP)
3.5.2.1RoutingStatus
Fromnavigationpanel,selectRouting/DynamicRouting,thenenter“RouteTablepage,asshown
inFigure358.
Figure358RoutingStatus
3.5.2.2RIP
RIP(RoutingInformationProtocol)isarelativelysimpleinteriorgatewayprotocol(IGP),mainly
usedforsmallernetworks.ThecomplexenvironmentsandlargenetworksgeneraldonotuseRIP.
RIPusesHopCounttomeasurethedistancetothedestinationaddressanditiscalled
RoutingCost.InRIP,thehopcountfromtheroutertoitsdirectlyconnectednetworkis0andthe
hopcountofnetworktobereachedthrougharouteris1andsoon.Inordertolimitthe
convergencetime,thespecifiedRoutingCostofRIPisanintegerintherangeof0~15andhop
countlargerthanorequalto16isdefinedasinfinity,whichmeansthatthedestinationnetwork
orhostisunreachable.Becauseofthislimitation,theRIPisnotsuitableforlargescalenetworks.
Toimproveperformanceandpreventroutingloops,RIPsupportssplithorizonfunction.RIPalso
introducesroutingobtainedbyotherroutingprotocols.
ItisspecifiedinRFC1058RIPthatRIPiscontrolledbythreetimers,i.e.Periodupdate,Timeout
andGarbageCollection:
EachrouterthatrunsRIPmanagesaroutingdatabase,whichcontainsroutingentriestoreachall
reachabledestinations.Theroutingentriescontainthefollowinginformation:
Destinationaddress:IPaddressofhostornetwork.
Addressofnexthop:IPaddressofinterfaceoftherouter’sadjacentroutertobepassedby
onthewaytoreachthedestination.
Outputinterface:Theoutputinterfacefortheroutertoforwardpackage.
RoutingCost:Costfortheroutertoreachthedestination.
Routingtime:Thetimefromthelastupdateofrouterentrytothepresent.Eachtimethe
routerentryisupdated,theroutingtimewillberesetto0.
Fromnavigationpanel,selectRouting>>DynamicRouting,thenenter“RIP”page,asshownFigure
3591.
Figure3591RIP
AdvancedOptionsareshowninFigure3592.
Figure3592RIP
PagedescriptionisshowninTable332.
Table332RIPDescription
ParametersDescriptionDefault
EnableEnable/DisableDisable
UpdatetimerItdefinestheintervaltosendroutingupdates30
Timeouttimer
Itdefinestheroutingagingtime.Ifnoupdatepackageon
aroutingisreceivedwithintheagingtime,theroutings
RoutingCostintheroutingtablewillbesetto16.
180
ClearTimer
ItdefinesthetimefromthetimewhentheRoutingCost
ofaroutingbecomes16tothetimewhenitisdeleted
fromtheroutingtable.Inthetimeof
GarbageCollection,RIPuses16astheRoutingCostfor
sendingupdatesoftherouting.Incaseoftimeoutof
GarbageCollectionandtheroutingstillhasnotbeen
updated,theroutingwillbecompletelyremovedfrom
theroutingtable.
120
NetworkThefirstIPaddressandsubnetmaskofthesegmentNone
AdvancedOptions
DefaultPostClickEnable,thedefaultinformationwillenable
publishingDisable
DefaultMetricDefaultcostofroutertodestination1
Redirectdirectroute
Direct,Static,andOSProuteagreementintroducedto
RIProuteagreement
Disable
RedirectStatic
RoutEDisable
RedirectOSPRoutEDisable
AdvancedOptions‐Distance/MetricManagement
DistanceSetRIProutingadministrativedistance,priority,the
smallervalue,thepriority 120
IPaddressNetworknumberisthefirstIPaddressinnetwork
segmentNone
SubnetMaskSubnetmask,networknumberissubnetmaskofthefirst
IPaddressinnetworksegmentNone
AccessListApplicationoftheACLIDNone
Redirectrouting
metricRewritedefaultcostfromroutetothedestination None
Ingress/egress
filteringpolicySetredirectionroutefilteringpolicy(in/out)in
Interface SetInterfacerewritingtorouteNone
AccessListApplicationoftheACLIDNone
AdvancedOptions‐RouteFilteringPolicy
PolicyTypeSelectthetypeofpolicytoimplementAccesslist
PolicynameCustompolicynameNone
Ingress/egress
filteringpolicySelectpolicyappliedintheoutboundorinboundin
Interface SelectroutefilteringpolicyenforcementInterfaceNone
SendfiltrationAfterenabling,onlyRIPpacketsendtothedefault
routinginterface.Disable
AdvancedOptions‐Interface
PassiveInterfaceAfterenabling,onlyreceiveRIPpacket,nosendDisable
RIPsendversion SelectSendRIPpacketversionDefault
RIPReceiveversionChoosereceiveRIPpacketversionDefault
Horizontalsplit/
toxicityFlipSelectenablesplithorizonorpoisonreversefunctionNone
AuthenticationSelecttheinterfaceauthenticationmodeNone
Key FillinthecorrespondingkeyNone
AdvancedOptions‐Neighbor
IPaddressNeighborIPaddressNone
3.5.2.3OSPF
OpenShortestPathFirst(OSPF)isalinkstatusbasedinteriorgatewayprotocoldevelopedbyIETF.
RouterID
IfarouterwantstoruntheOSPFprotocol,thereshouldbeaRouterID.RouterIDcanbe
manuallyconfigured.IfnoRouterIDisconfigured,thesystemwillautomaticallyselectoneIP
addressofinterfaceastheRouterID.
Theselectionorderisasfollows:
IfaLoopbackinterfaceaddressisconfigured,thenthelastconfiguredIPaddressof
LoopbackinterfacewillbeusedastheRouterID;
IfnoLoopBackinterfaceaddressisconfigured,choosetheinterfacewiththebiggestIP
adressfromotherinterfacesastheRouterID.
NeighborandNeighboring
AfterthestartupofOSPFrouter,itwillsendoutHellopacketsthroughtheOSPFinterface.Upon
receiptofHellopacket,OSPFrouterwillchecktheparametersdefinedinthepacket.Ifbothare
consistent,aneighborrelationshipwillbeformed.Notallbothsidesinneighborrelationshipcan
formtheadjacencyrelationship.Itisdeterminedbasedonthenetworktype.Onlywhenboth
sidessuccessfullyexchangeDDpacketsandLSDBsynchronizationisachieved,theadjacencyin
thetruesensecanbeformed.LSAdescribethenetworktopologyaroundarouter,LSDBdescribe
entirenetworktopology.
Fromnavigationpanel,selectRouting/DynamicRouting,thenenterOSPF”page,asshownin
Figure360.
Figure360OSPF
PagedescriptionisshowninTable333.
Table333OSPFDescription
ParametersDescriptionDefault
EnableEnable/DisableDisable
RouterIDRouterIDoftheoriginatingtheLSANone
Interface
Interface Theinterface None
HelloInterval SendintervalofHellopacket.IfthetheHello10
timebetweentwoadjacentroutersisdifferent,
youcannotestablishaneighborrelationship.
