United Bus Tech WIFUN1050 Vehicle Wi-Fi Media Server User Manual UBT

United Bus Tech, Inc. Vehicle Wi-Fi Media Server UBT

User Manual

WIFUN1050VehicleWiFiMediaServer
User’sManual
©2015UBTInc.Allrightsreserved.
Republicationwithoutpermissionisprohibited.

WIFUN1050User’sManual
CopyrightNotice
Copyright©2015UBTInc.
Allrightsreserved.
Reproductionwithoutpermissionisprohibited.
Trademarks
UBTisaregisteredtrademarkofUnitedBusTech.Otherregisteredmarkscitedinthismanual
representedtheirrespectivecompanies.
Disclaimer
Informationinthisdocumentissubjecttochangewithoutnoticeanddoesnotrepresentan
obligationonthepartofUnitedBusTech.
Thisusermanualmayincludeintentionaltechnicalortypographicalerrors.Changesare
periodicallymadetothemanualtocorrectsucherrors,andthesechangesarenotinformedin
neweditions.
TechnicalSupportContactInformation
UnitedBusTechnology
info@ubt.io

TableofContents
WIFUN1050USER’SMANUAL...................................................................................................2
1.WIFUN1050INTRODUCTION..........................................................................................................6
1.1Overview.............................................................................................................................6
1.2Features...............................................................................................................................6
2.ESTABLISHNETWORKCONNECTION...................................................................................................9
2.1EstablishNetworkConnection............................................................................................9
2.1.1AutomaticacquisitionofIPaddress(recommended)..................................................9
2.1.2SetastaticIPaddress.................................................................................................12
2.2ConfirmthatthenetworkbetweenthesupervisoryPCandrouterisconnected............13
2.3CanceltheProxyServer....................................................................................................15
3.WEBCONFIGURATION..................................................................................................................17
3.1LogintheWebSettingPageofRouter..............................................................................17
3.2Management.....................................................................................................................18
3.2.1System........................................................................................................................18
3.2.1.1SystemStatus......................................................................................................18
3.2.1.2BasicSettings.......................................................................................................19
3.2.2SystemTime...............................................................................................................19
3.2.2.1SystemTime........................................................................................................20
3.2.2.2SNTPClientPort..................................................................................................20
3.2.3AdminAccess.............................................................................................................
22
3.2.3.1Createauser.......................................................................................................22
3.2.3.2ModifyaUser......................................................................................................23
3.2.3.3RemoveUsers......................................................................................................23
3.2.3.4ManagementService..........................................................................................24
3.2.4AAA.............................................................................................................................26
3.2.4.1Radius..................................................................................................................27
3.2.4.2Tacacs+................................................................................................................28
3.2.4.3LDAP....................................................................................................................29
3.2.4.4AAASettings........................................................................................................30
3.2.5ConfigurationManagement.......................................................................................32
3.2.6SNMP..........................................................................................................................33
3.2.6.1SNMP...................................................................................................................35
3.2.6.2SnmpTrap............................................................................................................37
3.2.7Alarm..........................................................................................................................37
3.2.7.1AlarmStatus........................................................................................................38
3.2.7.2AlarmInput.........................................................................................................39
3.2.7.3AlarmOutput......................................................................................................39
3.2.7.4AlarmMap...........................................................................................................41
3.2.8SystemLog.................................................................................................................41
3.2.8.1SystemLog..........................................................................................................41
3.2.8.2SystemLogSettings.............................................................................................42
3.2.8.3KiwiSyslogDaemon............................................................................................43
3.2.9SystemUpgrading.......................................................................................................43
3.2.10Reboot......................................................................................................................44
3.2.11CloudPlatform.........................................................................................................44
3.2.11.1CloudPlatform..................................................................................................44
3.2.11.2MOTTClient......................................................................................................45
3.2.12ScheduledTasks........................................................................................................46
3.3Network.............................................................................................................................46
3.3.1Cellular.......................................................................................................................46
3.3.1.1Status...................................................................................................................47
3.3.1.2Cellular................................................................................................................47
3.3.2WLANInterface2.4G...........................................................................................50
3.3.2.1Status...................................................................................................................50
3.3.2.2WLAN(2.4G).......................................................................................................50
3.3.2.3IPSetup...............................................................................................................53
3.3.2.4SSIDScan.............................................................................................................53
3.3.3WLANInterface5.8G...........................................................................................53
3.3.3.1Status...................................................................................................................53
3.3.3.2WLAN5.8G...................................................................................................54
3.3.3.3IPSetup...............................................................................................................56
3.3.3.4SSIDScan.............................................................................................................57
3.3.4CaptivePortal.............................................................................................................57
3.3.5DHCPservice..............................................................................................................59
3.3.5.1Status...................................................................................................................60
3.3.5.2DHCPServer........................................................................................................60
3.3.5.3DHCPRelay..........................................................................................................62
3.3.5.4DHCPClient.........................................................................................................62
3.3.6DNSServices...............................................................................................................63
3.3.6.1DNSServer..........................................................................................................64
3.3.6.2DNSRelay............................................................................................................64
3.3.7SMS............................................................................................................................65
3.3.8VLANInterface...........................................................................................................66
3.3.8.1VLANConfiguration.............................................................................................66
3.3.8.2VLANAggregation...............................................................................................67
3.3.9ADSLDialupPPPoE..............................................................................................68
3.3.10LoopbackInterface...................................................................................................69
3.3.11DynamicDomainName...........................................................................................71
3.3.12BridgeInterface........................................................................................................72
3.4LinkBackup.......................................................................................................................73
3.4.1SLA..............................................................................................................................73
3.4.2TrackModule..............................................................................................................74
3.4.3VRRP...........................................................................................................................76
3.4.4InterfaceBackup.........................................................................................................79
3.5Routing..............................................................................................................................80
3.5.1StaticRoute................................................................................................................80
3.5.1.1RoutingStatus.....................................................................................................81
3.5.1.2StaticRouting......................................................................................................81
3.5.2DynamicRouting........................................................................................................82
3.5.2.1RoutingStatus.....................................................................................................83
3.5.2.2RIP.......................................................................................................................83
3.5.2.3OSPF....................................................................................................................87
3.5.2.4FilteringRoute.....................................................................................................89
3.5.3MulticastRouting.......................................................................................................90
3.5.3.1BasicSettings.......................................................................................................90
3.5.3.2IGMP....................................................................................................................91
3.6Tools..................................................................................................................................
93
3.6.1PING...........................................................................................................................93
3.6.2RoutingDetection......................................................................................................94
3.6.3LinkSpeedTest...........................................................................................................94
3.7InstallationGuide..............................................................................................................95
3.7.1NewDial.....................................................................................................................95
3.7.2NewIPSecTunnel.......................................................................................................96
3.8PersonalizationFeatures...................................................................................................97
3.8.1NginxServer...............................................................................................................97
3.8.2FileSynchronization...................................................................................................98
3.8.3GPSLocationInformation..........................................................................................99
3.8.4RoamingManagement.............................................................................................100
3.8.4.1RoamingManagement......................................................................................100
3.8.4.2UpgradefromAP...............................................................................................100
3.9Firewall............................................................................................................................101
3.9.1AccessControlACL............................................................................................101
3.9.2NAT...........................................................................................................................103
3.10QoS................................................................................................................................106
3.11VPN................................................................................................................................108
3.11.1IPSec.......................................................................................................................108
3.11.1.1IPSecPhase1...................................................................................................109
3.11.1.2IPSecPhase2...................................................................................................112
3.11.1.3IPSecConfiguration.........................................................................................113
3.11.1.4IPSecVPNConfigurationExample...................................................................114
3.11.2GRE.........................................................................................................................118
3.11.3L2TP........................................................................................................................120
3.11.4OPENVPN...............................................................................................................122
3.11.5CertificateManagement........................................................................................124
3.12ConfigurationWizard....................................................................................................126
4.APPLICATIONSCENARIOS.............................................................................................................128
APPENDIX1TROUBLESHOOTING..........................................................................................129
APPENDIX2INSTRUCTIONOFCOMMANDLINE....................................................................132
1.WIFUN1050Introduction
ThisChapterincludes:
Overview
Features
1.1Overview
WIFUN1050isadedicatedvehicleWiFiMediaServerwithembeddedNGINXwebserver
andlocalstorageSSD.WithWIFUN1050andtheRainbowWiFicloud,motorcoachoperators
mayeasilysetupanadvancedWiFioperatingsystemwhichprovidesdevicemanagement,
contentmanagement,vehiclelocationmanagement,visitormanagement,statisticalreports,and
otherfeatures.TravelerssimplyconnecttotheWiFihotspotprovidedbyWIFUN1050tosurf
Internet,andtoenjoylocalservicessuchasVODmoviesandinteractivegamesprovidedby
operators.BydeployingtheRainbowWiFicloud,motorcoachoperatorsmayeasilyremotely
managethousandsofWIFUN1050devices,nomatterchangingvisitorpolicyorupdatingmedia
contentdeployedinWIFUN1050.
TheWIFUN1050isaportalintothemobileinternetandastepforwardinproviding
valueaddedservicestotravelers.
1.2Features
AdvancedWiFi
Supportdualband2.4GHzand5.8GH,fullycompliancewithIEEE802.11ac/a/b/g/n
standards.
With2X2MIMOtechnologyenabled,WiFiconnectionbandwidthcanreachashighas
1.2Gbps,bringsamazingmultiuserperformance.
Highspeed4GAccess
Integratinguptotwo4Gcellularmodules,WIFUN1050providesreliable
TDLTE/FDDLTEaccess,with100Mbpsuplinkand50Mbpsdownlink.
QuadBandLTE:700/850/AWS(1700/2100)/1900MHz;FDDBand(17,5,4,2);TriBand
UMTS(WCDMA):850/AWS(1700/2100)/1900MHz;FDDBand(5,4,2)QuadBand
GSM/GPRS/EDGE:850/900/1800/1900MHz
GPS
WithGPSenabled,WIFUN1050providesvehiclelocation,speed/courseoverground
andtrackinformation.
PowerfulWebPortal
WhenvisitorsconnecttotheWiFihotspotprovidedbyWIFUN1050,agreetingsplash
pagepopsup,providinglocalmediaservicesanduserauthentication.
BuiltinWebServer
EmbedreliableNGINXwebserver,enablinglocalmediaservices.
SupportPHP,enablingdynamicpagecontent.
LocalStorage
SupportSSDupto1TB,toleratingvibrationfromvehicle.
Localstoragemaybeusedtostorelocalwebcontent,movies,music,apps,etc.to
acceleratelocalaccessandtosaveinternetbandwidth.
ContentUpdateMechanism
Inremotesynchronizationmode,locallystoredcontentsmaysyncwiththecloud.
Inlocalsynchronizationmode,contentmaybeupdatedviaSDcardorFTP.
Bothmodesmaybehybridtoenableevenmoreflexibleoperation.
VisitorBehaviorManagement
SupportvisitorauthenticationbySMSorsocialaccounts.
SupportQoStolimitperuserbandwidthandtraffic,preventingoveragesand
protectinglatencysensitivetraffic.
Supportwebsitesblacklistandwhitelist.
CloudManagement
SupporttheRainbowWiFicloud,enablingdevicemanagement,contentmanagement,
vehiclelocationmanagement,visitormanagement,statisticalreports,andother
features.
SupportCLI,webUIandSNMPv3.
HighReliability
Withdedicatedvehiclepowermoduleinside,WIFUN1050toleratespowervoltagedips,
overruns,shortandotherfailures.SupportautomaticallypowercontrolwithACC
signaltoprotectSSDandvehiclebattery.
Fanlesscoolingdesigntosimplifyinstallation.
SupportlinkqualityinspectionandautorecoverytoensurereliableLTEaccess.
RobustSecurity
SupportIPSecVPN,DMVPN,L2TP,SSLVPN,andCAcertificationtoensuredata
security.
SupportpowerfulfirewallfunctionssuchasStatefulPacketInspection(SPI),Access
ControlList(ACLs),DoSattackprevention,etc.
SupportAAA,TACACS,Radius,localauthentication,andmultilevelsuserauthorityto
ensuresecuremanagement.

2.EstablishNetworkConnection
Thischaptermainlycontainsthefollowingcontents:
EstablishNetworkConnection
ConfirmthattheconnectionbetweensupervisoryPCandrouter
CanceltheProxyServer
Aftercompletingthehardwareinstallation,beforetologintheWebsetuppage,youneedto
ensurethatthemanagementoftheEthernetcardinstalledonyourcomputer.
2.1EstablishNetworkConnection
2.1.1AutomaticacquisitionofIPaddress(recommended)
Pleasesetthesupervisorycomputerto"automaticacquisitionofIPaddress"and"automatic
acquisitionofDNSserveraddress"(defaultconfigurationofcomputersystem)tolettherouter
automaticallyassignIPaddressforsupervisorycomputer.
1)Open“ControlPanel,doubleclick“NetworkandInternet”icon,enter“NetworkandSharing
Centers”
2)Clickthebutton<LocalConnection>toenterthewindowof"LocalConnectionStatus”
3)Click<Properties>toenterthewindowof"LocalConnectionProperties”,asshownbelow.
4)Select“InternetPortocolVersion4(TCP/IPv4)”,click<Properties>toenter“InternetPortocol
Version4(TCP/IPv4)Properties”page.Select“ObtainanIPaddressautomatically”and“Obtain
DNSServeraddressautomatically,thenclick<OK>tofinishsetting,asshownbelow.
2.1.2SetastaticIPaddress
SetcomputermanagementIPaddressanddevieceFEportIPaddressonthesamenetwork
segment(deviceFEportinitialIPaddress:192.168.2.1,SubnetMask:255.255.255.0).The
followingFE1/1portconnectedtoacomputerandmanagementprovidedinWindowsXPsystem
describedasanexample.
Enter“InternetPortocol(TCP/IP)Properties”page,select“UsethefollowingIPaddress”,typeIP
address(arbitraryvaluebetween192.168.2.2192.168.2.254),SubnetMask(255.255.255.0),
andDefafultGateway(192.168.2.1),thenclick<OK>tofinishsetting,asshownFigure25.
Figure25InternetPortocol(TCP/IP)Properties
2.2ConfirmthatthenetworkbetweenthesupervisoryPCandrouterisconnected
1)Clickthelowerleftcornerofthescreen<Start>buttontoenterthe"Start"menu,select"Run"
popup"Run"dialogbox,showninFigure26.
Figure26Run
2)Enter"ping192.168.2.1(IPaddressofrouter;itisthedefaultIPaddress),andclickthebutton
<OK>.Ifthepopupdialogboxshowstheresponsereturnedfromtherouterside,itindicates
thatthenetworkisconnected;otherwise,checkthenetworkconnection,showninFigure27.
Figure27CommandPrompt
2.3CanceltheProxyServer
IfthecurrentsupervisorycomputerusesaproxyservertoaccesstheInternet,itisrequiredto
canceltheproxyserviceandtheoperatingstepsareasfollows:
1)Select[Tools/InternetOPtions]inthebrowsertoenterthewindowof[InternetOptions],
showninFigure28.
Figure28InternetOPtions
2Selectthetab”Connectandclickthebutton<LANSetting(L)>toenterthepageof“LAN
Setting.Pleaseconfirmiftheoption”UseaProxyServerforLANischecked;ifitis
checked,pleasecancelandclickthebutton<OK>,showninFigure29.
Figure29LANSetting

3.WebConfiguration
Thischapterincludesthefollowingparts:
Login/outWebConfigurationPage
Management
Network
LinkBackup
Routing
Tools
InstallationGuide
PersonalizationFeatures
Firewall
Qos
VPN
3.1LogintheWebSettingPageofRouter
RuntheWebbrowser,enter“http://192.168.2.1:8080”intheaddressbar,andpressEntertoskip
totheWebloginpage,asshowninFigure31.Enterthe“UserName”(default:adm)and
“Password”(default:123456),andclickbutton<OK>ordirectlypressEntertoentertheWeb
settingpage.
Figure31LoginRouter
AfterenteringtheWebSettingpage,clickthe"AdvancedConfiguration"webinterface,the
popupdialogbox,enter"UserName"(default:adm)againand"Password"(default:123456),
thenentertheparameterconfigurationinterfacestartparametersettings.Advanced
configurationisshownin3.2~3.11.
Atthesametime,therouterallowsuptofouruserstomanagethroughtheWebsetting
page.Whenmultiusermanagementisimplementedfortherouter,itissuggestednotto
conductconfigurationoperationfortherouteratthesametime;otherwiseitmayleadto
inconsistentdataconfiguration.
Forsecurity,youaresuggestedtomodifythedefaultloginpasswordafterthefirstlogin
andsafekeepthepasswordinformation.
3.2Management
3.2.1System
3.2.1.1SystemStatus
Fromtheleftnavigationpanel,selectAdministration/System,thenenter“SystemStatus”page.
Onthispageyoucanchecksystemstatusandnetworkstatus,asshowninFigure32.Insystem
status,byclicking<SyncTime>youcanmakethetimeofroutersynchronizedwiththesystem
timeofthehost.Clickthe“Set”onnetworkstatustoenterintotheconfigurationscreendirectly.
Forconfigurationmethods,refertoSection3.3.2.
Figure32SystemStatus
3.2.1.2BasicSettings
SelectAdministration/System,thenenter“BasicSetup”page.YoucansetthelanguageofWeb
ConfigurationPageanddefineRouterName,asshowninFigure33.
Figure33BasicSettings
3.2.2SystemTime
Toensurethecoordinationbetweenthisdeviceandotherdevices,userisrequiredtosetthe
systemtimeinanaccuratewaysincethisfunctionisusedtoconfigureandchecksystemtimeas
wellassystemtimezone.
ThedevicesupportsmanualsettingofsystemtimeandthetimetopassselfsynchronisticSNTP
server.
3.2.2.1SystemTime
Timesynchronizationofrouterwithconnectedhostcouldbesetupmanuallyinsystemtime
configurationpartwhilesystemtimeisallowedtobesetasanyexpectedvalueafterYear2000
manually.
Fromtheleftnavigationpanel,selectAdministration/SystemTime,thenenter“SystemTime
page,asshowninFigure34.
Byclicking<SyncTime>youcanmakethetimeofroutersynchronizedwiththesystemtimeofthe
host.SelecttheexpectedparametersinYear/Month/DateandHour:Min:SecColum,thenclick
<Apply&Save>.Therouterwillimmediatelysetthesystemtimeintoexpectedvalue.
Figure34SystemTime
3.2.2.2SNTPClientPort
SNTP,namelySimpleNetworkTimeProtocol,isasystemforsynchronizingtheclocksof
networkedcomputers.InmostplacesoftheInternettoday,SNTPprovidesaccuraciesof150ms
dependingonthecharacteristicsofthesynchronizationsourceandnetworkpaths.
ThepurposeofusingSNTPistoachievetimesynchronizationofalldevicesequippedwithaclock
onnetworksoastoprovidemultipleapplicationsbasedonuniformtime.
Fromtheleftnavigationpanel,selectAdministration/SystemTime,thenenter“SNTPClient
page,asshowninFigure35.
Figure35SNTPClientPort
PagedescriptionisshowninTable31.
Table31SNTPClientPortPageDescription
ParameterDescriptionDefault
SourceIPThecorrespondingIPofsourceinterfaceNone
SNTPServersList
ServerAddressSNTPserveraddress(domainname/IP),maximumto
set10SNTPserverNone
PortTheserviceportofSNTPserver123
BeforesettingaSNTPserver,shouldensureSNTPserverreachable.EspeciallywhentheIP
addressofSNTPserverisdomain,shouldensureDNSserverhasbeenconfigured
correctly.
Ifyouconfigureasourceinterfaceandthencannotconfigurethesourceaddress.the
oppositeisalsotrue.
WhensettingmultipleSNTPserver,systemwillpollallSNTPserversuntilfindanavailableSNTP
server.
3.2.3AdminAccess
AdminAccessallowsthemanagementofuserswhicharecategorizedintosuperuserand
commonuser.
Superuser:onlyoneautomaticallycreatedbythesystem,allocatedwiththeusername
ofadmandgrantedwithallaccessrightstotherouter.
Commonuser:createdbysuperuserwiththerighttocheckratherthenmodifyrouter
configuration.
3.2.3.1Createauser
Clicknavigationpanel/AdminAccess,enter“Createauserpage,Whereintheuserpermissions
value,thehighertheprivilege,showninFigure36.
Figure36Createauser
3.2.3.2ModifyaUser
Fromtheleftnavigationpanel,selectAdministration/AdminAccess,thenenter“ModifyaUser
page,asshowninFigure37.Presstheuserthatneedstomodifyin“UserSummary,afterthe
backgroundturnsblue,enternewinformationin“ModifyaUser.
Figure37ModifyaUser
3.2.3.3RemoveUsers
Fromtheleftnavigationpanel,selectAdministration/AdminAccess,thenenter“RemoveUsers
page,asshowninFigure38.
Presstheuserthatneedstoremovein”UserSummary.Afterthebackgroundturnsblue,press
<Delete>toremovetheuser.
Figure38RemoveUsers
Thesuperuser(adm)canneitherbemodifiednordeleted.Butsuperuser’spasswordcanbe
modified.
3.2.3.4ManagementService
HTTP
HTTP,shortenedformofHypertextTransferProtocol,isusedtotransmitWebpageinformation
onInternet.HTTPislocatedastheapplicationlayerinTCP/IPprotocolstack.
ThroughHTTP,usercouldlogonthedevicetoaccessandcontrolitthroughWeb.
HTTPS
HTTPS(HypertextTransferProtocolSecure)supportsHTTPinSSL(SecuritySocketLayer).
HTTPS,dependingonSSL,isabletoimprovethedevice’ssecuritythroughfollowingaspects:
DistinguishlegalclientsfromillegalclientsthroughSSLandDisableillegalclientsto
accessthedevice;
Encryptthedataexchangedbetweenclientanddevicetoguaranteesecurityand
integralityofdatatransmissionsoastoachievethesafemanagementofdevice;
Anaccesscontrolstrategybasedoncertificateattributionsisestablishedforfurther
controlofclientsaccessauthoritysoastofurtheravoidattackforillegalclients.
TELNET
Telnet isanapplicationlayerprotocolinTCP/IPprotocolfamily,providingtelnetandVTfunctions
throughWeb.DependingonServer/Client,Tel netClientcouldsendrequesttoTelnetserver
whichprovidesTeln etservices.ThedevicesupportsTel netClientandTe lnetServer.
SSH
IncomparisonwithTel net, STelnet(SecureTel net) ,basedonSSH2,allowstheClienttonegotiate
withServersoastoestablishsecureconnection.ClientcouldlogonServerjustasoperationof
Telnet .
ThroughfollowingmeasuresSSHwillrealizethesecuretelnetoninsecurenetwork:
SupportRASauthentication.
SupportencryptionalgorithmssuchasDES,3DESandAES128toencrypt
usernamepasswordanddatatransmission.
Localconnection.ASSHchannelcouldbeestablishedbetweenSSHClientandSSH
Servertoachievelocalconnection.Followingisafigureshowingthe
establishmentofaSSHchannelinLAN:
WANconnection.ASSHchannelcouldbeestablishedbetweenSSHClientandSSH
ServertoachieveWANconnection.Followingisafigureshowingtheestablishmentofa
SSHchannelinWAN:
Fromtheleftnavigationpanel,selectAdministration/AdminAccess,thenenter“Management
Service”page,asshowninFigure39.
Figure39ManagementService
3.2.4AAA
AAAaccesscontrolisusedtocontrolvisitorsandcorrespondingservicesavailableaslongas
accessisallowed.Samemethodisadoptedtoconfigurethreeindependentsafetyfunctions.It
providesmodularizationmethodsforfollowingservices:
Authentication:verifywhethertheuserisqualifiedtoaccesstothenetwork.
Authorization:relatedwithservicesavailable.
Charging:recordsoftheutilizationofnetworkresources.
UsermayonlyuseoneortwosafetyservicesprovidedbyAAA.Forexample,thecompanyjust
wantsidentityauthenticationwhenemployeesareaccessingtosomespecifiedresources,then
networkadministratoronlyneedstoconfigureauthenticationserver.Butifrecordingofthe
utilizationofnetworkisrequired,then,achargingservershallbeconfigured.
CommonlyAAAadopts“Client—Serverstructurewhichisfeaturedbyfavorableexpandability
andfacilitatescentralizedmanagementofusers’information,asthefollowingfigureshows:
3.2.4.1Radius
RemoteAuthenticationDialinUserService(RADIUS),aninformationexchangeprotocolwitha
distributiveClient/Serverstructure,couldpreventthenetworkfromanydisturbancefrom
unauthorizedaccessandisgenerallyappliedinvariousnetworkenvironmentswithhigher
requirementsonsecurityandthatpermitremoteuseraccess.Theprotocolhasdefinedthe
RadiusframeformatbasedonUDPandinformationtransmissionmechanism,confirmedUDP
Port1812astheauthenticationport.RadiusServergenerallyrunsoncentralcomputeror
workstation;RadiusClientgenerallyislocatedonNAS.
InitiallyRadiusisdesignedanddevelopedagainstAAAprotocolofdialinusers.Alongwiththe
diversifieddevelopmentofuseraccessways,Radiusalsoadaptsitselftosuchchanges,including
EthernetaccessandADSLaccess.Accessserviceisrenderedthroughauthenticationand
authorization.
MessageflowbetweenRadiusClientandServerisshownasfollows:
UsernameandpassportwillbesenttotheNASwhentheuserlogsonit;
RadiusClientonNASreceivesusernameandpasswordandthensendsan
authenticationrequesttoRadiusServer;
Uponthereceptionoflegalrequest,RadiusServerexecutesauthenticationandfeeds
backrequireduserauthorizationinformationtoClient;Forillegalrequest,Radius
ServerwillfeedbackAuthenticationFailedtoClient.
Fromtheleftnavigationpanel,selectAdministration/AAA,thenenter“Radius”page,asshownin
Figure310.
Figure310Radius
PagedescriptionisshowninTable32.
Table32RadiusDescription
ParameterDescriptionDefault
ServerAddressServeraddress(domainname/IP)None
PortConsistentwiththeserverport1812
KeyConsistentwiththeserverauthenticationkeyNone
3.2.4.2Tacacs+
Tacacs+,orTerminalAccessControllerAccessControlSystem,similartoRadius,adopts
Client/ServermodetoachievethecommunicationbetweenNASandTacacs+Server.But,Tacacs+
adoptsTCPwhileRadiusadoptsUDP.
Tacacs+ismainlyusedforauthentication,authorizationandchargingofaccessusersandterminal
usersadoptingPPPandVPDN.Itstypicalapplicationisauthentication,authorizationandcharging
forterminalusersrequiringloggingonthedevicetocarryoutoperation.AstheClient,thedevice
willhaveusernameandpasswordsenttoTacacs+Serverforverification.Solongasuser
verificationpassedandauthorizationobtained,loggingandoperationonthedeviceareallowed.
Fromtheleftnavigationpanel,selectAdministration/AAA,thenenterTacacs+”page,asshown
inFigure311.
Figure311Tacacs+
PagedescriptionisshowninTable33.
Table33Tacacs+Description
ParametersDescriptionDefault
ServerAddressServeraddress(domainname/IP)None
PortConsistentwiththeserverport49
KeyConsistentwiththeserverauthenticationkeyNone
3.2.4.3LDAP
OneofthegreatadvantagesofLDAPisrapidresponsetousers’searchingrequest.Forinstance,
usersauthenticationwhichmaygeneralalargeamountofinformationsentasthesametime.If
databaseisadoptedforthispurpose,sinceitisdividedintomanytables,eachtimetomeetsuch
asimplerequirement,thewholedatabasehastobesearched,integratedandfilteredslowlyand
disadvantageously.LDAP,simpleasatable,onlyrequiresusernameandcommandandsomething
else.Authenticationismetfromefficiencyandstructure.
Fromtheleftnavigationpanel,selectAdministration/AAA,thenenter“LDAP”page,asshownin
Figure312.
Figure312LDAP
PagedescriptionisshowninTable34.
Table34LDAPDescription
ParametersDescriptionDefault
Name DefineservernameNone
ServerAddressServeraddress(domainname/IP)None
PortConsistentwiththeserverportNone
BaseDNThetopofLDAPdirectorytreeNone
UsernameUsernameaccessingtheserverNone
PasswordPasswordaccessingtheserverNone
Security Encryptionmod:None,SSL,StartTLSNone
VerifyPeer VerifyPeerUnopened
3.2.4.4AAASettings
AAAsupportsfollowingauthenticationways:
None:withgreatconfidencetousers,legalcheckomitted,generallynotrecommended.
Local:HaveusersinformationstoredonNAS.Advantages:rapidness,costreduction.
Disadvantages:storagecapacitylimitedbyhardware.
Remote:Haveusersinformationstoredonauthenticationserver.Radius,Tacacs+and
LDAPsupportedforremoteauthentication.
AAAsupportsfollowingauthorizationways:
None:authorizationrejected.
Local:authorizationbasedonrelevantattributionsconfiguredbyNASforlocalusers
account.
Tacacs+:authorizationdonebyTacacs+Server.
RadiusAuthenticationBased:authenticationbondedwithauthorization,authorization
onlybyRadiusnotallowed.
LDAPAuthorization.
Fromtheleftnavigationpanel,selectAdministration/AAA,thenenterAAASettingpage,as
showninFigure313.
Figure313AAAauthentication
PagedescriptionisshowninTable35.
Table35AAASettingsKeyItems
KeyItemsDescription
radiusAuthenticationandAuthorizationServer
tacacs+AuthenticationandAuthorizationServer
ldapAuthenticationandAuthorizationServer
local Thelocalusernameandpassword
Authentication1shouldbesetconsistentlywithAuthorization1;Authentication2shouldbe
setconsistentlywithAuthorization2;Authentication3shouldbesetconsistentlywith
Authorization3.
Whenconfigureradius,Tacas+,localatthesametime,priorityorderfollow:1>2>3.
3.2.5ConfigurationManagement
Hereyoucanbackuptheconfigurationparameters,importthedesiredparametersconfiguration
backupandrestorethefactorysettingsoftherouter.
Fromtheleftnavigationpanel,selectAdministration/ConfigManagement,thenenter“Config
Management”page,asshownin314.
Figure314ConfigurationManagement
PagedescriptionisshowninTable36.
Table36ConfigManagementDescription
ParametersDescriptionDefault
BackuprunningconfigBackuprunningconfigfiletohost.None
BackupstartupconfigBackupstartupconfigfiletohost.None
Automaticallysavemodified
configuration
Decidewhethertoautomaticallysave
configurationaftermodifytheconfiguration.
On
RestoreDefault
Configuration
RestorefactoryconfigurationNone
Whenimporttheconfiguration,thesystemwillfilterincorrectconfigurationfiles,andsavethe
correctconfigurationfiles,whensystemrestarts,itwillorderlyexecutethesesconfiguration
files.Iftheconfigurationfilesdidn’tbearrangedaccordingtoeffectiveorder,thesystemwon’t
enterthedesiredstate.