DeadInterval
DeadTime.IfnoHellopacketisreceivedfrom
theneighbors,theneighborisconsideredfailed.
Ifdeadtimesoftwoadjacentroutersare
different,theneighborrelationshipcannotbe
established.
40
RetransmitInterval
WhentherouternotifiesanLSAtoitsneighbor,
itisrequiredtomakeacknowledgement.Ifno
acknowledgementpacketisreceivedwithinthe
retransmissioninterval,thisLSAwillbe
retransmittedtotheneighbor.
5
LSAtransmissiondelay
timer
OSPFpacketalsoneedtospendtimewhen
travelingonlinks,soLSAagingtime(age)before
transferringtoaddadelaytime,inthe
lowspeedlinksrequireconsiderationof
configuration.
1
Interface‐InterfaceAdvancedOptions
InterfaceNameConfigureOSPFinterfaceparametersNone
PassiveInterfaceAfterenabling,onlyreceiveRIPpacket,nosendDisable
InterfaceCostBydefault,aninterfacecomputesitscost
accordingtothebandwidth10
ProtocolPriorityConfigureOSPFrouterinterfacepriority10
Network
IPAddress IPAddressoflocalnetwork None
SubnetMask SubnetMaskofIPAddressoflocalnetworkNone
AreaIDAreaIDofrouterwhichoriginatingLSA None
3.5.2.4FilteringRoute
Clicknavigationpanel“Routing/DynamicRoutingmenu,enter“FilteringRouteinterface,as
showninFigure361.
Figure361FilteringRoute
PagedescriptionisshowninTable334.
Table334FilteringRouteDescription
ParameterDescriptionDefault
AccessControlList
AccesslistUserdefined None
ActionPermitanddenyPermit
AnyAddress Anyaddressafterclicking,nomatchingIPaddressand
subnetmaskagain
Disable
3.5.3MulticastRouting
Multicastroutingsetsupanacyclicdatatransmissionroutefromdatasourceendtomultiple
receivingends,whichreferstotheestablishmentofamulticastdistributiontree.Themulticast
routingprotocolisusedforestablishingandmaintainingthemulticastroutingandforrelaying
multicastdatapacketcorrectlyandefficiently.
3.5.3.1BasicSettings
Thebasicismainlytodefinethesourceofmulticastrouting.
Fromnavigationpanel,selectRouting/MulticastRouting,thenenter“Basic”page,asshownin
Figure362.
Figure362BasicSettings
PagedescriptionisshowninTable335.
Table335BasicSettingsDescription
ParametersDescriptionDefault
EnableOpen/CloseClose
SourceIPAddressofSource None
Netmask NetmaskofSource 255.255.255.0
3.5.3.2IGMP
IGMP,beingamulticastprotocolinInternetprotocolfamily,whichisusedforIPhosttoreportits
constitutiontoanydirectlyadjacentrouter,definesthewayformulticastcommunicationofhosts
amongstdifferentnetworksegmentswithpreconditionthattherouteritselfsupportsmulticast
andisusedforsettingandmaintainingtherelationshipbetweenmulticastmembersbetweenIP
hostandthedirectlyadjacentmulticastrouting.IGMPdefinesthewayformaintenanceof
memberinformationbetweenhostandmulticastroutinginanetworksegment.
Inthemulticastcommunicationmodel,sender,withoutpayingattentiontotheposition
informationofreceiver,onlyneedstosenddatatotheappointeddestinationaddress,whilethe
informationaboutreceiverwillbecollectedandmaintainedbynetworkfacility.IGMPissucha
signalingmechanismforahostusedinthenetworksegmentofreceivertotherouter.IGMP
informstheroutertheinformationaboutmembersandtherouterwillacquirewhetherthe
multicastmemberexistsonthesubnetconnectedwiththerouterviaIGMP.
Functionofmulticastroutingprotocol:
Discoveringupstreaminterfaceandinterfaceclosesttothesourceforthereasonthat
multicastroutingprotocolonlycarestheshortestroutetothesource.
Decidingtherealdownstreaminterfacevia(S,G).Amulticasttreewillbefinishedafterall
routersacquiretheirupstreamanddownstreaminterfaceswithrootbeingrouterdirectly
connectedwiththesourcehostandbranchesbeingroutersdirectlyconnectedviasubnet
withmemberdiscoveredbyIGMP.
Managingmulticasttree.Themessagecanbetransferredoncetheaddressofnexthopcan
beacquiredbyunicastrouting,whilemulticastreferstorelaymessagegeneratedbysource
toagroup.
Fromnavigationpanel,selectRouting/MulticastRouting,thenenter“IGMP”page,asshownin
Figure363.
Figure363IGMP
PagedescriptionisshowninTable336.
Table336IGMPDescription
ParametersDescriptionDefault
UplinkInterface
UplinkInterfacelinktouppernetworkdeviceinterfaceNone
DownlinkInterface
DownlinkInterfacelinktoterminalequipmentinterfacecellular1
UplinkInterfacelinktouppernetworkdeviceinterfacecellular1
3.6Tools
3.6.1PING
HelptoPINGinternetthroughroute.
Fromnavigationpanel,selectTools/Ping,thenenter“Ping”page,asshowninFigure364.
Figure364PING
PagedescriptionisshowninTable337.
Table337PINGDescription
ParametersDescriptionDefault
HostItrequiresthedestinationhostaddressofPING
detection
192.168.2.1
PingCountSetPingdetectioncount 4
PacketSize Setpacketsizeofpingdetection 32bytes
ExpertOptionsAdvancedparametersofpingcanbeusedNone
3.6.2RoutingDetection
Itisusedtodetectnetworkroutingfailure.
Fromnavigationpanel,selectTools/Traceroute,thenenter“Traceroutepage,asshowninFigure
365.
Figure365Traceroute
PagedescriptionisshowninTable338.
Table338TracerouteDescription
ParametersDescriptionDefault
HostHostaddressneedstodetect 192.168.2.1
MaxiumHopsSetthemaxiumhopsofroutingdetection 20
TimeoutSettimeoutofroutingdetection3secs
ProtocolSelectICMP/UDPUDP
ExpertOptions AdvancedparametersofpingcanbeusedNone
3.6.3LinkSpeedTest
Throughuploadanddownloadfiles,linkspeedcanbetested.
Fromnavigationpanel,selectTools/LinkSpeedTest,thenenter“LinkSpeedTest ”page,asshown
inFigure366.
Figure366LinkSpeedTest
3.7InstallationGuide
Simplifygeneralconfiguration,wheretherouterwithfast,simple,basicconfiguration,
configurationresultcannotbedisplayedhere,butviewitwhenfinishedinaspecific
correspondingconfigurationsetting.
3.7.1NewDial
Fromnavigationpanel"Wizards/NewCellular"menu,enter"NewCellular"page,asshownin
Figure367.
Figure367NewCellular
PagedescriptionisshowninTable339.
Table339NewCellularDescription
ParametersDescriptionDefault
APNSelectNewWANInterface3gnet
AccessnumberMobileoperatorprovidedialupparameters(pleasechoose
accordingtothelocaloperator)*99***1#
UsernameMobileoperatorprovidedialupparameters(pleasechoose
accordingtothelocaloperator)gprs
passwordMobileoperatorprovidedialupparameters(pleasechoose
accordingtothelocaloperator)
●●●●
Network
Address
ClickEnable,putprivateIPaddressconvertedintoapublicIP
addressDisable
Translation
3.7.2NewIPSecTunnel
Fromnavigationpanel"Wizards/NewIPSecTunnel"menu,enter"NewIPSecTunnel"page,as
showninFigure368.
Table368NewIPSecTunnel
PagedescriptionisshowninTable340.
Table340NewIPSecTunnelDescription
ParametersDescriptionDefault
Basic
TunnelNo.SetTunnelNo.1
InterfaceNameSelectInterfaceNamecellular1
PeerAddressSetVPNpeerIPNone
NegotiationModeOptionalmainmode,aggressivemode.(UsuallyMainmode
selectmainmode)
Localsubnet
addressSetIPSeclocalprotectionsubnetNone
LocalSubnetMaskSetIPSeclocalprotectionsubnetmask255.255.255.0
Peersubnet
addressSetIPSecpeerprotectionsubnetNone
PeersubnetmaskSetIPSecpeerprotectionsubnetmask255.255.255.0
Phase1
IKEPolicyOptional3DESMD5DH1or3DESMD5DH2,etc.3DESMD5DH2
IKELifeCycleSetIKELifeCycle86400sec
LocalIdentityType OptionalFQDN,USERFQDN,IPaddressIPaddress
LocalIndex
OnlyinFQDNandUSERFQDN.Fillinthe
appropriateidentificationaccordingtotheselected
identitytype(USERFQDNshouldbeastandard
mailboxformat)
None
PeerIdentityTypeOptionalFQDN,USERFQDN,IPaddressIPaddress
PeerIndex
OnlyinFQDNandUSERFQDN.Fillinthe
appropriateidentificationaccordingtotheselected
identitytype(USERFQDNshouldbeastandard
mailboxformat)
None
AuthenticationChoosetosharekeysanddigitalcertificatessharekeys
Key Authenticationmodeselectsharedkeysshowthe
feature.SetIPSecVPNagreementkeyNone
Phase2
IPSecPolicyOptional3DESMD596or3DES‐SHA196etc.3DESMD596
IPSecLifeCycleSetIPSecLifeCycle3600sec
Createinboundandoutboundrulestoeachtunnelcollection.Ifonlytocreateaoneway
connectionfilter,theruleisnotapplied.
3.8PersonalizationFeatures
Accordingtothespecificneedsofindividualcustomers,privatecustomfunctionscanbe
equippedtoInPortal.
3.8.1NginxServer
Setharddiskserverfunction.Afteropeningcaptiveportalloginb,usershareharddiskdata.
Fromnavigationpanel"PersonalizedFunction/Nginx"menu,enter"Nginx"page,asshownin
Figure369.
Figure369Nginx
3.8.2FileSynchronization
Fromnavigationpanel"PersonalizedFunction/FileSynchronization"menu,enter"File
Synchronization"page,asshowninFigure370.
Figure370FileSynchronization
PagedescriptionisshowninTable341.
Table341FileSynchronizationDescription
ParametersDescriptionDefault
TaskUserdefinedtasknameNone
ServerRsyncServerAddressNone
ServerDirectorySynchronizefilestoRsyncserveraddressNone
LocalDirectorySynchronizefilestolocaldirectoryNone
UsernameRsyncservernameNone
Password RsyncserverpasswordNone
3.8.3GPSLocationInformation
Fromnavigationpanel"PersonalizedFunction/GPSConfig"menu,enter"GPSConfig"page,
showninFigure371.
Figure371GPSSettings
PagedescriptionisshowninTable342.
Table342GPSConfigDescription
ParametersDescriptionDefault
Server uploadlocationinformationserverIPaddressNone
Port Uploadlocationinformationserverport80
PositioningtimeintervalSetpositioningtimeinterval60
UploadLocation
informationgapSetuploadLocationinformationgap60
3.8.4RoamingManagement
3.8.4.1RoamingManagement
Fromnavigationpanel“PersonalizedFunction/RoamingManagement"menu,enter"Roaming
Management"page,showninFigure372.
Figure372RoamingManagement
3.8.4.2UpgradefromAP
Fromnavigationpanel"PersonalizedFunction/RoamingManagement"menu,enter"SlaveAP
Upgrade"page,asshowninFigure373.
Figure373SlaveAPUpgrade
3.9Firewall
Withtheexpansionofnetworkandincreaseinflow,thecontrolovernetworksafetyandthe
allocationofbandwidthbecometheimportantcontentsofnetworkmanagement.Thefirewall
functionoftherouterimplementscorrespondingcontroltodataflowatentrydirection(from
Internettolocalareanetwork)andexitdirection(fromlocalareanetworktoInternet)according
tothecontentfeaturesofmessage(suchas:protocolstyle,source/destinationIPaddress,etc.)
andensuressafeoperationofrouterandhostinlocalareanetwork.
3.9.1AccessControlACL
ACL,namelyaccesscontrollist,implementspermissionorprohibitionofaccessforappointed
dataflow(suchasprescribedsourceIPaddressandaccountnumber,etc.)viaconfigurationofa
seriesofmatchingrulessoastofilterthenetworkinterfacedata.Aftermessageisreceivedby
portofrouter,thefieldisanalyzedaccordingtoACLruleappliedonthecurrentport.Andafter
thespecialmessageisidentified,thepermissionorprohibitionofcorrespondingpacketis
implementedaccordingtopresetstrategy.
ACLclassifiesdatapackagesthroughaseriesofmatchingconditions.Theseconditionscanbe
datapackages’sourceMACaddress,destinationMACaddress,sourceIPaddress,destinationIP
address,portnumber,etc.
ThedatapackagematchingrulesasdefinedbyACLcanalsobeusedbyotherfunctionsrequiring
flowdistinguish.
Fromnavigationpanel,selectFirewall/ACL,thenenter“ACL”page,asshowninFigure3741.
Figure3741AccessControlACL
Click<Add>toaddnewaccesscontrollist,asshowninFigure3742.
Figure3742AccessControlACL
PagedescriptionisshowninTable343.
Table343AccessControlDescription
ParametersDescriptionDefault
Type
StandardACLcanblockallcommunicationflowsfroma
network,orallowallcommunicationflowsfroma
particularnetwork,ordenyallcommunicationflowsofa
protocolstack(e.g.IP)of.
TheextendedACLprovidesawiderrangeofcontrolthan
thatprovidedbythestandardACL.Forexample,ifthe
networkadministratorwantsto"allowexternalWeb
communicationflowstopassthroughandrejectexternal
communicationflows,e.g.FTPandTeln et ”,theextended
ACLcanbeusedtoachievetheobjective.Thestandard
ACLcannotbecontrolledsoprecisely.