Inordernottoaffectcurrentsystemrunning,whenperformingtheimportconfigurationand
restorethedefaultconfiguration,needtoreboottherouternewconfigurationwilltakeeffect.
3.2.6SNMP
Definition
SNMP,orSimpleNetworkManagementProtocol,isastandardnetworkmanagementprotocol
widelyusedinTCP/IPnetworksandprovidesamethodofmanagingthedevicethroughthe
runningthecentralcomputerofnetworkmanagementsoftware.FeaturesofSNMP:
Simplicity:SNMPadoptspollingmechanism,providesthemostbasicsetsoffeatures
andcouldbeusedinsmallscale,rapid,lowcostenvironments.SNMP,withUDP
messageasthecarrier,issupportedbyagreatmajorityofdevices.
Powerfulness:objectiveofSNMPistoensurethetransmissionofmanagement
informationbetweenanytwopointssoastofacilitateadministratorsretrievalof
informationonanynodeonnetworkandmodificationandtroubleshooting.
Benefits
NetworkadministratorscouldmakeuseofSNMPtoaccomplishtheinformationquery,
modification,troubleshootingandotherjobsonanynodeonnetworktoachieve
higherefficiency.
Shieldingofphysicaldifferencesbetweendevices.SNMPonlyprovidesthemostbasic
setsoffeaturesformutualindependencebetweenadministrationandthephysical
properties,networktypesofdevicesunderadministration;therefore,itcouldrealize
theuniformmanagementofdifferentdevicesatalowercost.
Simpledesign,lowercost.Simplicityisstressedonadditionofsoftware/hardware,
typesandformatsofmessageondevicessoastominimizetheinfluenceandcoston
devicescausedbyrunningSNMP.
Application:managementofdeviceisachievedthroughSNMP
Administratorisrequiredtocarryoutconfigurationandmanagementofalldevicesinthesame
network,whicharescattered,makingonsitedeviceconfigurationimpracticable.Moreover,in
casethatthosenetworkdevicesaresuppliedfromdifferentsourcesandeachsourcehasits
independentmanagementinterfaces(forexample,differentcommandlines),theworkloadof
batchconfigurationofnetworkdeviceswillbeconsiderable.Therefore,undersuchcircumstances,
traditionalmanualwayswillresultinlowerefficiencyathighercost.Atthattime,network
administratorwouldmakeuseofSNMPtocarryoutremotemanagementandconfigurationof
attacheddevicesandachieverealtimemonitoring.Followingisafigureshowinghowtomanage
devicesthroughSNMP:
ToconfigureSNMPinnetworking,NMS,amanagementprogramofSNMP,shallbeconfiguredat
theManager.Meanwhile,Agentshallbeconfiguredaswell.
ThroughSNMP:
NMScouldcollectstatusinformationofdeviceswheneverandwhereverandachieve
remotecontrolofdevicesundermanagementthroughAgent.
AgentcouldtimelysendcurrentstatusinformationtoNMSreportdevice.Incaseofany
problem,NMSwillbenotifiedimmediately.
3.2.6.1SNMP
SNMPagentofdevicesupportsSNMPv1,SNMPv2andSNMPv3atpresent.
SNMPv1andSNMPv2adoptcommunitynametoauthenticate.
SNMPv3adoptusernameandpasswordtoauthenticate.
Fromtheleftnavigationpanel,selectAdministration/SNMP,thenenter“SNMPpage,as
showninFigure315.
Figure31SNMPv1&SNMPv2cSettings
PagedescriptionisshowninTable37.
Table37SNMPKeyItems
ParametersDescriptionDefault
CommunityNameUserdefineCommunityNamePublicandprivate
AccessLimitSelectaccesslimitReadonly
MIBView SelectMIBViewdefaultView
WhenchoosingSNMPv3version,thecorrespondingUseandUserGroupshouldbeconfigured.
TheconfigurationpageisshowninFigure316.
Figure316SNMPv3Setting
PagedescriptionisshowninTable38.
Table38SNMPv3Description
ParametersDescriptionDefault
GroupManagement
GroupnameUserdefine,length:132charatersNone
SecurityLevelIncludesNoAuth/NoPriv,Auth/NoPriv,Auth/privNoAuth/NoPriv
ReadonlyViewOnlysupportdefaultViewatpresentdefaultView
ReadwriteViewOnlysupportdefaultViewatpresentdefaultView
InformViewOnlysupportdefaultViewatpresentdefaultView
UserManagement
UsernameUserdefinedusername,length:132charactersNone
GroupNameSelectusertojoinusergroup,firstdefinedintheusergroup
managementtable,beforethis,selectappropriateusergroupNone
Authentication
Mode
Selectauthenticationmode.MD5andSHAprovidestwo
authenticationmodes,“noidentification"notenable
authentication.
SHA
Authentication
password
Whenonlyauthenticationmodeisnot"noidentification",
authenticationpasswordcanenter.
Length:832characters.
None
EncryptionmodeChoosewhethertouseDESencryptionmodeDES
Encryption
Password
Onlyencryptionmodeisnot"noencryption",encryption
modepasswordcanenter.
Length:832characters.
None
3.2.6.2SnmpTrap
SNMPtrap:AcertainportwheredevicesunderthemanagementofSNMPwillnotifySNMP
managerratherthanwaitingforpollingfromSNMPmanager.InNMS,Agentsinmanageddevices
couldhaveallerrorsreportedtoNMWatanytimeinsteadofwaitingforpollingfromNMWafter
itsreceptionofsucherrorswhich,asamatteroffact,arethewellknownSNMPtraps.
Fromtheleftnavigationpanel,selectAdministration/SNMP,thenenter“SnmpTrap”page,as
showninFigure317.
Figure317SnmpTrap
PagedescriptionisshowninTable39.
Table39SnmpTrapDescription
ParametersDescriptionDefault
HostAddressFillintheNMSIPaddressNone
SecurtiyName
FillinthegroupnamewhenusetheSNMPv1/v2c;Fillinthe
usernamewhenusetheSNMPv3.Length:132characters
None
UDPPort FillinUDPport,thedefaultportrangeis165535162
3.2.7Alarm
Alarmfunctionisawaywhichisprovidedforuserstogetexceptionsofdevice,whichcanmake
theusersfindandsolveexceptionsassoonaspossible.Whenabnormalityhappened,devicewill
sendalarm.Usercanchoosemanykindsofexceptionswhichsystemdefinedandchoose
appropriatenoticewaytogettheseexceptions.Alltheexceptionsshouldberecordedinalarm
logsothatusertroubleshootproblem.
Alarmcanbedivided:
Raise:Indicatesthealarmoccurrencehasnotbeenconfirmed.
Confirm:Alarmindicatesthatausercannottemporarysolve.
All:Indicatesallalarmsoccur.
Alarmlevelcanbedivided:
EMERGDeviceoccurssomefaults,itcouldleadtothesystemrestart.
CRITDeviceoccurssomefaultswhichareunrecoverable.
WARNDeviceoccurssomefaultswhichcouldaffectsystemfunction.
NOTICEDeviceoccurssomefaultswhichcouldaffectsystemproperties.
INFODeviceoccurssomenormalevents.
3.2.7.1AlarmStatus
Fromtheleftnavigationpanel,selectAdministration/Alarm,thenenter“AlarmState”page,as
showninFigure318.Throughthispage,youcancheckallthealrmssincetherouterispowered.
Click<ClearAllAlarms>tosetallthealarmto“clearstate.
Click<ConfirmAllAlarms>tosetallthealarmto“cconfirmstate.
Click<Reload>toreloadallthealarms.
Figure318AlarmStatus
3.2.7.2AlarmInput
Hereusercouldselectalarmtypesincludingsystemalarmandportalarm.Oneormorethanone
typescouldbeselected.
Fromtheleftnavigationpanel,selectAdministration/Alarm,thenenter“AlarmInputpage,as
showninFigure319.
Figure319AlarmInput
3.2.7.3AlarmOutput
Whenanalarmhappens,thesystemconfiguredwiththisfunctionwillsendthealarmcontentto
intendedemailaddressfromthemailaddresswhereanalarmemailissentinaformofemail.
Generallythisfunctionisnotconfigured.
Fromtheleftnavigationpanel,selectAdministration/Alarm,thenenter“AlarmOutputpage,as
showninFigure320.
Figure320AlarmOutput
PagedescriptionisshowninTable310.
Table310AlarmOutputDescription
ParametersDescriptionDefault
MailServerIP/NameSetIPaddressofMailServerthatsendalarmemails None
MailServerPortSetPortofMailServerthatsendalarmemails25
AccountName SetEmailaddressfromwhichalarmemailsaresentNone
AccountPassword SetEmailpassword None
CryptSetthecryptmethodNone
EmailAddressesDestinationaddressofreceivingalarmemail(110)None
Whentheemailparametershadbeenconfigured,youshouldclickthe“sendtestemail”button
sothatensuretheconfigurationiscorrect.Ifthetestemailfailed,itmaythenetwork
configurationormailboxconfigurationisnotcorrect.
3.2.7.4AlarmMap
AlarmMapconsistsoftwomappingways:CLI(consoleinterface)andEmail.Incaseoflatterone
isselected,andthenalarmoutputshallbeactivatedwithanemailaddresswellconfigured.
Fromtheleftnavigationpanel,selectAdministration/Alarm,thenenter“AlarmMap”page,as
showninFigure321.
Figure321AlarmMap
3.2.8SystemLog
SystemLogincludesmassiveinformationaboutnetworkanddevices,includingoperatingstatus,
configurationchangesandsoon,servingasanimportantwayfornetworkadministratorto
monitorandcontroltheoperationofnetworkanddevices.SystemLogcouldprovideinformation
tohelpnetworkadministratortofindnetworkproblemsorsafetyhazardsoastotakemore
targetedmeasures.
3.2.8.1SystemLog
Fromtheleftnavigationpanel,selectAdministration/Log,thenenter“SystemLogpage,as
showninFigure322.
Figure322SystemLog
Whendownloadsystemlog,routersettingswillalsobedownloaded.
3.2.8.2SystemLogSettings
On“SystemLogSettings”,remotelogservercouldbeset.Routerwillhaveallsystemlogssentto
remotelogserverdependingonremotelogsoftware(forexample:KiwiSyslogDaemon).
Fromnavigationpanel,selectAdministration/Log,thenenter“SystemLogpage,asshownin
Figure223.
Figure323SystemLogSettings
PagedescriptionisshowninTable311.
Table311SystemLogSettingsDescription
ParametersDescriptionDefault
LogtoRemoteSystemOpen/closeremotelogfunctionClose
IPAddress/Port(UDP)SetremoteserversIPaddress/PortNone/514
LogtoConsoleOpen/closeconsolelogfunctionOpen
3.2.8.3KiwiSyslogDaemon
KiwiSyslogDaemonisakindoffreelogserversoftwareusedinWindows,whichcouldreceive,
recordanddisplaylogsformedwhenpoweringonthehostofsyslog(forexample,router,
exchangeboard,Unixhost).AfterdownloadingandinstallationofKiwiSyslogDaemon,configure
necessaryparameterson“File>>Setup>>Input>>UDP.
3.2.9SystemUpgrading
Fromnavigationpanel,selectAdministration/Upgrade,thenenter“Upgrade”page,asshownin
Figure324.
Figure324SystemUpgrading
Click<Browse>toupgradedocumentsandthenclick<Upgrade>tostart.Thewholeprocess
takesabout1min,uponthecompletionofwhich,restarttherouterandnewfirmwaretakes
effect.
Softwareupgradetakestime,duringwhich,pleasedonocarryoutanyoperationonWeb,
otherwise,interruptionmaytakeplace.
Upgradeconsistsoftwostages:firststage:readinofupgradedocumentintobackupfirmware
zone,asdescribedinSectionofSystemUpgrade;secondstage:copyofdocumentsinbackup
firmwarezoneintomainfirmwarezone,whichmaybeexecutedinsystemreboot.
3.2.10Reboot
Fromnavigationpanel,selectAdministration/Reboot,thenenter“Rebootpage,asshownin
Figure325.Click<Yes>torebootthesystem.
Figure325Reboot
Pleasesavetheconfigurationsbeforereboot,otherwisetheconfigurationsthatarenotsaved
willbelostafterreboot.
3.2.11CloudPlatform
Cloudplatformisthroughsoftwareplatformtomanagedevices.Afterenablingcloudplatform,it
canoperatethedevicemanagementthroughsoftwareplatformthatenablesnetworkefficient
running.Forexample,queryequipmentrunningstatus,updatethedevicesoftware,rebootthe
device,andsendconfigurationparameterstotheequipment,etc.,mayalsosendcontrolor
querymessagetothedevicethroughthecloudplatform.
3.2.11.1CloudPlatform
Fromnavigationpanel"Administration>>DeviceManagementCloud"menu,enterthe"Cloud
Platform"screen,asshowninFigure326.
Figure326CloudPlatform
PagedescriptionisshowninTable312.
Table312CloudPlatformDescription
ParametersDescriptionDefault
Server SetcloudplatformIPaddress none
PortSettingcloudplatformportnumbernone
3.2.11.2MOTTClient
FromnavigationpanelAdministration>>DeviceManagementCloud"menu,enterthe"MOTT
Client"screen,asshownbelow.
3.2.12ScheduledTasks
Fromnavigationpanel,selectAdministration>>ScheduleManagement,thenenter“Schedule
Management”page,asshowninFigure327.
Figure327ScheduleManagement
3.3Network
3.3.1Cellular
SIMcarddialoutthroughDialInterface,achieverouterWiFicapabilities.
Dialinterfacesupportsthreeconnections:alwayson,ondemanddialingandmanualdialing.
3.3.1.1Status
Fromnavigationpanel,selectNetwork>>Cellular,thenenter“Status”page,asshowninFigure
328.
Figure328Status
3.3.1.2Cellular
Inthe"Cellular"page,youcancompletethewirelessdialconfiguration.
Fromnavigationpanel,selectNetwork>>Cellular,thenenter“Cellularpage,asshowninFigure
3291.
Figure3291Cellular
AdvancedoptionsareshowninFigure3292.
Figure3292CellularAdvancedoptions
PagedescriptionisshowninTable313.
Table313CellularPageDescription
ParametersDescriptionDefault
ProfileDialpolicychoices,donotneedtoconfigurehere1
RoamingSelectroamingEnable
PINCodeSIMcardPINcodeNone
NetworkSelectionModeThreeoptions:Automatic,2Gand3GAuto
StaticIPClickEnable(Enablerequireoperatorstoopen
relatedservices)Off
Connection
Alternativelyalwaysonline,ondemanddial(allows
dataactivation,phoneactivation,SMSactivation),
manualdialing
Always
online
RedialIntervalwhensettingupthelandingfails,redialinginterval10sec
ICMPdetectionserverDetectremoteIPaddressNone
ICMPdetectionintervalSetICMPdetectioninterval30sec
ICMPdetectiontimeoutSetICMPdetectiontimeout5sec
ICMPdetectionmaximum
numberofretries
SetmaximumnumberofretrieswhenICMP
detectionfails(Redialafterreachingthemaximum
number)
5
ICMPstrictdetectionClickEnableOff
Dialparameters
IndexUserdefined,generallyintheorderdefinedby
digital.None
NetworkMobilenetworktypeusedforselectingGSM
APN(CDMA2000series
doesnotsetthis)
Mobileoperatorstoprovidetherelevant
parameters(accordingtolocaloperatorschoose)3gnet
DialNumberMobileoperatorstoprovidetherelevant
parameters(accordingtolocaloperatorschoose)*99***1#
UserNameMobileoperatorstoprovidetherelevant
parameters(accordingtolocaloperatorschoose)gprs
PasswordMobileoperatorstoprovidetherelevant
parameters(accordingtolocaloperatorschoose)******
ClickEnableShowAdvancedOptions(thefollowingaretherelevantparameterstoconfigure
aftertheadvancedoptionsturnon)
InitiaCommandsUsedtosetadvancednetworkparameters,
generallydonotneedtofillinNone
RSSIPollIntervalSetsignalqueryinterval120sec
DialtimeoutSetdialtimeout(afterdialingtimeoutthesystem
willredial)120sec
MTUSetsthemaximumtransmissionunitinbytes1500
MRUSettingmaximumreceivingunitinbytes1500
EnabledefaultasyncmapClickEnabledefaultasyncmapDisable
UseassignedDNSserverClicktoenabletoacceptassignedDNSbymobile
operators.Enable
Connectiondetection
intervalSetconnectiondetectioninterval55sec
ConnectionDetection
maximumnumberof
retries
Setmaximumnumberofretrieswhenconnection
detectionfails(Redialafterreachingthemaximum
number)
5
EnabledebugmodeThesystemcanprintamoredetailedlogEnable
ExpertOptionsProvideadditionalPPPparameters,usersgenerally
donotsetNone
3.3.2WLANInterface2.4G
WLANorWirelessLAN,isquiteconvenientdatatransmissionsystem,whichusesradiofrequency
(RadioFrequency;RF)technology,toreplacetheoldoutofthewayoftwistedcopper(Coaxial)
localareanetworkcomposedofsuchawirelesslocalareanetwork,canbeaccessedusinga
simplearchitectureallowsuserstothroughit,to"carryinformationtechnologytofacilitatetravel
theworld,"theidealstate.
3.3.2.1Status
Fromnavigationpanel,selectNetwork/WLAN(2.4G),enter“Status”page,asshowninFigure
330.
Figure330WLAN(2.4G)Status
3.3.2.2WLAN(2.4G)
WLANinterfacehasaccesspointandclienttwotypes.Fromnavigationpanel,select
"Network/WLAN(2.4G)"menu,enter"WLAN(2.4G)"page.Interfacetypeusingthe"access
point",asshowninFigure331a;interfacetypeusingthe"client",asshowninFigure331b.
Figure331aWLAN(2.4G)‐AccessPoint
PagedescriptionisshowninTable314a.
Table314aAccessPointDescription
ParametersDescriptionDefault
MultipleSSIDClickEnable,enabledreusablecustom3SSIDDisable
SSIDBroadcastOpen"SSIDBroadcast",usercansearchwirelessnetwork
throughSSIDname.Enable
RFType
SixtypesOptional:
802.11g/n,802.11g,802.11n,802.11b,802.11b/g,802.11b/
g/n
802.11g/n
Channel Selectchannel11
SSIDUserdefinedSSIDnameWIFUN10503
000
AuthenticationFourauthenticationmodesavailable:Open,Shared,
WPAPSKandWPA2PSKOpen
EncryptionAccordingtothedifferentauthenticationmethods,NONE
supportNONE,WEP40andWEP104
Wireless
BandwidthTwooptions:20MHzand40MHz20MHz
MaximumNumber
ofClients Userdefined(upto128)None
Figure331bWLAN(2.4G)‐Client
PagedescriptionisshowninTable314b.
Table314bClientInterfaceDescription
ParametersDescriptionDefault
SSIDFillintheSSIDnametoconnectNone
AuthenticationSSIDauthenticationmethodOpen
EncryptionSSIDencryptionmethodNONE
WhentheWLANissetasClientmode,refertothefollowing3steps:
Step1:select"Network/Cellular"menu,enter"Cellular"page,anddisableCellularfunction.If
therouterdoesnothavecelluarmodule,skipthisstepandgotostep2.
Step2:select"Network/WLAN(2.4G)"menu,enter"WLAN(2.4G)"pageandchoose“Clientto
configurerelatedparametersasshowninFigure331b.
Step2:select"Network/WLAN(2.4G)"menu,enter"IPSetup"pagetoconfigureIPparametersas
shownin3.3.2.3IPSetup.
3.3.2.3IPSetup
WLANinterfaceIPaddresssupportmultipleIP,itcanbesetaccordingtodemand,butuptomore
than10.
Fromnavigationpanel,select"Network/WLAN(2.4G)"menu,enter"IPSetup"page,asshownin
Figure332.
Figure332WLAN(2.4G)IPSetup
3.3.2.4SSIDScan
WLANinterfaceselectsclient(Section3.3.2.2WLANInterface(2.4G)),SSIDscanningfunction
starts.Fromnavigationpanel"Network/WLAN(2.4G)"menu,enter"SSIDScan"page,willdisplay
alltheavailableSSIDnames,andthedisplayWIFUN1050canbeconnectedasaclientstate.
3.3.3WLANInterface5.8G
3.3.3.1Status
Fromnavigationpanel,selectNetwork/WLAN(5.8G),enter“Status”page,asshowninFigure
334.
Figure334WLAN(5.8G)Status
3.3.3.2WLAN5.8G
WLANinterfacehasaccesspointandclienttwotypes.Fromnavigationpanel"Network/WLAN
(5.8G)"menu,enter"WLAN(5.8G)"page.Interfacetypeusingthe"accesspoint",asshownin
Figure335a;interfacetypeusingthe"client",asshowninFigure335b.
Figure335aWLANinterface(5.8G)‐AcessPoint
PagedescriptionisshowninTable315a.
Table315aAcessPointDescription
ParametersDescriptionDefault
MultipleSSIDClickEnable,enabledreusablecustom3SSIDDisable
SSIDBroadcastOpen"SSIDBroadcast",usercansearchwirelessnetwork
throughSSIDname.Enable
RFType
SixtypesOptional:
802.11g/n,802.11g,802.11n,802.11b,802.11b/g,802.11b/
g/n
802.11g/n
Channel Selectchannel11
SSIDUserdefinedSSIDnameWIFUN1050
AuthenticationFourauthenticationmodesavailable:Open,Shared,
WPAPSKandWPA2PSKOpen
EncryptionAccordingtothedifferentauthenticationmethods,
supportNONE,WEP40andWEP104NONE
Wireless
BandwidthTwooptions:20MHzand40MHz20MHz
MaximumNumber
ofClients Userdefined(upto128)None
Figure335bWLANinterface(5.8G)Client
PagedescriptionisshowninTable315b.
Table315bWLANinterface(5.8G)Description
ParametersDescriptionDefault
5GprioritySelectEnable Disable
SSIDSSIDnametoconnectNone
AuthenticationSSIDauthenticationmethodOpen
EncryptionSSIDencryptionmethodNONE
WhentheWLANissetasClientmode,refertothefollowing3steps:
Step1:select"Network/Cellular"menu,enter"Cellular"page,anddisableCellularfunction.If
therouterdoesnothavecelluarmodule,skipthisstepandgotostep2.
Step2:select"Network/WLAN(5.8G)"menu,enter"WLAN(5.8G)"pageandchoose“Clientto
configurerelatedparametersasshowninFigure335b.
Step2:select"Network/WLAN(5.8G)"menu,enter"IPSetup"pagetoconfigureIPparametersas
shownin3.3.3.3IPSetup.
3.3.3.3IPSetup
WLANinterfaceIPaddresssupportmultipleIP,itcanbesetaccordingtodemand,butuptomore
than10.
Fromnavigationpanel,selectNetwork/WLAN(5.8G),enter"IPSetup"page,asshowninFigure
336.
Figure336WLAN(5.8G)IPSetup
3.3.3.4SSIDScan
WLANinterfaceselectsclient(Section3.3.3.2WLANInterface(5.8G)),SSIDscanningfunction
starts.Fromnavigationpanel"Network/WLANinterface(5.8G)"menu,enter"SSIDScan"page,
willdisplayalltheavailableSSIDnames,andthedisplayWIFUN1050canbeconnectedasaclient
state.
3.3.4CaptivePortal
CaptiveportalisWebpagethatusermustvisitandinteractwithbeforegrantedaccesstopublic
accessnetwork.CaptiveportalusuallyoffersfreeWiFihotspotservicestoInternetusersin
commercialcenters,airports,hotellobbies,cafesandotherpublicplacestouse.
Fromnavigationpanel"Network/captiveportal"menu,enterthe"captiveportal"page.Asshown
inFigure338.
Figure338CaptivePortal
PagedescriptionisshowninTable316.
Table316CaptivePortalDescription
ParametersDescriptionDefault
LANInterfaceCaptiveportallocalinterfacedotllradio1
WANInterfaceExternalnetworkadaptercellular1
SplashedHomePage PushHometocustomerswifi.go
Authentication
Server
UserauthenticationserverIPaddressforuserlogin
authenticationNone:80
ForceReloginPeriod ForceusertoreloginNone
SilentUser
AutomaticLogoffUserautomaticlogoffwhennoflow5
ClientFairnessUsedinconjunctionwiththespeedfunctionEnable
SpeedLimitWificlienttrafficrestrictionsNone
KnownUsersAccess
Control
Authenticateduseraccesscontroltwooptionals:
blacklistandwhitelistmode.Blacklist
TrustedMACAddressesList
IDSerialnumberNone
MACAddressMACaddressauthenticationfreeuserNone
Globalwhitelist
IDSerialnumberNone
Domain/IPaddressorIPthatcanbeaccessedwithout
authentication
None
Authenticatedusersblacklist
IDSerialnumberNone
Domain/IPRestrictauthenticateduserstoaccessnetwork,thatis
cannotbeaccessedbyauthenticatedusersto
None
blacklistaddressesorIP
3.3.5DHCPservice
Alongwiththecontinuousexpansionofnetworksizeandcomplicationofnetwork,numberof
computersoftenexceedsdistributableIPaddresses.Meanwhile,inpacewiththeextensive
applicationofportabledevicesandwirelessnetwork,positionofcomputerchangesfrequently,
resultingtothefrequentupgradeofIPaddress,leadingtoamoreandmorecomplicatednetwork
configuration.DHCP(DynamicHostConfigurationProtocol)isaproductforsuchdemands.
DHCPadoptsClient/Servercommunicationmode.ClientsendsconfigurationrequesttoServer
whichfeedsbackcorrespondingconfigurationinformation,includingdistributedIPaddresstothe
ClienttoachievethedynamicconfigurationofIPaddressandotherinformation.
IntypicalapplicationsofDHCP,generallyoneDHCPServerandanumberofClients(PCand
PortableDevices)areincluded,asthefollowingfigureshows:
WhenDHCPClientandDHCPServerareindifferentphysicalnetworksegment,Clientcould
communicatewithServerthroughDHCPRelaytoobtainIPaddressandotherconfiguration
information,asthefollowingfigureshows:
3.3.5.1Status
Fromnavigationpanel,selectNetwork/DHCP,thenenter“Status”page,asshowninFigure339.
Figure339DHCPStatus
3.3.5.2DHCPServer
ThedutyofDHCPServeristodistributeIPaddresswhenWorkstationlogsonandensureeach
workstationissuppliedwithdifferentIPaddress.DHCPServerhassimplifiedsomenetwork
managementtasksrequiringmanualoperationsbeforetothelargestextent.
Fromnavigationpanel,selectNetwork>>DHCP,thenenter“DHCPServerpage,asshownin
Figure340.
Figure340DHCPServer
PagedescriptionisshowninTable317.
Table317DHCPServerDescription
ParametersDescriptionDefault
EnableOn/OffOff
Interfacedot11radio1dot11radio1
StartingAddressDynamicaldistributionofstartingIPaddressN/A
EndingAddressDynamicaldistributionofendingIPaddressN/A
LeaseDynamicaldistributionofIPvalidity1440
DNSServerOneortwo,orNoneN/A
WINSSetupofWINS,generallyleftblankN/A
StaticIPSetup
MACAddress
SetupastaticspecifiedDHCP’sMACaddress
(differentfromotherMACstoavoidconfliction)
0000.0000.0000
IPAddress
SetupastaticspecifiedIPaddress(withinthe
scopefromstartIPtoendIP)
N/A
IfthehostconnectedwithrouterchoosestoobtainIPaddressautomatically,thensuch
servicemustbeactivated.StaticIPsetupcouldhelpacertainhosttoobtainspecifiedIP
address.
3.3.5.3DHCPRelay
Generally,DHCPdatapacketisunabletobetransmittedthroughrouter.Thatistosay,DHCP
ServerisunabletoprovideDHCPservicesfortwoormoredevicesconnectedwitharouter
remotely.ThroughDHCPrelay,DHCPrequestsandresponsedatapacketcouldgothroughmany
routers(BroadbandRouter).
Fromnavigationpanel,selectNetwork/DHCP,thenenter“DHCPRelaypage,asshowninFigure
341.
Figure341DHCPRelay
PagedescriptionisshowninTable318.
Table318DHCPRealyDescription
ParametersDescriptionDefault
EnableOn/OffOff
DHCPSeverSetDHCPserver;upto4serverscanbeconfiguredN/A
SourceIPAddressoftheinterfaceconnectedtotheDHCPserverN/A
3.3.5.4DHCPClient
Fromnavigationpanel,selectNetwork/DHCP,thenenter“DHCPClientpage,byclickingto
enable,chooseSSIDinterface,asshowninFigure342.
Figure342DHCPClient
3.3.6DNSServices
DNS(DomainNameSystem)isaDDBusedinTCP/IPapplicationprograms,providingswitch
betweendomainnameandIPaddress.ThroughDNS,usercoulddirectlyusesomemeaningful
domainnamewhichcouldbememorizedeasilyandDNSServerinnetworkcouldresolvethe
domainnameintocorrectIPaddress.
Thedevicesupportstoachievefollowingtwofunctionsthroughdomainnameservice
configuration:
 DNSServer:fordynamicdomainnameresolution.
 DNSrelay:thedevice,asaDNSAgent,relaysDNSrequestandresponsemessagebetween
DNSClientandDNSServertocarryoutdomainnameresolutioninlieuofDNSClient.
3.3.6.1DNSServer
DomainNameServer:DNSstandsforDomainNameSystem.ItisacoreserviceoftheInternet.
AsadistributeddatabasethatcanletthedomainnamesandIPaddressesmappingtoeachother,
itallowspeopletomoreconvenientlyaccesstotheInternetwithouttheneedtomemorizetheIP
stringthatcanbedirectlyreadbythecomputer.
Fromnavigationpanel,selectNetwork/DNS,thenenter“DNSServerpage.Inmanualsetupof
DNSServer,ifitisblank,thendialtoobtainDNS.Generallythisitemisrequiredtobesetwhen
WANportusesstaticIP,asshowninFigure343.
Figure343DNSServer
PagedescriptionisshowninTable319.
Table319DNSServerDescription
ParametersDescriptionDefault
PrimaryDNSUserdefinePrimaryDNSaddress N/A
SecondaryDNSUserdefineSecondaryDNSaddressN/A
3.3.6.2DNSRelay
DNSforwarding:DNSforwardingisopenbydefault.Youcansetthespecified[DomainName<=>
IPAddress]toletIPaddressmatchwiththedomainname,thusallowingaccesstothe
appropriateIPthroughaccessingtothedomainname.
Fromnavigationpanel,selectNetwork/DNS,thenenter“DNSRelaypage,asshownin344.
Figure344DNSRelay
PagedescriptionisshowninTable320.
Table320DNSDelayDescription
ParametersDescriptionDefault
EnableDNSRelay On/OffOn
HostDomainNameN/A
IPAddress1SetIPAddress1N/A
IPAddress2SetIPAddress2N/A
OnceDHCPisturnedon,DNSrelaywillbeturnedonasdefaultandcan’tbeturnedoff;toturn
offDNSrely,DHCPServerhastobeclosedfirstly.