Extended
IDUserdefineNone
ActionPermit/Deny Permit
ProtocolAccessControlProtocolip
SourceIPAddress IPAddressofSourceNone
DestinationIP IPAddressofDestinationNone
DestinationIP
addressDestinationnetworkaddressNone
DestinationInvert
Mask DestinationaddressmaskinvertedNone
LoggingClickEnable,thesystemwillrecordaccesscontrolona
logDisable
Description EasytorecordcontrolaccessparametersonalogNone
NetworkInterfacelist
InterfaceNameSelectInterfaceNamecellular1
Rules Selectinbound,outboundandmanagementrulesnone
3.9.2NAT
NATcanachieveInternetaccessbymultiplehostswithintheLANthroughoneormorepublic
networkIPaddresses.ItmeansthatfewpublicnetworkIPaddressesrepresentmoreprivate
networkIPaddresses,thussavingpublicnetworkIPaddresses.
Fromnavigationpanel,selectFirewall/NAT,thenenter“NATpage,asshowninFigure3751.
Figure3751NAT
NATruleistoapplyACLtoaddresspool,onlymatchingtheACLaddressbeforeconversion.
Click<Add>toaddnewNATrules,asshowninFigure3752.
Figure3752NAT
PagedescriptionisshowninTable344.
Table344NATDescription
ParametersDescriptionDefault
Action
SNATSourceNATTranslateIPpacket'ssourceaddress
intoanotheraddress
DNATDestinationNAT:Mapasetoflocalinternal
addressestoasetoflegalglobaladdresses.
1:1NATTransferIPaddressonetoone.
SNAT
SourceNetwork
InsideInsideaddress
OutsideOutsideaddress
Inside
TranslationTypeSelecttheTranslationTypeIPtoIP
PrivatenetworkIPaddressreferstotheIPaddressofinternalnetworkorhost,whilepublic
networkIPaddressisagloballyuniqueIPaddressontheInternet.
RFC1918threeIPaddressblocksfortheprivatenetworkasfollows:
ClassA:10.0.0.0~10.255.255.255
ClassB:172.16.0.0~172.31.255.255
ClassA:192.168.0.0~192.168.255.255
TheaddresseswithintheabovethreerangeswillnotbeallocatedontheInternet.Therefore,
theycanbefreelyusedincompaniesorenterpriseswithouttheneedtomakeapplicationtothe
operatororregistrationcenter
3.10QoS
InthetraditionalIPnetwork,allpacketsaretreatedequallywithoutdistinction.Eachnetwork
deviceusesfirstinfirstoutstrategyforpacketprocessing.Thebesteffortnetworksendspackets
tothedestination,butitcannotguaranteetransmissionreliabilityanddelay.
QoScancontrolnetworktraffic,avoidandmanagenetworkcongestion,andreducepacket
droppingrate.Someapplicationsbringconveniencetousers,buttheyalsotakeupalotof
networkbandwidth.ToensureallLANuserscannormallygetaccesstonetworkresources,IP
trafficcontrolfunctioncanlimittheflowofspecifiedhostonlocalnetwork.
QoSprovidesuserswithdedicatedbandwidthanddifferentservicequalityfordifferent
applications,greatlyimprovingthenetworkservicecapabilities.Userscanmeetvarious
requirementsofdifferentapplicationslikeguaranteeinglowlatencyoftimesensitivebusiness
andbandwidthofmultimediaservices.
QoScanguaranteehighprioritydataframesreceiving,acceleratehighprioritydataframe
transmission,andensurethatcriticalservicesareunaffectedbynetworkcongestion.IR900
supportsfourservicelevels,whichcanbeidentifiedbyreceivingportofdataframe,Tagpriority
andIPpriority.
Fromnavigationpanel,selectQos/TrafficControl,thenenter“TrafficControl”page,asshownin
Figure376.
Figure376QoS
PagedescriptionisshowninTable345.
Table345QoSDescription
ParametersDescriptionDefault
Type
NameNameName
AnyPackets ClickStartupforflowcontroltoanypackets Disable
Source SourceaddressofflowcontrolN/A
Destination DestinationaddressofflowcontrolN/A
Protocol ClicktoselectprotocolstyleN/A
Policy
NameNameofuserdefinedflowcontrolstrategyN/A
Classifier NameofstyledefinedaboveN/A
GuaranteedBandwidth
Kbps
Userdefinedguaranteedbandwidth
N/A
MaximumBandwidthKbpsUserdefinedmaximumbandwidthN/A
LocalPriorityLocalpriorityofselectionstrategyN/A
ApplyQos
InterfaceSelectionofflowcontrolinterfacecellular1
IngressMaxbandwidth
Kbps
Userdefine,biggerthanmaximumbandwidthof
inputstrategy
N/A
EgressMaxbandwidthKbps
Userdefine,biggerthanmaximumbandwidthof
outputstrategy
N/A
IngressPolicy NameofpolicydefinedaboveN/A
EgressPolicyNameofpolicydefinedaboveN/A
3.11VPN
VPNisanewtechnologythatrapidlydevelopedinrecentyearswiththeextensiveapplicationof
Internet.Itisforbuildingaprivatededicatednetworkonapublicnetwork.'Virtuality"mainly
referstothatthenetworkisalogicalnetwork.
TwoBasicFeaturesofVPN:
Private:theresourcesofVPNareunavailabletounauthorizedVPNusersontheinternet;
VPNcanensureandprotectitsinternalinformationfromexternalintrusion.
Virtual:thecommunicationamongVPNusersisrealizedviapublicnetworkwhich,
meanwhilecanbeusedbyunauthorizedVPNuserssothatwhatVPNusersobtainedisonly
alogisticprivatenetwork.ThispublicnetworkisregardedasVPNBackbone.
FundamentalPrincipleofVPN
ThefundamentalprincipleofVPNindicatestoencloseVPNmessageintotunnelwithtunneling
technologyandtoestablishaprivatedatatransmissionchannelutilizingVPNBackbonesoasto
realizethetransparentmessagetransmission.
Tunnelingtechnologyenclosestheotherprotocolmessagewithoneprotocol.Also,encapsulation
protocolitselfcanbeenclosedorcarriedbyotherencapsulationprotocols.Totheusers,tunnelis
logicalextensionofPSTN/linkofISDN,whichissimilartotheoperationofactualphysicallink.
ThecommontunnelprotocolsincludeL2TP,PPTP,GRE,IPSec,MPLS,etc.
3.11.1IPSec
AmajorityofdatacontentsarePlaintextTransmissionontheInternet,whichhasmanypotential
dangerssuchaspasswordandbankaccountinformationstolenandtampered,useridentity
imitated,sufferingfrommaliciousnetworkattack,etc.AfterdisposalofIPSeconthenetwork,it
canprotectdatatransmissionandreduceriskofinformationdisclosure.