3.3.7SMS
SMSpermitsmessagebasedrebootandmanualdialing.
Fromnavigationpanel,selectNetwork/SMS,thenenter“Basic”page.ConfigurePermitactionto
PhoneNumberandclick<Apply&Save>.Afterthatyoucansend“rebootcommandtorestart
thedeviceorcellular1pppup/down”toredialordisconnectthedevice,asshowninFigure
345.
Figure345SMS
PagedescriptionisshowninTable321.
Table321SMSDescription
ParametersDescriptionDefault
EnableOn/OffOff
ModeTEXTandPDUTEXT
PollInterval UserdefinePollInterval 120
SMSAccessControl
IDUserdefineID1
Action Permitandrefuseareavailable Permit
PhoneNumber TrustingphonenumberN/A
3.3.8VLANInterface
VLAN(VirtualLocalAreaNetwork)dividesLANdevicelogicallyintooneandanothernetwork
segment,enableemergingdataexchangetechnologyofvirtualworkgroups.
3.3.8.1VLANConfiguration
Fromnavigationpanel"Network/VLAN"menu,enter"ConfigureVLANParameters"page,click
<Add>buttontoaddtheVLAN,asshowninFigure346.
Figure346ConfigureVLANParameters
PagedescriptionisshowninTable322.
Table322ConfigureVLANParametersDescription
ParametersDescriptionDefault
VLANIDVLANID,UserdefinedNone
VLANInterface
PrimaryIP
Address
IPaddressUserscanconfigureorchangetheprimaryIP
addressneeded
None
Subnet
Mask
Userscanconfigureorchangethesubnetmaskif
necessary
Secondary
IPAddress
IPaddressInadditiontoprimaryIP,usercanalsoconfigure
10SecondaryIPaddresses
None
Subnet
Mask
Userscanconfigureorchangethesubnetmaskif
necessary
3.3.8.2VLANAggregation
Fromnavigationpanel"Network/VLAN”menu,enter"VLANTrunk"page,setVLANportmodefor
WIFUN1050,themodecanbesettoAccessorTrunk,asshowninFigure347.
Figure347VLANTrunk
3.3.9ADSLDialupPPPoE
PPPoEisPointtoPointProtocoloverEthernet.Usersneedwhilemaintainingtheoriginalaccess,
installaPPPoEclient.ThroughPPPoE,aremoteaccessdevicecanrealizecontrolandaccounting
ofeachaccessuser.
EthernetinterfaceconnectionmodeyouconfigurehereisPPPoE,namelytheinterfaceasPPPoE
client.
Fromnavigationpanel"Network/ADSLDialup(PPPoE)"menu,enter"ADSLDialup(PPPoE)"page,
asshowninFigure348.
Figure348PPPoE
PagedescriptionisshowninTable323.
Table323PPPoEDescription
ParametersDescriptionDefault
DialPoolUserdefined,easytorememberandmanageNone
Interface SelectFastethernet0/1orFastethernet0/2Fastethernet0/1
PPPoEList
IDUserdefined,easytorememberandmanage1
PoolIDDialpoolIndexNone
AuthenticationTypeThreeoptions:Auto,PAP,CHAPAuto
UserNameRelevantparametersprovidedbypeer
operator
None
Password Relevantparametersprovidedbypeer
operator
None
LocalIPAddressAssignedIPaddresstoEthernetinterfaceNone
RemoteIPAddressRemoteIPaddressNone
3.3.10LoopbackInterface
LoopbackisusedtorepresentrouterID,becauseifyouuseactiveinterface,whenactivity
interfaceDOWN,routerIDissubjecttoreselection,thatwouldcauseOSPFconvergencetime
slow,thusloopbackinterfaceisgenerallyusedasarouterID.
Loopbackinterfaceislogicalandvirtualinterfaceonrouters.Nodefaultrouterloopbackinterface.
Youcancreateanynumberofloopbackinterfacesasneeded.Theseinterfacesonroutertreated
likephysicalinterface:Youcanassignthemaddressinginformation,includingtheirchoiceto
updatethenetworknumberinrouters,oreventerminateIPconnectiononthem.
Fromnavigationpanel"Network/LoopbackInterface"menu,enter"loopback"page,shownin
Figure349.
Figure349Loopback
PagedescriptionisshowninTable324.
Table324LoopbackInterfaceDescription
ParametersDescriptionDefault
IPAddressUsercannotchange.127.0.0.1
SubnetMaskUsercannotchange.255.0.0.0
MultiIPsettingsInadditiontotheaboveIP,useralsocanbeequipped
withotherIPaddresses
None
SinceloopbackinterfaceisexclusiveofoneIPaddress,subnetmaskisgenerallyrecommended
to255.255.255.255,tosaveresources.
3.3.11DynamicDomainName
DDNSDynamicDomainNameServiceismappinguserdynamicIPaddresstoafixeddomain
nameresolutionservices,whenuserconnecttothenetwork,clientprogramwillpassdynamicIP
addressofthehostthroughinformationtransfertoserverprogramonthehostofservice
providers,theserverprogramisresponsibleforprovidingDNSserviceandrealizingdynamic
domainnameresolution.Thatis,DDNStocapturechangeableIPaddress,thencorresponding
withdomainname,sothatotherInternetuserscancommunicatethroughthedomainname.
Andallfinalcustomerstoremember,istorememberthedynamicdomainnamegivenby
suppliers,withouthavingtopipehowtheyareimplemented.
DDNSfunctionasDDNSclienttools,weneedtoworkwithDDNSserver.Beforeusingthisfeature,
youneedfirsttofindcorrespondingsitessuchas(www.3322.org)andapplyforregistrationofa
domainname.
DDNSservicetypeinclude:DynAccess,QDNS(3322)Dynamic,QDNS(3322)Static,
DynDNSDynamic,DynDNSStaticandNoIP.
Fromnavigationpanel"Network/DDNS"menu,enter"DDNS"page.Setdynamicbindingdomain.
AsshowninFigure350.
Figure350DynamicDomainName
PagedescriptionisshowninTable325.
Table325DynamicDomainNameDescription
ParametersDescriptionDefault
MethodUserdefinedNone
ServiceTypeSelectdynamicdomainnameserviceprovidersDisable
UserNameApplyregistrationDDNSusernameNone
Password ApplyregistrationDDNSusernameNone
Host ApplyregistrationDDNShostNone
SpecifiedInterface
UpdateMethod
Defineddynamicdomainupdatemethod None
IfIProuterdialobtainaprivateaddress,dynamicDNSfunctionisnotavailable.
3.3.12BridgeInterface
Fromnavigationpanel"Network/Bridge"menu,enter"Bridge1"page,setrelatedparameters,as
showninFigure351.
Figure351Bridge1
PagedescriptionisshowninTable326.
Table326EthernetInterfaceParameterDescription
ParametersDescriptionDefault
BridgeIDBridgenumbercanonlybeassignedto1None
BridgeInterface
IPaddressandsubnetmaskof
primaryaddress
ConfigureorchangetheprimaryIPaddressand
subnetmaskasneeded.None
IPaddressandsubnetmaskof
secondaryaddress
InadditiontoprimaryIPfromoutside,clientsalso
canbeequippedwithsecondaryIPaddressand
subnetmask
None
BridgeMember
ClickenablebridgeinterfaceNone
3.4LinkBackup
3.4.1SLA
BasicConceptsandPrinciples
Undernormalcircumstances,theedgeroutercandetectifthelinklinkedtotheISPisinfault.If
thenetworklinkingtooneISPisinfault,anotherISPwillbeusedtotransmitallthedatastreams.
However,ifthelinkofanISPisnormalandtheinfrastructurefails,theedgerouterwillcontinue
tousethisroute.Then,thedataisnolongerreachable.
Onefeasiblesolutionistousingstaticroutingorpolicybasedroutingtofirsttestthereachability
ofimportantdestination.Ifitisunreachable,thestaticroutingwillbedeleted.
ThereachabilitytestcanbeperformedwithInHandSLAtocontinuouslycheckthereachabilityof
ISPandbeassociatedwithstaticrouting.
BasicprinciplesofInHandSLA:1.Objecttrack:Trackthereachabilityofthespecifiedobject.2.
SLAprobe:TheobjecttrackfunctioncanuseInHandSLAtosenddifferenttypesofdetectionsto
theobject.3.Policybasedroutingusingroutemappingtable:Itassociatesthetrackresultswith
theroutingprocess.4.Usingstaticroutingandtrackoptions.
SLAConfigurationSteps
Step1:DefineoneormoreSLAoperations(detection).
Step2:DefineoneormoretrackobjectstotrackthestatusofSLAoperation.
Step3:Definemeasuresassociatedwithtrackobjects.
Fromnavigationpanel,selectLinkBackup>>SLA,thenenter“SLApage,asshowninFigure
352.
Figure352SLA
PagedescriptionisshowninTable327.
Table327SLADescription
ParametersDescriptionDefault
IndexSLAindexorID1
TypeDetectiontype,defaultisicmpecho,theusercannotchange icmpecho
IPAddressDetectedIPaddressNone
DataSize Userdefinedatasize 56
Interval Userdefinedetectioninterval 30
Timeout(ms)Userdefine,Timeoutfordetectiontofail5000
ConnecutiveDetectionretries5
LifeDefaultis“forever,usercannotchange forever
StarttimeDetectionStarttime,select“noworNonenow
3.4.2TrackModule
Trackisdesignedtoachievelinkageconsistingofapplicationmodule,Trackmoduleand
monitoringmodule.Linkagereferstoachievethelinkageamongstdifferentmodulesthroughthe
establishmentoflinkageitems,namely,themonitoringmodulecouldtriggerapplicationmodule
totakeacertainactionthroughTrackmodule.Monitoringmoduleisresponsiblefordetectionof
linkstatus,networkperformanceandnotificationtoapplicationmoduleofdetectionresultsvia
Trackmodule.Oncetheapplicationmodulefindsoutanychangesinnetworkstatus,
correspondingmeasureswillbetakenonatimelybasissoastoavoidinterruptionof
communicationorreductionofservicequality.
Trackmoduleislocatedbetweenapplicationmoduleandmonitoringmodulewithmainfunctions
ofshieldingthedifferencesofdifferentmonitoringmodulesandprovidinguniforminterfacesfor
applicationmodule.
TrackModuleandMonitoringModuleLinkage
Throughconfiguration,thelinkagerelationshipbetweenTrackmoduleandmonitoringmoduleis
established.Monitoringmoduleisresponsiblefordetectionoflinkstatus,networkperformance
andnotificationtoapplicationmoduleofdetectionresultsviaTrackmodulesoastocarryout
timelychangeofthestatusofTrackitem:
Successfuldetection,correspondingtrackitemisPositive
Faileddetection,correspondingtrackitemisNegative
TrackModuleandApplicationModuleLinkage
Throughconfiguration,thelinkagerelationshipbetweenTrackmoduleandapplicationmoduleis
established.Incaseofanychangesintrackitem,anotificationrequiringcorrespondent
treatmentwillbesenttoapplicationmodule.
Currently,applicationmoduleswhichcouldachievelinkagewithtrackmoduleinclude:VRRP,
staticrouting,strategybasedroutingandinterfacebackup.
Undercertaincircumstances,onceanychangesinTrackitemarefounded,ifatimelynotification
issenttoapplicationmodule,thencommunicationmaybeinterruptedduetoroutingsfailurein
timelyrestorationandotherreasons.Forexample,MasterrouterinVRRPbackupgroupcould
monitorthestatusofupstreaminterfacethroughTrack.Incaseofanyfaultinupstreaminterface,
MasterrouterwillbenotifiedtoreduceprioritysothatBackuproutermayascendtothenew
Mastertoberesponsibleforrelayofmessage.Onceupstreaminterfaceisrecovered,solongas
TrackimmediatelysendsamessagetooriginalMasterroutertorecoverpriority,thentherouter
willtakeoverthetaskofmessagerelay.Atthattime,messagerelayfailuremayoccursincethe
routerhasnotrestoredtotheupstreamrouter.Undersuchcircumstances,usertoconfigurethat
onceanychangestakeplaceinTrackitem,delaysaperiodoftimetonotifytheapplication
module.
Fromnavigationpanel,selectLinkBackup/Track,thenenterTrack”page,asshownFigure353.
Figure353TrackM
PagedescriptionisshowninTable328.
Table328TrackDescription
ParametersDescriptionDefault
Index TrackindexorID1
TypeDefault“sla”,Usercannotchangesla
SLAIDDefinedSLAIndexorIDNone
InterfaceDetectinterface’sup/downstatecellular1
NegativeDelay
(m)
Incaseofnegativestatus,switchingcanbedelayedbasedon
thesettime(0representsimmediateswitching),ratherthan
immediateswitching.
0
PositiveDelay
(m)
Incaseoffailurerecovery,switchingcanbedelayedbasedon
thesettime(0representsimmediateswitching),ratherthan
immediateswitching.
0
3.4.3VRRP
Defaultrouteprovidesconvenienceforusersconfigurationoperationsbutalsoimposeshigh
requirementsonstabilityofthedefaultgatewaydevice.Allhostsinthesamenetworksegment
aresetupwithanidenticaldefaultroutewithgatewaybeingthenexthopingeneral.Whenfault
occursongateway,allhostswiththegatewaybeingdefaultrouteinthenetworksegmentcan’t
communicatewithexternalnetwork.
Increasingexitgatewayisacommonmethodforimprovingsystemreliability.Then,theproblem
tobesolvedishowtoselectrouteamongmultipleexits.VRRP(VirtualRouterRedundancy
Protocol)addsasetofroutersthatcanundertakegatewayfunctionintoabackupgrouptoforma
virtualrouter.TheelectionmechanismofVRRPwilldecidewhichroutertoundertakethe
forwardingtaskandthehostinLANisonlyrequiredtoconfigurethedefaultgatewayforthe
virtualrouter.
VRRPwillbringtogetherasetofroutersinLAN.Itconsistsofmultipleroutersandissimilartoa
virtualrouterinrespectoffunction.Accordingtothevlaninterfaceipofdifferentnetwork
segments,itcanbevirtualizedintomultiplevirtualrouters.EachvirtualrouterhasanIDnumber
andupto255canbevirtualized.
VRRPhasthefollowingcharacteristics:
VirtualrouterhasanIPaddress,knownastheVirtualIPaddress.ForthehostinLAN,it
isonlyrequiredtoknowtheIPaddressofvirtualrouter,andsetitastheaddressofthe
nexthopofthedefaultroute.
Hostinthenetworkcommunicateswiththeexternalnetworkthroughthisvirtual
router.
1routerwillbeselectedfromthesetofroutersbasedonprioritytoundertakethe
gatewayfunction.Otherrouterswillbeusedasbackuprouterstoperformthedutiesof
gatewayforthegatewayrouterincaseoffaultofgatewayrouter,thustoguarantee
uninterruptedcommunicationbetweenthehostandexternalnetwork
VRRPNetworkingScheme
AsshowninFigureabove,RouterAandRouterCcomposeavirtualrouter.Thisvirtualrouterhas
itsownIPaddress.ThehostinLANwillsetthevirtualrouterasthedefaultgateway.RouterAor
RouterC,theonewiththehighestpriority,willbeusedasthegatewayroutertoundertakethe
functionofgateway.AnotherrouterwillbeusedasaBackuprouter.
MonitorinterfacefunctionofVRRPbetterexpandsbackupfunction:thebackupfunctioncanbe
offeredwheninterfaceofacertainrouterhasfaultorotherinterfacesoftherouterare
unavailable.
WheninterfaceconnectedwiththeuplinkisatthestateofDownorRemoved,therouteractively
reducesitsprioritysothatthepriorityofotherroutersinthebackupgroupishigherandthusthe
routerwithhighestprioritybecomesthegatewayforthetransmissiontask.
Fromnavigationpanel,selectLinkBackup/VRRP,thenenter“VRRP”page,asshowninFigure
354.
Figure354VRRP
PagedescriptionisshowninTable329.
Table329VRRPDescription
ParametersDescriptionDefault
EnableEnable/DisableEnable
VirtualRouteIDUserdefineVirtualRouteIDNone
InterfaceConfiguretheinterfaceofVirtualRoutevlan1
VirtualIPAddressConfiguretheIPaddressofVirtualRouteNone
PriorityTheVRRPpriorityrangeis0255(alargernumberindicates100
ahigherpriority).Therouterwithhigherprioritywillbe
morelikelytobecomethegatewayrouter.
Advertisement
Interval
Heartbeatpackagetransmissiontimeintervalbetween
routersinthevirtualipgroup
1
PreemptionMode
Iftherouterworksinthepreemptivemode,onceitfinds
thatitsownpriorityishigherthanthatofthecurrent
gatewayrouter,itwillsendVRRPnotificationpackage,
resultinginreelectionofgatewayrouterandeventually
replacingtheoriginalgatewayrouter.Accordingly,the
originalgatewayrouterwillbecomeaBackuprouter.
Enable
TrackIDTraceDetection,selectthedefinedTrackindexorID None
3.4.4InterfaceBackup
Interfacebackupreferstobackuprelationshipformedbetweenappointedinterfacesinthesame
equipment.Whenservicetransmissioncan’tbecarriedoutnormallyduetofaultofacertain
interfaceorlackofbandwidth,rateofflowcanbeswitchedtobackupinterfacequicklyandthe
backupinterfacewillcarryoutservicetransmissionandsharenetworkflowsoastoraise
reliabilityofcommunicationofdataequipment.
Whenlinkstateofmaininterfaceisswitchedfromuptodown,systemwillwaitforpresetdelay
firstinsteadofswitchingtolinkofbackupinterfaceimmediately.Onlyifthestateofmain
interfacestillkeepsdownafterthedelay,systemwillswitchtolinkofbackupinterface.
Otherwise,systemwillnotswitch.
Afterlinkstateofmaininterfaceisswitchedfromdowntoup,systemwillwaitforpresetdelay
firstinsteadofswitchingbacktomaininterfaceimmediately.Onlyifstateofmaininterfacestill
keepsupafterthedelay,systemwillswitchbacktomaininterface.Otherwise,systemwillnot
switch.
Fromnavigationpanel,selectLinkBackup/InterfaceBackup,thenenter“InterfaceBackup”page,
asshowninFigure355.
Figure355InterfaceBackup
PagedescriptionisshowninTable330.
Table330InterfaceBackupDescription
ParametersDescriptionDefault
PrimaryInterfaceTheinterfacebeingusedcellular1
BackupInterfaceInterfacetobeswitchedcellular1
StartupDelaySethowlongtowaitforthestartuptrackingdetection
policytotakeeffect
60
UpDelay
Whentheprimaryinterfaceswitchesfromfailed
detectiontosuccessfuldetection,switchingcanbe
delayedbasedonthesettime(0representsimmediate
switching),ratherthanimmediateswitching.
0
DownDelay
Whentheprimaryinterfaceswitchesfromsuccessful
detectiontofaileddetection,switchingcanbedelayed
basedonthesettime(0representsimmediate
switching),ratherthanimmediateswitching.
0
TrackIDTraceDetection,selectthedefinedTrackindexorIDNone
3.5Routing
3.5.1StaticRoute
Staticroutingisaspecialroutingthatrequiresyourmanualsetting.Aftersettingstaticrouting,
thepackageforthespecifieddestinationwillbeforwardedaccordingtothepathdesignatedby
you.Inthenetworkwithrelativelysimplenetworkingstructure,itisrequiredtosetstaticrouting
toachievenetworkinterworking.Propersettingandusestaticroutingcanimprovethe
performanceofnetworkandcanguaranteebandwidthforimportantnetworkapplications.
Disadvantagesofstaticrouting:Itcannotautomaticallyadapttothechangesinthenetwork
topology.Thenetworkfailureorchangesintopologymaycausetherouteunreachableand
networkinterrupted.Then,youarerequiredtomanuallymodifythesettingofstaticrouting.
StaticRoutingperformsdifferentpurposesindifferentnetworkenvironments.
Whenthenetworkstructureiscomparativelysimple,thenetworkcanworknormally
onlywithStaticRouting.
Whileincomplexnetworkenvironment,StaticRoutingcanimprovetheperformanceof
networkandensurebandwidthforimportantapplication.
StaticRoutingcanbeusedinVPNexamples,mainlyforthemanagementofVPNroute.
3.5.1.1RoutingStatus
Fromnavigationpanel,selectRouting/StaticRouting,thenenter“RouteTablepage,asshownin
Figure356.
Figure356RoutingStatus
3.5.1.2StaticRouting
Fromnavigationpanel,selectRouting/StaticRouting,thenenter“StaticRouting,page.
Add/deleteadditionalRouterstaticrouting.Normallyusersdonnotneedtoconfigurethisitem,
asshownin357.
Figure357StaticRouting
PagedescriptionisshowninTable331.
Table331StaticRoutingDescription
ParametersDescriptionDefault
Destinationaddress EnterthedestinationIPaddressneedtobereachedNone
SubnetMaskEnterthesubnetmaskofdestinationaddressneedtobe
reached
None
InterfaceTheinterfacethroughwhichthedatareachesthe
destinationaddress
None
GatewayIPaddressofthenextroutertobepassedbybeforethe
inputdatareachesthedestinationaddress
None
DistancePriority,smallervaluecontributestohigherpriorityNone
TrackIDSelectthedefinedTrackindexorIDNone
3.5.2DynamicRouting
Theroutingtableentryondynamicrouterisobtainedinaccordancewithcertainalgorithm
optimizationthroughtheinformationexchangebetweentheconnectedrouters,whilethe
routinginformationiscontinuouslyupdatingincertaintimeslotsoastoadapttothe
continuouslychangingnetworkandobtaintheoptimizedpathfindingeffectsatanytime.
InordertoachieveefficientpathfindingofIPpacket,IETFhasdevelopedavarietyof
pathfindingprotocols,includingOpenShortestPathFirst(OSPF)andRoutingInformation
Protocol(RIP)forAutonomousSystem(AS)interiorgatewayprotocol.Thesocalledautonomous
systemreferstothecollectionofhosts,routersandothernetworkdevicesunderthe
managementofthesameentity(e.g.schools,businesses,orISP)
3.5.2.1RoutingStatus
Fromnavigationpanel,selectRouting/DynamicRouting,thenenter“RouteTablepage,asshown
inFigure358.
Figure358RoutingStatus
3.5.2.2RIP
RIP(RoutingInformationProtocol)isarelativelysimpleinteriorgatewayprotocol(IGP),mainly
usedforsmallernetworks.ThecomplexenvironmentsandlargenetworksgeneraldonotuseRIP.
RIPusesHopCounttomeasurethedistancetothedestinationaddressanditiscalled
RoutingCost.InRIP,thehopcountfromtheroutertoitsdirectlyconnectednetworkis0andthe
hopcountofnetworktobereachedthrougharouteris1andsoon.Inordertolimitthe
convergencetime,thespecifiedRoutingCostofRIPisanintegerintherangeof0~15andhop
countlargerthanorequalto16isdefinedasinfinity,whichmeansthatthedestinationnetwork
orhostisunreachable.Becauseofthislimitation,theRIPisnotsuitableforlargescalenetworks.
Toimproveperformanceandpreventroutingloops,RIPsupportssplithorizonfunction.RIPalso
introducesroutingobtainedbyotherroutingprotocols.
ItisspecifiedinRFC1058RIPthatRIPiscontrolledbythreetimers,i.e.Periodupdate,Timeout
andGarbageCollection:
EachrouterthatrunsRIPmanagesaroutingdatabase,whichcontainsroutingentriestoreachall
reachabledestinations.Theroutingentriescontainthefollowinginformation:
Destinationaddress:IPaddressofhostornetwork.
Addressofnexthop:IPaddressofinterfaceoftheroutersadjacentroutertobepassedby
onthewaytoreachthedestination.
Outputinterface:Theoutputinterfacefortheroutertoforwardpackage.
RoutingCost:Costfortheroutertoreachthedestination.
Routingtime:Thetimefromthelastupdateofrouterentrytothepresent.Eachtimethe
routerentryisupdated,theroutingtimewillberesetto0.
Fromnavigationpanel,selectRouting>>DynamicRouting,thenenter“RIPpage,asshownFigure
3591.
Figure3591RIP
AdvancedOptionsareshowninFigure3592.
Figure3592RIP
PagedescriptionisshowninTable332.
Table332RIPDescription
ParametersDescriptionDefault
EnableEnable/DisableDisable
UpdatetimerItdefinestheintervaltosendroutingupdates30
Timeouttimer
Itdefinestheroutingagingtime.Ifnoupdatepackageon
aroutingisreceivedwithintheagingtime,theroutings
RoutingCostintheroutingtablewillbesetto16.
180
ClearTimer
ItdefinesthetimefromthetimewhentheRoutingCost
ofaroutingbecomes16tothetimewhenitisdeleted
fromtheroutingtable.Inthetimeof
GarbageCollection,RIPuses16astheRoutingCostfor
sendingupdatesoftherouting.Incaseoftimeoutof
GarbageCollectionandtheroutingstillhasnotbeen
updated,theroutingwillbecompletelyremovedfrom
theroutingtable.
120
NetworkThefirstIPaddressandsubnetmaskofthesegmentNone
AdvancedOptions
DefaultPostClickEnable,thedefaultinformationwillenable
publishingDisable
DefaultMetricDefaultcostofroutertodestination1
Redirectdirectroute
Direct,Static,andOSProuteagreementintroducedto
RIProuteagreement
Disable
RedirectStatic
RoutEDisable
RedirectOSPRoutEDisable
AdvancedOptions‐Distance/MetricManagement
DistanceSetRIProutingadministrativedistance,priority,the
smallervalue,thepriority 120
IPaddressNetworknumberisthefirstIPaddressinnetwork
segmentNone
SubnetMaskSubnetmask,networknumberissubnetmaskofthefirst
IPaddressinnetworksegmentNone
AccessListApplicationoftheACLIDNone
Redirectrouting
metricRewritedefaultcostfromroutetothedestination None
Ingress/egress
filteringpolicySetredirectionroutefilteringpolicy(in/out)in
Interface SetInterfacerewritingtorouteNone
AccessListApplicationoftheACLIDNone
AdvancedOptions‐RouteFilteringPolicy
PolicyTypeSelectthetypeofpolicytoimplementAccesslist
PolicynameCustompolicynameNone
Ingress/egress
filteringpolicySelectpolicyappliedintheoutboundorinboundin
Interface SelectroutefilteringpolicyenforcementInterfaceNone
SendfiltrationAfterenabling,onlyRIPpacketsendtothedefault
routinginterface.Disable
AdvancedOptions‐Interface
PassiveInterfaceAfterenabling,onlyreceiveRIPpacket,nosendDisable
RIPsendversion SelectSendRIPpacketversionDefault
RIPReceiveversionChoosereceiveRIPpacketversionDefault
Horizontalsplit/
toxicityFlipSelectenablesplithorizonorpoisonreversefunctionNone
AuthenticationSelecttheinterfaceauthenticationmodeNone
Key FillinthecorrespondingkeyNone
AdvancedOptions‐Neighbor
IPaddressNeighborIPaddressNone
3.5.2.3OSPF
OpenShortestPathFirst(OSPF)isalinkstatusbasedinteriorgatewayprotocoldevelopedbyIETF.
RouterID
IfarouterwantstoruntheOSPFprotocol,thereshouldbeaRouterID.RouterIDcanbe
manuallyconfigured.IfnoRouterIDisconfigured,thesystemwillautomaticallyselectoneIP
addressofinterfaceastheRouterID.
Theselectionorderisasfollows:
IfaLoopbackinterfaceaddressisconfigured,thenthelastconfiguredIPaddressof
LoopbackinterfacewillbeusedastheRouterID;
IfnoLoopBackinterfaceaddressisconfigured,choosetheinterfacewiththebiggestIP
adressfromotherinterfacesastheRouterID.
NeighborandNeighboring
AfterthestartupofOSPFrouter,itwillsendoutHellopacketsthroughtheOSPFinterface.Upon
receiptofHellopacket,OSPFrouterwillchecktheparametersdefinedinthepacket.Ifbothare
consistent,aneighborrelationshipwillbeformed.Notallbothsidesinneighborrelationshipcan
formtheadjacencyrelationship.Itisdeterminedbasedonthenetworktype.Onlywhenboth
sidessuccessfullyexchangeDDpacketsandLSDBsynchronizationisachieved,theadjacencyin
thetruesensecanbeformed.LSAdescribethenetworktopologyaroundarouter,LSDBdescribe
entirenetworktopology.
Fromnavigationpanel,selectRouting/DynamicRouting,thenenter“OSPF”page,asshownin
Figure360.
Figure360OSPF
PagedescriptionisshowninTable333.
Table333OSPFDescription
ParametersDescriptionDefault
EnableEnable/DisableDisable
RouterIDRouterIDoftheoriginatingtheLSANone
Interface
Interface Theinterface None
HelloInterval
SendintervalofHellopacket.IfthetheHello
timebetweentwoadjacentroutersisdifferent,
youcannotestablishaneighborrelationship.
10
DeadInterval
DeadTime.IfnoHellopacketisreceivedfrom
theneighbors,theneighborisconsideredfailed.
Ifdeadtimesoftwoadjacentroutersare
different,theneighborrelationshipcannotbe
established.
40
RetransmitInterval
WhentherouternotifiesanLSAtoitsneighbor,
itisrequiredtomakeacknowledgement.Ifno
acknowledgementpacketisreceivedwithinthe
retransmissioninterval,thisLSAwillbe
retransmittedtotheneighbor.
5
LSAtransmissiondelay
timer
OSPFpacketalsoneedtospendtimewhen
travelingonlinks,soLSAagingtime(age)before
transferringtoaddadelaytime,inthe
lowspeedlinksrequireconsiderationof
configuration.
1
Interface‐InterfaceAdvancedOptions
InterfaceNameConfigureOSPFinterfaceparametersNone
PassiveInterfaceAfterenabling,onlyreceiveRIPpacket,nosendDisable
InterfaceCostBydefault,aninterfacecomputesitscost
accordingtothebandwidth10
ProtocolPriorityConfigureOSPFrouterinterfacepriority10
Network
IPAddress IPAddressoflocalnetwork None
SubnetMask SubnetMaskofIPAddressoflocalnetworkNone
AreaIDAreaIDofrouterwhichoriginatingLSA None
3.5.2.4FilteringRoute
Clicknavigationpanel“Routing/DynamicRoutingmenu,enter“FilteringRoute”interface,as
showninFigure361.
Figure361FilteringRoute
PagedescriptionisshowninTable334.
Table334FilteringRouteDescription
ParameterDescriptionDefault
AccessControlList
AccesslistUserdefined None
ActionPermitanddenyPermit
AnyAddress Anyaddressafterclicking,nomatchingIPaddressand
subnetmaskagain
Disable
3.5.3MulticastRouting
Multicastroutingsetsupanacyclicdatatransmissionroutefromdatasourceendtomultiple
receivingends,whichreferstotheestablishmentofamulticastdistributiontree.Themulticast
routingprotocolisusedforestablishingandmaintainingthemulticastroutingandforrelaying
multicastdatapacketcorrectlyandefficiently.