IPSecisagroupofopennetworksecurityprotocolmadebyIETF,whichcanensurethesecurityof
datatransmissionbetweentwopartiesontheInternet,reducetheriskofdisclosureand
eavesdropping,guaranteedataintegrityandconfidentialityaswellasmaintainsecurityofservice
transmissionofusersviadataoriginauthentication,dataencryption,dataintegrityand
antireplayfunctionontheIPlevel.
IPSec,includingAH,ESPandIKE,canprotectoneandmoredateflowsbetweenhosts,between
hostandgateway,andbetweengateways.ThesecurityprotocolsofAHandESPcanensure
securityandIKEisusedforciphercodeexchange.
IPSeccanestablishbidirectionalSecurityAllianceontheIPSecpeerpairstoformasecureand
interworkingIPSectunnelandtorealizethesecuretransmissionofdataontheInternet.
3.11.1.1IPSecPhase1
IKEcanprovideautomaticnegotiationciphercodeexchangeandestablishmentofSAforIPSecto
simplifytheoperationandmanagementofIPSec.TheselfprotectionmechanismsofIKEcan
completeidentityauthenticationandkeydistributioninaninsecurenetwork.
Fromnavigationpanel,selectVPN/IPSec,thenenter“IPSecPhase1”page,asshowninFigure
377.
Figure377IPSecPhase1
PagedescriptionisshowninTable346.
Table346IPSecPhase1Description
Parameters DescriptionDefault
Keyring
Name Userdefinekey N/A
IPAddress EndtoendIPaddressN/A
SubnetMaskEndtoendsubnetmaskN/A
KeyUserdefinekeycontentN/A
IKEPolicy
Identification PolicyidentificationofuserdefinedIKE N/A
Authentication Alternativeauthentication:sharedkeyanddigitalcertificate
Shared
key
Encryption
3des:encryptplaintextwiththreeDESciphercodesof64bit
des:encrypta64bitplaintextblockwith64bitciphercode
Aes:encryptplaintextblockwithAESAlgorithmwithcipher
codelengthof128bit,192bitor256bit
3des
Hash md5:inputinformationofarbitrarylengthtoobtain128bitmd5
messagedigest.
sha1:inputinformationwithshorterlengthofbittoobtain
160bitmessagedigest.
Comparingboth,md5isfasterwhilesha1issafer.
DiffieHellman
KeyExchange
Threeoptions:Group1,Group2andGroup5Group2
LifetimeActivetimeofpolicy 86400
ISAKMPProfile
Name NameofuserdefinedISAKMPProfileN/A
Negotiation
Mode
Mainmode:asanexchangemethodofIKE,mainmodeshallbe
establishedinthesituationwherestricteridentityprotectionis
required.
Aggressivemode:asanexchangemethodofIKE,aggressive
modeexchangingfewermessage,canacceleratenegotiationin
thesituationwhereordinaryidentityprotectionisrequired.
Main
mode
LocalIDTypeSelecttypeoflocalidentification
IP
Address
LocalIDThelocalIDcorrespondingtotheselectedlocalIDN/A
RemoteID
Type
SelecttypeofRemoteID
IP
Address
RemoteID
TheRemoteIDcorrespondingtotheselectedpeer
identification
N/A
Policy ThedefinedstrategyidentificationintheIKEStrategylist
N/A
KeyRingThedefinedkeysetinthekeysetlist
N/A
DPDInterval
UsedfordetectionintervalofIPSecneighborstate.
AfterinitiatingDPD,IfreceivingendcannotreceiveIPSec
cryptographicmessagesentbypeerendwithinintervalof
N/A
triggeringDPD,receivingendcanmakeDPDcheck,send
requestmessagetooppositeendautomatically,detectwhether
IKEpeerpairexists.
DPDTimeout
ReceivingendwillmakeDPDcheckandsendrequestmessage
automaticallytooppositeendforcheck.Ifitdoesnotreceive
IPSeccryptographicmessagefrompeerendbeyondtimeout,
ISAKMPProfilewillbedeleted.
N/A
Thesecuritylevelofthreeencryptionalgorithmsrankssuccessively:AES,3DES,DES.The
implementationmechanismofencryptionalgorithmwithstrictersecurityiscomplexandslow
arithmeticspeed.DESalgorithmcansatisfytheordinarysafetyrequirements.
3.11.1.2IPSecPhase2
Fromnavigationpanel,selectVPN>>IPSec,thenenter“IPSecPhase2”page,asshowninFigure
378.
Figure378IPSecPhase2
PagedescriptionisshowninTable347.
Table347IPSecIPSecPhase2Description
ParametersDescriptionDefault
Name UserdefineTransformSetname N/A
Encapsulation
Chooseencapsulationformsofdatapacket
AH:protectintegrityandauthenticityofdatapacketfrom
esp
hackerinterceptingdatapacketorinsertingfalsedata
packetontheinternet.
ESP:encrypttheuserdataneedingprotection,andthen
encloseintoIPpacketforthepurposeofconfidentialityof
data.
Encryption Threeoptions:AES,3DES,DES3des
AuthenticationAlternativeauthentication:md5andsha1md5
IPSecMode
TunnelMode:besidessourcehostanddestinationhost,
specialgatewaywillbeoperatedwithpasswordtoensure
thesafetyfromgatewaytogateway.
TransmissionMode:sourcehostanddestinationhostmust
directlybeoperatedwithallpasswordsforthepurposeof
higherworkefficiency,butcomparingwithtunnelmodethe
securitywillbeinferior.
Tunnel
Mode
3.11.1.3IPSecConfiguration
Fromnavigationpanel,selectVPN/IPSec,thenenter“IPSecSettingpage,asshownin
Figure379.
Figure379IPSecConfiguration
PagedescriptionisshowninTable348.
Table348IPSecConfigurationDescription
ParametersDescriptionDefault
IPSecProfile
NameUserdefineIPSecProfilenameN/A
ISAKMPProfile
ISAKMPProfilenamesdefinedinthefirststageof
parametersofIPSec
N/A
TransformSet
TransformSetdefinedinthefirststageofparametersof
IPSec
N/A
PerfectForward
Security(PFS)
Meanstherevealofoneciphercodewillnotendanger
informationprotectedbyotherciphercodes.
Disable
LifetimeLifetimeofIPSecProfile3600
RekeyMargin(S)Reconnectiontimeforthesecondstage540
RekeyFuzz()
Deviationpercentageofthereconnectiontimeforthe
secondstage
100
SIMCardBinding Withthisfunctionactivated,successfuldialingoftheDisable
cardwithwhichIPSecisbondedisapreconditionforthe
useofIPSec.
CryptoMap
NameUserdefinenameofcryptomapN/A
IDUserdefineIDofcryptomapN/A
PeerAddressPeerIPAddressN/A
ACLIDIDofACLdefinedinACLoffirewallN/A
ISAKMPProfile
ISAKMPProfilenamesdefinedinthefirststageof
parametersofIPSec
N/A
TransformSet
TransformSetdefinedinthefirststageofparametersof
IPSec
N/A
PerfectForward
Security(PFS)
Meanstherevealofoneciphercodewillnotendanger
informationprotectedbyotherciphercodes.
Disable
LifetimeValidityofCryptoMap3600
RekeyMargin(S)Reconnectiontimeforthesecondstage540
RekeyFuzz()
Deviationpercentageofthereconnectiontimeforthe
secondstage
100
ParametersDescriptionDefault
Interface<==>CryptoMap
MAPInterface SelectInterfaceNamecellular1
MapName
SelectfromdefinednamesofCryptoMap.Onenameis
matchedwithseveralmarks.
none
3.11.1.4IPSecVPNConfigurationExample
BuildingasecurechannelbetweenRouterAandRouterBtoensurethesecuredataflow
betweenCustomerBranchA‘ssubnet(192.168.1.0/24)andCustomerBranchB‘ssubnet
(172.16.1.0/24).SecurityprotocolisESP,theencryptionalgorithmis3DES,andauthentication
algorithmisSHA.
Thetopologyisasfollows:
ConfigurationSteps:
(1)RouterASettings
Step1:IPSecSettingPhase1
Fromnavigationpanel,selectVPN/IPSec,thenenterIPSecSettingPhase1page,asshown
below.
NoneedtofillinLocalIDTypeandRemoteIDType.
Step2:IPSecSettingPhase2
Fromnavigationpanel,selectVPN/IPSec,thenenter“IPSecSettingPhase2”page,asshown
below.
Step3:IPSecSetting
Fromnavigationpanel,selectVPN/IPSec,thenenter“IPSecSettingpage,asshownbelow.
IPSecProfilesettingisneededonlywhenitsDMVPN.
(2)RouterBSettings
Step1:IPSecSettingPhase1
Fromnavigationpanel,selectVPN/IPSec,thenenter“IPSecSettingPhase1”page,asshown
below.
Step2:IPSecSettingPhase2
Fromnavigationpanel,selectVPN/IPSec,thenenter“IPSecSettingPhase2”page,asshown
below.
Step3:IPSecSetting
Fromnavigationpanel,selectVPN/IPSec,thenenter“IPSecSettingpage,asshownbelow.
(3)VPNStatusChecking
Fromnavigationpanel,selectVPN/IPSec,thenenter“IPSecStatus”page,asshownbelow.
3.11.2GRE
GenericRouteEncapsulation(GRE)definestheencapsulationofanyothernetworklayerprotocol
onanetworklayerprotocol.GREcouldbeusedastheL3TPofVPNtoprovideatransparent
transmissionchannelforVPNdata.Insimpleterms,GREisatunnelingtechnologywhichprovides
achannelthroughwhichencapsulateddatamessagecouldbetransmittedandencapsulationand
decapsulationcouldberealizedatbothends.GREtunnelapplicationnetworkingshownasthe
followingfigure:
AlongwiththeextensiveapplicationofIPv4,tohavemessagesfromsomenetworklayerprotocol
transmittedonIPv4network,thosemessagescouldbyencapsulatedbyGREtosolvethe
transmissionproblemsbetweendifferentnetworks.
InfollowingcircumstancesGREtunneltransmission:
GREtunnelcouldtransmitmulticastdatapacketsasifitwereatruenetworkinterface.
SingleuseofIPSeccannotachievetheencryptionofmulticast.
Acertainprotocoladoptedcannotberouted.
AnetworkofdifferentIPaddressshallberequiredtoconnectothertwosimilarnetworks.
GREapplicationexample:combinedwithIPSectoprotectmulticastdata
GREcanencapsulateandtransmitmulticastdatainGREtunnel,butIPSec,currently,couldonly
carryoutencryptionprotectionagainstunicastdata.Incaseofmulticastdatarequiringtobe
transmittedinIPSectunnel,aGREtunnelcouldbeestablishedfirstforGREencapsulationof
multicastdataandthenIPSecencryptionofencapsulatedmessagesoastoachievethe
encryptiontransmissionofmulticastdatainIPSectunnel.
Fromnavigationpanel,selectVPN/GRE,thenenter“GRE”page,asshowninFigure380.
Figure380GRESettings
PagedescriptionisshowninTable349.
Table349GREDescription
ParametersDescriptionDefault
Enable Clicktoopen Open
Index SetGREtunnelname None
NetworkTypeSelectGREnetworktype peerto
peer
LocalVirtualIPSetLocalVirtualIPAddressNone
PeerVirtualIPSetPeerVirtualIPAddressNone
SourceTypeSelectsourcetypeandsettheaccordingIPaddressorinterfaceIP
LocalIPSetLocalIPAddressNone
PeerIPSetPeerIPAddress None
KeySetthekeyoftunnelNone
MTUSetthemaximumtransmission,unitinbytesNone
EnableNHRP
NextHopResolutionProtocol,usedtoconnectto
nonbroadcastmultipleaccess(NBMA)formulasubnetwork
sourcestation(hostorrouter)decidedtoreach"NBMAnext
hop"internetworkinglayeraddressandNBMAsubnetwork
betweenthedestinationstationaddress.
Enable
Description AdddescriptionNone
3.11.3L2TP
L2TP,oneofVPDNTPs,hasexpandedtheapplicationsofPPP,knownasaveryimportantVPN
technologyforremotedialinusertoaccessthenetworkofenterpriseheadquarters.
L2TP,throughdialupnetwork(PSTN/ISDN),basedonnegotiationofPPP,couldestablishatunnel
betweenenterprisebranchesandenterpriseheadquarterssothatremoteuserhasaccesstothe
networkofenterpriseheadquarters.PPPoEisapplicableinL2TP.Throughtheconnectionof
EthernetandInternet,aL2TPtunnelbetweenremotemobileofficersandenterprise
headquarterscouldbeestablished.
L2TPLayer2TunnelProtocol,encapsulatesprivatedatafromusernetworkattheheadofL2PPP.
Noencryptionmechanismisavailable,thusIPSesisrequiredtoensuresafety.
 MainPurpose:branchesinotherplacesandemployeesonabusinesstripcouldaccessto
thenetworkofenterpriseheadquarterthroughavirtualtunnelbypublicnetworkremotely.
Fromnavigationpanel,selectVPN/L2TP,thenenter“L2TPClient”page,asshowninFigure381.
Figure381L2TPClient
PagedescriptionisshowninTable350.
Table350L2TPClientDescription
ParametersDescriptionDefault
L2TPClass
NameUserdifineL2TPClassNameNone
AuthenticationClickEnable,peerauthenticationisrequiredtonetwork
connectionwhenenable.Disable
HostNameNetworkconnectiontolocalhostname,notto
configure.None
Tunnel
Authenticationkey
Whenthetunnelmustbeconfiguredtoenablethe
authentication,clickauthenticationkey,oryouwillnot
needtoconfigure.