3.5.3.1BasicSettings
Thebasicismainlytodefinethesourceofmulticastrouting.
Fromnavigationpanel,selectRouting/MulticastRouting,thenenter“Basic”page,asshownin
Figure362.
Figure362BasicSettings
PagedescriptionisshowninTable335.
Table335BasicSettingsDescription
ParametersDescriptionDefault
EnableOpen/CloseClose
SourceIPAddressofSource None
Netmask NetmaskofSource 255.255.255.0
3.5.3.2IGMP
IGMP,beingamulticastprotocolinInternetprotocolfamily,whichisusedforIPhosttoreportits
constitutiontoanydirectlyadjacentrouter,definesthewayformulticastcommunicationofhosts
amongstdifferentnetworksegmentswithpreconditionthattherouteritselfsupportsmulticast
andisusedforsettingandmaintainingtherelationshipbetweenmulticastmembersbetweenIP
hostandthedirectlyadjacentmulticastrouting.IGMPdefinesthewayformaintenanceof
memberinformationbetweenhostandmulticastroutinginanetworksegment.
Inthemulticastcommunicationmodel,sender,withoutpayingattentiontotheposition
informationofreceiver,onlyneedstosenddatatotheappointeddestinationaddress,whilethe
informationaboutreceiverwillbecollectedandmaintainedbynetworkfacility.IGMPissucha
signalingmechanismforahostusedinthenetworksegmentofreceivertotherouter.IGMP
informstheroutertheinformationaboutmembersandtherouterwillacquirewhetherthe
multicastmemberexistsonthesubnetconnectedwiththerouterviaIGMP.
Functionofmulticastroutingprotocol:
Discoveringupstreaminterfaceandinterfaceclosesttothesourceforthereasonthat
multicastroutingprotocolonlycarestheshortestroutetothesource.
Decidingtherealdownstreaminterfacevia(S,G).Amulticasttreewillbefinishedafterall
routersacquiretheirupstreamanddownstreaminterfaceswithrootbeingrouterdirectly
connectedwiththesourcehostandbranchesbeingroutersdirectlyconnectedviasubnet
withmemberdiscoveredbyIGMP.
Managingmulticasttree.Themessagecanbetransferredoncetheaddressofnexthopcan
beacquiredbyunicastrouting,whilemulticastreferstorelaymessagegeneratedbysource
toagroup.
Fromnavigationpanel,selectRouting/MulticastRouting,thenenter“IGMP”page,asshownin
Figure363.
Figure363IGMP
PagedescriptionisshowninTable336.
Table336IGMPDescription
ParametersDescriptionDefault
UplinkInterface
UplinkInterfacelinktouppernetworkdeviceinterfaceNone
DownlinkInterface
DownlinkInterfacelinktoterminalequipmentinterfacecellular1
UplinkInterfacelinktouppernetworkdeviceinterfacecellular1
3.6Tools
3.6.1PING
HelptoPINGinternetthroughroute.
Fromnavigationpanel,selectTools/Ping,thenenter“Pingpage,asshowninFigure364.
Figure364PING
PagedescriptionisshowninTable337.
Table337PINGDescription
ParametersDescriptionDefault
HostItrequiresthedestinationhostaddressofPING
detection
192.168.2.1
PingCountSetPingdetectioncount 4
PacketSize Setpacketsizeofpingdetection 32bytes
ExpertOptionsAdvancedparametersofpingcanbeusedNone
3.6.2RoutingDetection
Itisusedtodetectnetworkroutingfailure.
Fromnavigationpanel,selectTools/Traceroute,thenenter“Traceroutepage,asshowninFigure
365.
Figure365Traceroute
PagedescriptionisshowninTable338.
Table338TracerouteDescription
ParametersDescriptionDefault
HostHostaddressneedstodetect 192.168.2.1
MaxiumHopsSetthemaxiumhopsofroutingdetection 20
TimeoutSettimeoutofroutingdetection3secs
ProtocolSelectICMP/UDPUDP
ExpertOptions AdvancedparametersofpingcanbeusedNone
3.6.3LinkSpeedTest
Throughuploadanddownloadfiles,linkspeedcanbetested.
Fromnavigationpanel,selectTools/LinkSpeedTest ,thenenter“LinkSpeedTest ” page,asshown
inFigure366.
Figure366LinkSpeedTest
3.7InstallationGuide
Simplifygeneralconfiguration,wheretherouterwithfast,simple,basicconfiguration,
configurationresultcannotbedisplayedhere,butviewitwhenfinishedinaspecific
correspondingconfigurationsetting.
3.7.1NewDial
Fromnavigationpanel"Wizards/NewCellular"menu,enter"NewCellular"page,asshownin
Figure367.
Figure367NewCellular
PagedescriptionisshowninTable339.
Table339NewCellularDescription
ParametersDescriptionDefault
APNSelectNewWANInterface3gnet
AccessnumberMobileoperatorprovidedialupparameters(pleasechoose
accordingtothelocaloperator)*99***1#
UsernameMobileoperatorprovidedialupparameters(pleasechoose
accordingtothelocaloperator)gprs
passwordMobileoperatorprovidedialupparameters(pleasechoose
accordingtothelocaloperator)
●●●●
Network
Address
Translation
ClickEnable,putprivateIPaddressconvertedintoapublicIP
addressDisable
3.7.2NewIPSecTunnel
Fromnavigationpanel"Wizards/NewIPSecTunnel"menu,enter"NewIPSecTunnel"page,as
showninFigure368.
Table368NewIPSecTunnel
PagedescriptionisshowninTable340.
Table340NewIPSecTunnelDescription
ParametersDescriptionDefault
Basic
TunnelNo.SetTunnelNo.1
InterfaceNameSelectInterfaceNamecellular1
PeerAddressSetVPNpeerIPNone
NegotiationModeOptionalmainmode,aggressivemode.(Usually
selectmainmode)Mainmode
Localsubnet
addressSetIPSeclocalprotectionsubnetNone
LocalSubnetMaskSetIPSeclocalprotectionsubnetmask255.255.255.0
Peersubnet
addressSetIPSecpeerprotectionsubnetNone
PeersubnetmaskSetIPSecpeerprotectionsubnetmask255.255.255.0
Phase1
IKEPolicyOptional3DESMD5DH1or3DESMD5DH2,etc.3DESMD5DH2
IKELifeCycleSetIKELifeCycle86400sec
LocalIdentityType OptionalFQDN,USERFQDN,IPaddressIPaddress
LocalIndex
OnlyinFQDNandUSERFQDN.Fillinthe
appropriateidentificationaccordingtotheselected
identitytype(USERFQDNshouldbeastandard
mailboxformat)
None
PeerIdentityTypeOptionalFQDN,USERFQDN,IPaddressIPaddress
PeerIndex
OnlyinFQDNandUSERFQDN.Fillinthe
appropriateidentificationaccordingtotheselected
identitytype(USERFQDNshouldbeastandard
mailboxformat)
None
AuthenticationChoosetosharekeysanddigitalcertificatessharekeys
Key Authenticationmodeselectsharedkeysshowthe
feature.SetIPSecVPNagreementkeyNone
Phase2
IPSecPolicyOptional3DESMD596or3DES‐SHA196etc.3DESMD596
IPSecLifeCycleSetIPSecLifeCycle3600sec
Createinboundandoutboundrulestoeachtunnelcollection.Ifonlytocreateaoneway
connectionfilter,theruleisnotapplied.
3.8PersonalizationFeatures
Accordingtothespecificneedsofindividualcustomers,privatecustomfunctionscanbe
equippedtoWIFUN1050.
3.8.1NginxServer
Setharddiskserverfunction.Afteropeningcaptiveportalloginb,usershareharddiskdata.
Fromnavigationpanel"PersonalizedFunction/Nginx"menu,enter"Nginx"page,asshownin
Figure369.
Figure369Nginx
3.8.2FileSynchronization
Fromnavigationpanel"PersonalizedFunction/FileSynchronization"menu,enter"File
Synchronization"page,asshowninFigure370.
Figure370FileSynchronization
PagedescriptionisshowninTable341.
Table341FileSynchronizationDescription
ParametersDescriptionDefault
TaskUserdefinedtasknameNone
ServerRsyncServerAddressNone
ServerDirectorySynchronizefilestoRsyncserveraddressNone
LocalDirectorySynchronizefilestolocaldirectoryNone
UsernameRsyncservernameNone
Password RsyncserverpasswordNone
3.8.3GPSLocationInformation
Fromnavigationpanel"PersonalizedFunction/GPSConfig"menu,enter"GPSConfig"page,
showninFigure371.
Figure371GPSSettings
PagedescriptionisshowninTable342.
Table342GPSConfigDescription
ParametersDescriptionDefault
Server uploadlocationinformationserverIPaddressNone
Port Uploadlocationinformationserverport80
PositioningtimeintervalSetpositioningtimeinterval60
UploadLocationSetuploadLocationinformationgap60
informationgap
3.8.4RoamingManagement
3.8.4.1RoamingManagement
Fromnavigationpanel“PersonalizedFunction/RoamingManagement"menu,enter"Roaming
Management"page,showninFigure372.
Figure372RoamingManagement
3.8.4.2UpgradefromAP
Fromnavigationpanel"PersonalizedFunction/RoamingManagement"menu,enter"SlaveAP
Upgrade"page,asshowninFigure373.
Figure373SlaveAPUpgrade
3.9Firewall
Withtheexpansionofnetworkandincreaseinflow,thecontrolovernetworksafetyandthe
allocationofbandwidthbecometheimportantcontentsofnetworkmanagement.Thefirewall
functionoftherouterimplementscorrespondingcontroltodataflowatentrydirection(from
Internettolocalareanetwork)andexitdirection(fromlocalareanetworktoInternet)according
tothecontentfeaturesofmessage(suchas:protocolstyle,source/destinationIPaddress,etc.)
andensuressafeoperationofrouterandhostinlocalareanetwork.
3.9.1AccessControlACL
ACL,namelyaccesscontrollist,implementspermissionorprohibitionofaccessforappointed
dataflow(suchasprescribedsourceIPaddressandaccountnumber,etc.)viaconfigurationofa
seriesofmatchingrulessoastofilterthenetworkinterfacedata.Aftermessageisreceivedby
portofrouter,thefieldisanalyzedaccordingtoACLruleappliedonthecurrentport.Andafter
thespecialmessageisidentified,thepermissionorprohibitionofcorrespondingpacketis
implementedaccordingtopresetstrategy.
ACLclassifiesdatapackagesthroughaseriesofmatchingconditions.Theseconditionscanbe
datapackages’sourceMACaddress,destinationMACaddress,sourceIPaddress,destinationIP
address,portnumber,etc.
ThedatapackagematchingrulesasdefinedbyACLcanalsobeusedbyotherfunctionsrequiring
flowdistinguish.
Fromnavigationpanel,selectFirewall/ACL,thenenter“ACLpage,asshowninFigure3741.
Figure3741AccessControlACL
Click<Add>toaddnewaccesscontrollist,asshowninFigure3742.
Figure3742AccessControlACL
PagedescriptionisshowninTable343.
Table343AccessControlDescription
ParametersDescriptionDefault
Type
StandardACLcanblockallcommunicationflowsfroma
network,orallowallcommunicationflowsfroma
particularnetwork,ordenyallcommunicationflowsofa
protocolstack(e.g.IP)of.
TheextendedACLprovidesawiderrangeofcontrolthan
thatprovidedbythestandardACL.Forexample,ifthe
networkadministratorwantsto"allowexternalWeb
communicationflowstopassthroughandrejectexternal
communicationflows,e.g.FTPandTel ne t ”,theextended
ACLcanbeusedtoachievetheobjective.Thestandard
ACLcannotbecontrolledsoprecisely.
Extended
IDUserdefineNone
ActionPermit/Deny Permit
ProtocolAccessControlProtocolip
SourceIPAddress IPAddressofSourceNone
DestinationIP IPAddressofDestinationNone
DestinationIP
addressDestinationnetworkaddressNone
DestinationInvert
Mask DestinationaddressmaskinvertedNone
LoggingClickEnable,thesystemwillrecordaccesscontrolona
logDisable
Description EasytorecordcontrolaccessparametersonalogNone
NetworkInterfacelist
InterfaceNameSelectInterfaceNamecellular1
Rules Selectinbound,outboundandmanagementrulesnone
3.9.2NAT
NATcanachieveInternetaccessbymultiplehostswithintheLANthroughoneormorepublic
networkIPaddresses.ItmeansthatfewpublicnetworkIPaddressesrepresentmoreprivate
networkIPaddresses,thussavingpublicnetworkIPaddresses.
Fromnavigationpanel,selectFirewall/NAT,thenenter“NAT”page,asshowninFigure3751.
Figure3751NAT
NATruleistoapplyACLtoaddresspool,onlymatchingtheACLaddressbeforeconversion.
Click<Add>toaddnewNATrules,asshowninFigure3752.
Figure3752NAT
PagedescriptionisshowninTable344.
Table344NATDescription
ParametersDescriptionDefault
Action
SNATSourceNATTranslateIPpacket'ssourceaddress
intoanotheraddress
DNATDestinationNAT:Mapasetoflocalinternal
addressestoasetoflegalglobaladdresses.
1:1NATTransferIPaddressonetoone.
SNAT
SourceNetwork
InsideInsideaddress
OutsideOutsideaddress
Inside
TranslationTypeSelecttheTranslationTypeIPtoIP
PrivatenetworkIPaddressreferstotheIPaddressofinternalnetworkorhost,whilepublic
networkIPaddressisagloballyuniqueIPaddressontheInternet.
RFC1918threeIPaddressblocksfortheprivatenetworkasfollows:
ClassA:10.0.0.0~10.255.255.255
ClassB:172.16.0.0~172.31.255.255
ClassA:192.168.0.0~192.168.255.255
TheaddresseswithintheabovethreerangeswillnotbeallocatedontheInternet.Therefore,
theycanbefreelyusedincompaniesorenterpriseswithouttheneedtomakeapplicationtothe
operatororregistrationcenter
3.10QoS
InthetraditionalIPnetwork,allpacketsaretreatedequallywithoutdistinction.Eachnetwork
deviceusesfirstinfirstoutstrategyforpacketprocessing.Thebesteffortnetworksendspackets
tothedestination,butitcannotguaranteetransmissionreliabilityanddelay.
QoScancontrolnetworktraffic,avoidandmanagenetworkcongestion,andreducepacket
droppingrate.Someapplicationsbringconveniencetousers,buttheyalsotakeupalotof
networkbandwidth.ToensureallLANuserscannormallygetaccesstonetworkresources,IP
trafficcontrolfunctioncanlimittheflowofspecifiedhostonlocalnetwork.
QoSprovidesuserswithdedicatedbandwidthanddifferentservicequalityfordifferent
applications,greatlyimprovingthenetworkservicecapabilities.Userscanmeetvarious
requirementsofdifferentapplicationslikeguaranteeinglowlatencyoftimesensitivebusiness
andbandwidthofmultimediaservices.
QoScanguaranteehighprioritydataframesreceiving,acceleratehighprioritydataframe
transmission,andensurethatcriticalservicesareunaffectedbynetworkcongestion.IR900
supportsfourservicelevels,whichcanbeidentifiedbyreceivingportofdataframe,Tagpriority
andIPpriority.
Fromnavigationpanel,selectQos/TrafficControl,thenenter“TrafficControl”page,asshownin
Figure376.
Figure376QoS
PagedescriptionisshowninTable345.