None
PseudowireClass
Name UserdifinePseudowireClassNameNone
L2TPClassL2TPClassnameNone
SourceInterfaceSeclectsourceinterfacenamecellular1
L2TPTunnel
Enable Clicktoenable Enable
IndexAutomaticgenerated1
L2TPServerSetL2TPServeraddressNone
PseudowireClassPseudowireClassnameNone
AuthenticationType SelectAuthenticationType Auto
UsernamePeerServerusername None
PasswordPeerServerpasswordNone
LocalIPAddress SetlocalIPaddress,orautomaticallyallocatedbypeer
server.
None
RemoteIPAddressSetremoteIPaddres,ornotNone
3.11.4OPENVPN
SinglepointparticipatingintheestablishmentofVPNisallowedtocarryoutIDverificationby
presetprivatekey,thirdpartycertificateorusername/password.OpenSSLencryptionlibraryand
SSLv3/TLSv1protocolaremassivelyused.
InOpenVpn,ifauserneedstoaccesstoaremotevirtualaddress(addressfamilymatchingvirtual
networkcard),thenOSwillsendthedatapacket(TUNmode)ordataframe(TAPmode)tothe
visualnetworkcardthroughroutingmechanism.Uponthereception,serviceprogramwill
receiveandprocessthosedataandsendthemoutthroughouternetbySOCKET,owingtowhich,
theremoteserviceprogramwillreceivethosedataandcarryoutprocessing,thensendthemto
thevirtualnetworkcard,thenapplicationsoftwarereceiveandaccomplishacomplete
unidirectionaltransmission,viceversa.
Fromnavigationpanel,selectVPN/OPENVPN,thenenter“OPENVPNClient”page,asshownin
Figure382.
Figure382OPENVPNClient
PagedescriptionisshowninTable351.
Table351OPENVPNOPENVPNClientDescription
ParameterDescriptionDefault
EnableClickEnableEnable
IDSetchannelIDNone
ServerIPAddressSetpeerserverIPaddresssNone
PortNumberSetpeerserverportnumber1194
AuthenticationType Selectandconfigureauthenticationtypeparameters
oftypecertification
User
name/Password
UsernameKeepconsistencywithserver None
Password KeepconsistencywithserverNone
Channeldescription userdefinechanneldescriptionNone
AdvancedOptions
SourcePortSelectsourceportnameNone
NetworkTypeSelectnetworktypenet30
PortTypeSelectdataformissuedfromtheinterface.tun‐
packet,tap‐dataframetun
ProtocolType Keepconsistencywithserverprotocoludp
AdvancedOptions
Encryption
AlgorithmkeepconsistencywithserverDefault
LZOCompressionClickEnableOff
ConnectionTesting
Interval
Setconnectingtestingtimeinterval
None
ConnectionTesting
Overtime
Setconnectingtestingovertime
None
Expert
Configuration
Setexpertoption:blankadvisable
None
Importconfigurationscanbedirectlyimportedintotheconfigureddocumentsgeneratedfrom
backendserverandmanualconfigurationofOPENVPNcustomerendparameterisinnoneed
afterimport.
3.11.5CertificateManagement
Fromnavigationpanel,selectVPN/CertificateManagement,thenenter“Certificate
Management”page,asshowninFigure383.
Figure383CertificateManagement
PagedescriptionisshowninTable352.
Table352CertificateManagementDescription
ParameterDescriptionDefault
Forcedtoreapply
Ifthecertificatehasnotexpired,butneedtoreapply,click
forcedtoreapply,reconfigurethecertificaterequest
parameter.
Disable
RequestStatussuccessfulapplication,"RequestStatus"shows:
CompletionInitiation
Certificate
ProtectionKey
Setcertificateprotectionkey
None
Certificate
ProtectionKey
Confirmation
Confirmcertificateprotectionkey None
ServerURLSetcertificateserverIPNone
CertificatenameSetcertificatenameNone
FQDNSetfulldomainnameNone
UnitName1Setunitname1None
UnitName2Setunitname2None
DomainName SetdomainnameNone
SerialNumberSetapplicationcertificateserialnumberNone
Authentication
PasswordSetauthenticationpasswordNone
Authentication
Password
Confirmation
Confirmauthenticationpassword
None
HostIPSetrouteraddressintheuseofcertificateapplicationNone
RSAKeylengthSetRSAkeylength1024
QueryIntervalSetqueryinterval60sec
QueryTimeoutSetquerytimeout3600sec
3.12ConfigurationWizard
AfterlogintheconfigurationpageviaWeb,click“ConnectInternet”toenterconfigurationpage
below:
Figure3121ConnectInternet
Pagedescription:
Table3121ConnectInternetConfigurationDescription
ParametersDescriptionDefault
InterfaceType:3G/LTE,ADSL,DHCPandStaticIPAddress
3G/LTE
APNProvidedbylocaloperator3gnet
UsernameProvidedbylocaloperatorgprs
PasswordProvidedbylocaloperatorgprs
DialedNumbersProvidedbylocaloperator*99***1#
ADSL
UsernameProvidedbylocaloperatorN/A
PasswordProvidedbylocaloperatorN/A
NoconfigurationforDHCP
StaticIPAddress
IPAddress Userdefine N/A
SubnetmaskUserdefine255.255.255.0
GatewayUserdefineN/A
PrimaryDNSUserdefineN/A
SecondaryDNSUserdefineN/A
Savetheconfigurationandclick<NextStep>toenter“CloudPlatform”configurationpageas
shownbelow:
Figure3122CloudManagementPlatform
Table3122CloudManagementPlatformConfigurationDescription
ParametersDescriptionDefault
Platform
Address
Theaddressandportnumberofcloud
platformrainbow.inhand.com.cn80
DemoModeClicktoenableDisable
4.ApplicationScenarios
PlaceonabusoneInhandIPortal3000server,usingWIFIwirelesscoverageinsidethecar,built
3G/4GmoduletoaccesstheInternet.Passengers’smartphones,tabletandnotebooksandother
intelligentterminalaccesstotheWIFIhotspot,InPortal3000withPortalauthenticationmethod
pushspecifiedpagetothemobileterminal,toprovideinformation,downloads,entertainment
andotherinformationservicesandInternetservices.Informationservicesavailableatthelocal
storeInPortal3000enhanceuseraccessexperience,synchronousupdateCenterandlocal
contentvia3G/4G.

Appendix1Troubleshooting
Thismanualdescribesonlyasimpleroutertroubleshootingmethod,ifstillcannotruleout,you
cangettheservicethroughTable11.
1) CannotlogonlocallyrouterthroughWebsettingpage?
useMSDOSPingcommandtocheckthenetworkconnection
a.Ping127.0.0.1usedtocheckthecomputermanagementTCP/IPprotocolisinstalled.
b.PingcollectiontoFEinterfaceIPaddresswhichdirectlyconnectedtorouter,usedto
checkwhethercollectionofmanagementcomputertorouter.
Numberofusersallowedtomanagetherouterhasreachedthemaximum(foruptofour
userstosimultaneouslylog),pleasetryagainlater.
PleasechecktheWebbrowserissetupaproxyserverordialupconnection,ifany,unset.
SeeabovePCfirewallsettingsareusedtoconfiguretherouter,whethershieldingfunction.
PleasecheckwhetherIEisequippedwiththirdpartyplugins(eg:3721,IEpartner,etc.)itis
recommendedtoconfigureafteruninstalling.
2) InPortalispoweredon,butcannotaccessInternet?
Pleasecheck
WhethertheInPortalisinsertedwithaSIMcard.
WhethertheSIMcardisenabledwithdataservice,whethertheserviceoftheSIMcardis
suspendedbecauseofanoverduecharge.
Whetherthedialupparameters,e.g.APN,dialupnumber,account,andpasswordare
correctlyconfigured.
WhethertheIPAddressofyourcomputeristhesamesubnetwithInPortalandthegateway
addressisInPortalLANaddress.
3) LANusersdroppedcable,cannotaccesstheInternet?
Checkswitchcablecollectedtorouter,andWANportnetworkcable,ifthereisloosening.
Logintotherouter'sWebsetuppage,checkaccesscontrollist,tocheckwhethertheIP
addressofasegmentisnotallowedtoaccesstheInternet.
4) InPortalispoweredon,haveapingtodetectInPortalfromyourPCandfindpacketloss?
Pleasecheckifthenetworkcrossovercableisingoodcondition.
5) ForgetthesettingafterrevisingIPaddressandcannotconfigureInPortal?
Method1:connectInPortalwithserialcable,configureitthroughconsoleport.
Method2:InPortalispoweredon,pressandholdRESETResetbutton(untilERRORlights),
releasetheRESETbutton(ERRORlampisoff),pressandholdtheRESETbuttonagain(untilthe
ERRORindicatorblinks),andyoucanrestorethefactorydefaultsettings.
Afterapplyingtheabovetwomethods,configuretheInPortal.
6) AfterInPortalispoweredon,itfrequentlyautorestarts.Whydoesthishappen?
Pleasecheck:
Whetherthemoduleworksnormally.
WhethertheInPortalrisinsertedwithaSIMcard.
WhethertheSIMcardisenabledwithdataservice,whethertheserviceoftheSIMcardis
suspendedbecauseofanoverduecharge.
Whetherthedialupparameters,e.g.APN,dialupnumber,account,andpasswordare
correctlyconfigured.
Whetherthesignalisnormal.
Whetherthepowersupplyvoltageisnormal.
7) InPortalispoweredon,butthePowerLEDisnoton?
Pleasecheck:
Checkthefuseisburnedout.
Checksupplyvoltage,andthepolarityisconnectedcorrectly.
8) InPortalispoweredon,connectedtothePC,WhyEthernetportlightisnoton?
Pleasecheck:
Checkthenetworkcableisnormal.
NICcharacteristiconthePCissetto10/100M,fullduplex.
9) InPortalispoweredon,whenconnectedwithPC,theNetworkLEDisnormalbutcannot
haveapingdetectiontotheInPortal?
CheckiftheIPAddressofthePCandInPortalareinthesamenetworksegmentandInPortalIPas
gatewayaddress.
10) InPortaldialupalwaysfails,Icannotfindoutwhy?
PleaserestoreInPortaltofactorydefaultsettingsandconfiguretheparametersagain.
Table11SalesService
TroubleDescriptionObtainservice
Hardware
failure
Forexample:InPortaldoesnotappearnormal
power,didnotplugthenetworkcablewhile
Ethernetportlightwaslitandotherissues.
PleasecontactInhand
TechnicialSupportHotline
forhelp:01064391099
Software
Prolem
Forexample:InPortalfeatureisunavailable,
abnormalorconfigurationadvice.
PleasecontactInhand
TechnicialSupportHotline
forhelp:01064391099

Appendix2InstructionofCommandLine
OperatingstatusLED:
POWERSTATUSWARNERROR
Description
Thepower
LED(red)
StatusLED
(green)
AlarmLED
(yellow)
Error
LED(red)
onononoffPowerstatus
onblinkonoffPowerSuccess
onblinkblinkoffDialing
onblinkoffoffDialingSuccess
onblinkblinkblinkBeingupgraded
onblinkonblinkResetSuccess
SignalStatusLEDandDescription:
Signal
Status
GreenLED1
Signal
Status
GreenLED2
Signal
Status
GreenLED3
Description
offoffoffNosignalwasdetected
onoffoff
19signalcondition(inthiscasesignalconditions
describeproblems,pleasechecktheantennais
installedintact,thesignalsituationintheregionis
good)
ononoff
1019signalcondition(inthiscaseillustratesignal
statusisnormal,InPortalcanbeusednormally)
ononon
2031signalcondition(inthiscaseillustratethe
signalingoodcondition)
EthernetPortStatusLEDandDescription:
GreenLEDDescription
onThenetworkportis100M,inanormalstate,nodatatransmission
blinkThenetworkportis100M,inanormalstate,indatatransmission
offNoconnection
MODEMLEDandDescription
MODEMGreenLEDDescription
onAlreadydialed
blinkNotdailed
POWERLEDandDescription
POWERRedLEDDescription
onNomalpowerconnection
offNopowerconnection
WLANLEDandDescription
WLANGreenLEDDescription
onWLANonfunction
offWLANofffunction
FCCSTATEMENT
1.ThisdevicecomplieswithPart15oftheFCCRules.Operationissubjecttothefollowingtwo
conditions:
(1)Thisdevicemaynotcauseharmfulinterference.
(2)Thisdevicemustacceptanyinterferencereceived,includinginterferencethatmaycause
undesiredoperation.
2.Changesormodificationsnotexpresslyapprovedbythepartyresponsibleforcompliance
couldvoidtheuser'sauthoritytooperatetheequipment.
NOTE: This equipment has been tested and found to comply with the limits for a
Class A digital device, pursuant to part 15 of the FCC Rules. These limits are
designed to provide reasonable protection against harmful interference when the
equipment is operated in a commercial environment. This equipment generates, uses,
and can radiate radio frequency energy and, if not installed and used in accordance
with the instruction manual, may cause harmful interference to radio communications.
Operation of this equipment in a residential area is likely to cause harmful
interference in which case the user will be required to correct the interference at his
own expense.
InHandNetworks
7926JonesBranchDr.Suite110
McLean,Virginia22102
USA
T:+17033482988
F:+17033482988
info@inhandnetworks.com
www.inhandnetworks.com
InHandNetworks
InHandNetworksprovidesreliable,securedandintelligent
M2Msolutionforelectricpower,industrialautomation,
commercialandmedicaldevices.Wearerecognizedby
worldclasscustomersandpartnersandprovenbyalarge
installbase.

InHandNetworkshasbecomeleaderinindustrialgrade
networktechnologybyprovidingindustrialcellularrouters,
industrialEthernetswitches,wirelesssensornetwork
devicesandcloudbasedM2Mplatforms.
Connectingdevices,enablingservice.

Navigation menu