Table345QoSDescription
ParametersDescriptionDefault
Type
NameNameName
AnyPackets ClickStartupforflowcontroltoanypackets Disable
Source SourceaddressofflowcontrolN/A
Destination DestinationaddressofflowcontrolN/A
Protocol ClicktoselectprotocolstyleN/A
Policy
NameNameofuserdefinedflowcontrolstrategyN/A
Classifier NameofstyledefinedaboveN/A
GuaranteedBandwidth
Kbps
Userdefinedguaranteedbandwidth
N/A
MaximumBandwidthKbpsUserdefinedmaximumbandwidthN/A
LocalPriorityLocalpriorityofselectionstrategyN/A
ApplyQos
InterfaceSelectionofflowcontrolinterfacecellular1
IngressMaxbandwidth
Kbps
Userdefine,biggerthanmaximumbandwidthof
inputstrategy
N/A
EgressMaxbandwidthKbps
Userdefine,biggerthanmaximumbandwidthof
outputstrategy
N/A
IngressPolicy NameofpolicydefinedaboveN/A
EgressPolicyNameofpolicydefinedaboveN/A
3.11VPN
VPNisanewtechnologythatrapidlydevelopedinrecentyearswiththeextensiveapplicationof
Internet.Itisforbuildingaprivatededicatednetworkonapublicnetwork.'Virtuality"mainly
referstothatthenetworkisalogicalnetwork.
TwoBasicFeaturesofVPN:
Private:theresourcesofVPNareunavailabletounauthorizedVPNusersontheinternet;
VPNcanensureandprotectitsinternalinformationfromexternalintrusion.
Virtual:thecommunicationamongVPNusersisrealizedviapublicnetworkwhich,
meanwhilecanbeusedbyunauthorizedVPNuserssothatwhatVPNusersobtainedisonly
alogisticprivatenetwork.ThispublicnetworkisregardedasVPNBackbone.
FundamentalPrincipleofVPN
ThefundamentalprincipleofVPNindicatestoencloseVPNmessageintotunnelwithtunneling
technologyandtoestablishaprivatedatatransmissionchannelutilizingVPNBackbonesoasto
realizethetransparentmessagetransmission.
Tunnelingtechnologyenclosestheotherprotocolmessagewithoneprotocol.Also,encapsulation
protocolitselfcanbeenclosedorcarriedbyotherencapsulationprotocols.Totheusers,tunnelis
logicalextensionofPSTN/linkofISDN,whichissimilartotheoperationofactualphysicallink.
ThecommontunnelprotocolsincludeL2TP,PPTP,GRE,IPSec,MPLS,etc.
3.11.1IPSec
AmajorityofdatacontentsarePlaintextTransmissionontheInternet,whichhasmanypotential
dangerssuchaspasswordandbankaccountinformationstolenandtampered,useridentity
imitated,sufferingfrommaliciousnetworkattack,etc.AfterdisposalofIPSeconthenetwork,it
canprotectdatatransmissionandreduceriskofinformationdisclosure.
IPSecisagroupofopennetworksecurityprotocolmadebyIETF,whichcanensurethesecurityof
datatransmissionbetweentwopartiesontheInternet,reducetheriskofdisclosureand
eavesdropping,guaranteedataintegrityandconfidentialityaswellasmaintainsecurityofservice
transmissionofusersviadataoriginauthentication,dataencryption,dataintegrityand
antireplayfunctionontheIPlevel.
IPSec,includingAH,ESPandIKE,canprotectoneandmoredateflowsbetweenhosts,between
hostandgateway,andbetweengateways.ThesecurityprotocolsofAHandESPcanensure
securityandIKEisusedforciphercodeexchange.
IPSeccanestablishbidirectionalSecurityAllianceontheIPSecpeerpairstoformasecureand
interworkingIPSectunnelandtorealizethesecuretransmissionofdataontheInternet.
3.11.1.1IPSecPhase1
IKEcanprovideautomaticnegotiationciphercodeexchangeandestablishmentofSAforIPSecto
simplifytheoperationandmanagementofIPSec.TheselfprotectionmechanismsofIKEcan
completeidentityauthenticationandkeydistributioninaninsecurenetwork.
Fromnavigationpanel,selectVPN/IPSec,thenenter“IPSecPhase1”page,asshowninFigure
377.
Figure377IPSecPhase1
PagedescriptionisshowninTable346.
Table346IPSecPhase1Description
Parameters DescriptionDefault
Keyring
Name Userdefinekey N/A
IPAddress EndtoendIPaddressN/A
SubnetMaskEndtoendsubnetmaskN/A
KeyUserdefinekeycontentN/A
IKEPolicy
Identification PolicyidentificationofuserdefinedIKE N/A
Authentication Alternativeauthentication:sharedkeyanddigitalcertificate
Shared
key
Encryption
3des:encryptplaintextwiththreeDESciphercodesof64bit
des:encrypta64bitplaintextblockwith64bitciphercode
Aes:encryptplaintextblockwithAESAlgorithmwithcipher
codelengthof128bit,192bitor256bit
3des
Hash
md5:inputinformationofarbitrarylengthtoobtain128bit
messagedigest.
sha1:inputinformationwithshorterlengthofbittoobtain
160bitmessagedigest.
Comparingboth,md5isfasterwhilesha1issafer.
md5
DiffieHellman
KeyExchange
Threeoptions:Group1,Group2andGroup5Group2
LifetimeActivetimeofpolicy 86400
ISAKMPProfile
Name NameofuserdefinedISAKMPProfileN/A
Negotiation
Mode
Mainmode:asanexchangemethodofIKE,mainmodeshallbe
establishedinthesituationwherestricteridentityprotectionis
required.
Aggressivemode:asanexchangemethodofIKE,aggressive
Main
mode
modeexchangingfewermessage,canacceleratenegotiationin
thesituationwhereordinaryidentityprotectionisrequired.
LocalIDTypeSelecttypeoflocalidentification
IP
Address
LocalIDThelocalIDcorrespondingtotheselectedlocalIDN/A
RemoteID
Type
SelecttypeofRemoteID
IP
Address
RemoteID
TheRemoteIDcorrespondingtotheselectedpeer
identification
N/A
Policy ThedefinedstrategyidentificationintheIKEStrategylist
N/A
KeyRingThedefinedkeysetinthekeysetlist
N/A
DPDInterval
UsedfordetectionintervalofIPSecneighborstate.
AfterinitiatingDPD,IfreceivingendcannotreceiveIPSec
cryptographicmessagesentbypeerendwithinintervalof
triggeringDPD,receivingendcanmakeDPDcheck,send
requestmessagetooppositeendautomatically,detectwhether
IKEpeerpairexists.
N/A
DPDTimeout
ReceivingendwillmakeDPDcheckandsendrequestmessage
automaticallytooppositeendforcheck.Ifitdoesnotreceive
IPSeccryptographicmessagefrompeerendbeyondtimeout,
ISAKMPProfilewillbedeleted.
N/A
Thesecuritylevelofthreeencryptionalgorithmsrankssuccessively:AES,3DES,DES.The
implementationmechanismofencryptionalgorithmwithstrictersecurityiscomplexandslow
arithmeticspeed.DESalgorithmcansatisfytheordinarysafetyrequirements.
3.11.1.2IPSecPhase2
Fromnavigationpanel,selectVPN>>IPSec,thenenter“IPSecPhase2”page,asshowninFigure
378.
Figure378IPSecPhase2
PagedescriptionisshowninTable347.
Table347IPSecIPSecPhase2Description
ParametersDescriptionDefault
Name UserdefineTransformSetname N/A
Encapsulation
Chooseencapsulationformsofdatapacket
AH:protectintegrityandauthenticityofdatapacketfrom
hackerinterceptingdatapacketorinsertingfalsedata
packetontheinternet.
ESP:encrypttheuserdataneedingprotection,andthen
encloseintoIPpacketforthepurposeofconfidentialityof
data.
esp
Encryption Threeoptions:AES,3DES,DES3des
AuthenticationAlternativeauthentication:md5andsha1md5
IPSecMode
TunnelMode:besidessourcehostanddestinationhost,
specialgatewaywillbeoperatedwithpasswordtoensure
thesafetyfromgatewaytogateway.
TransmissionMode:sourcehostanddestinationhostmust
directlybeoperatedwithallpasswordsforthepurposeof
higherworkefficiency,butcomparingwithtunnelmodethe
Tunnel
Mode
securitywillbeinferior.
3.11.1.3IPSecConfiguration
Fromnavigationpanel,selectVPN/IPSec,thenenter“IPSecSettingpage,asshownin
Figure379.
Figure379IPSecConfiguration
PagedescriptionisshowninTable348.
Table348IPSecConfigurationDescription
ParametersDescriptionDefault
IPSecProfile
NameUserdefineIPSecProfilenameN/A
ISAKMPProfile
ISAKMPProfilenamesdefinedinthefirststageof
parametersofIPSec
N/A
TransformSet
TransformSetdefinedinthefirststageofparametersof
IPSec
N/A
PerfectForward
Security(PFS)
Meanstherevealofoneciphercodewillnotendanger
informationprotectedbyotherciphercodes.
Disable
LifetimeLifetimeofIPSecProfile3600
RekeyMargin(S)Reconnectiontimeforthesecondstage540
RekeyFuzz()
Deviationpercentageofthereconnectiontimeforthe
secondstage
100
SIMCardBinding
Withthisfunctionactivated,successfuldialingofthe
cardwithwhichIPSecisbondedisapreconditionforthe
useofIPSec.
Disable
CryptoMap
NameUserdefinenameofcryptomapN/A
IDUserdefineIDofcryptomapN/A
PeerAddressPeerIPAddressN/A
ACLIDIDofACLdefinedinACLoffirewallN/A
ISAKMPProfile
ISAKMPProfilenamesdefinedinthefirststageof
parametersofIPSec
N/A
TransformSet
TransformSetdefinedinthefirststageofparametersof
IPSec
N/A
PerfectForward
Security(PFS)
Meanstherevealofoneciphercodewillnotendanger
informationprotectedbyotherciphercodes.
Disable
LifetimeValidityofCryptoMap3600
RekeyMargin(S)Reconnectiontimeforthesecondstage540
RekeyFuzz()
Deviationpercentageofthereconnectiontimeforthe
secondstage
100
ParametersDescriptionDefault
Interface<==>CryptoMap
MAPInterface SelectInterfaceNamecellular1
MapName
SelectfromdefinednamesofCryptoMap.Onenameis
matchedwithseveralmarks.
none
3.11.1.4IPSecVPNConfigurationExample
BuildingasecurechannelbetweenRouterAandRouterBtoensurethesecuredataflow
betweenCustomerBranchA‘ssubnet(192.168.1.0/24)andCustomerBranchB‘ssubnet
(172.16.1.0/24).SecurityprotocolisESP,theencryptionalgorithmis3DES,andauthentication
algorithmisSHA.
Thetopologyisasfollows:
ConfigurationSteps:
(1)RouterASettings
Step1:IPSecSettingPhase1
Fromnavigationpanel,selectVPN/IPSec,thenenterIPSecSettingPhase1page,asshown
below.
NoneedtofillinLocalIDTypeandRemoteIDType.
Step2:IPSecSettingPhase2
Fromnavigationpanel,selectVPN/IPSec,thenenter“IPSecSettingPhase2”page,asshown
below.
Step3:IPSecSetting
Fromnavigationpanel,selectVPN/IPSec,thenenter“IPSecSettingpage,asshownbelow.
IPSecProfilesettingisneededonlywhenitsDMVPN.
(2)RouterBSettings
Step1:IPSecSettingPhase1
Fromnavigationpanel,selectVPN/IPSec,thenenter“IPSecSettingPhase1”page,asshown
below.
Step2:IPSecSettingPhase2
Fromnavigationpanel,selectVPN/IPSec,thenenter“IPSecSettingPhase2”page,asshown
below.
Step3:IPSecSetting
Fromnavigationpanel,selectVPN/IPSec,thenenter“IPSecSettingpage,asshownbelow.
(3)VPNStatusChecking
Fromnavigationpanel,selectVPN/IPSec,thenenter“IPSecStatus”page,asshownbelow.
3.11.2GRE
GenericRouteEncapsulation(GRE)definestheencapsulationofanyothernetworklayerprotocol
onanetworklayerprotocol.GREcouldbeusedastheL3TPofVPNtoprovideatransparent
transmissionchannelforVPNdata.Insimpleterms,GREisatunnelingtechnologywhichprovides
achannelthroughwhichencapsulateddatamessagecouldbetransmittedandencapsulationand
decapsulationcouldberealizedatbothends.GREtunnelapplicationnetworkingshownasthe
followingfigure:
AlongwiththeextensiveapplicationofIPv4,tohavemessagesfromsomenetworklayerprotocol
transmittedonIPv4network,thosemessagescouldbyencapsulatedbyGREtosolvethe
transmissionproblemsbetweendifferentnetworks.
InfollowingcircumstancesGREtunneltransmission:
GREtunnelcouldtransmitmulticastdatapacketsasifitwereatruenetworkinterface.
SingleuseofIPSeccannotachievetheencryptionofmulticast.
Acertainprotocoladoptedcannotberouted.
AnetworkofdifferentIPaddressshallberequiredtoconnectothertwosimilarnetworks.
GREapplicationexample:combinedwithIPSectoprotectmulticastdata
GREcanencapsulateandtransmitmulticastdatainGREtunnel,butIPSec,currently,couldonly
carryoutencryptionprotectionagainstunicastdata.Incaseofmulticastdatarequiringtobe
transmittedinIPSectunnel,aGREtunnelcouldbeestablishedfirstforGREencapsulationof
multicastdataandthenIPSecencryptionofencapsulatedmessagesoastoachievethe
encryptiontransmissionofmulticastdatainIPSectunnel.
Fromnavigationpanel,selectVPN/GRE,thenenter“GRE”page,asshowninFigure380.
Figure380GRESettings
PagedescriptionisshowninTable349.
Table349GREDescription
ParametersDescriptionDefault
Enable Clicktoopen Open
Index SetGREtunnelname None
NetworkTypeSelectGREnetworktype peerto
peer
LocalVirtualIPSetLocalVirtualIPAddressNone
PeerVirtualIPSetPeerVirtualIPAddressNone
SourceTypeSelectsourcetypeandsettheaccordingIPaddressorinterfaceIP
LocalIPSetLocalIPAddressNone
PeerIPSetPeerIPAddress None
KeySetthekeyoftunnelNone
MTUSetthemaximumtransmission,unitinbytesNone
EnableNHRP
NextHopResolutionProtocol,usedtoconnectto
nonbroadcastmultipleaccess(NBMA)formulasubnetwork
sourcestation(hostorrouter)decidedtoreach"NBMAnext
hop"internetworkinglayeraddressandNBMAsubnetwork
betweenthedestinationstationaddress.
Enable
Description AdddescriptionNone
3.11.3L2TP
L2TP,oneofVPDNTPs,hasexpandedtheapplicationsofPPP,knownasaveryimportantVPN
technologyforremotedialinusertoaccessthenetworkofenterpriseheadquarters.
L2TP,throughdialupnetwork(PSTN/ISDN),basedonnegotiationofPPP,couldestablishatunnel
betweenenterprisebranchesandenterpriseheadquarterssothatremoteuserhasaccesstothe
networkofenterpriseheadquarters.PPPoEisapplicableinL2TP.Throughtheconnectionof
EthernetandInternet,aL2TPtunnelbetweenremotemobileofficersandenterprise
headquarterscouldbeestablished.
L2TPLayer2TunnelProtocol,encapsulatesprivatedatafromusernetworkattheheadofL2PPP.
Noencryptionmechanismisavailable,thusIPSesisrequiredtoensuresafety.
 MainPurpose:branchesinotherplacesandemployeesonabusinesstripcouldaccessto
thenetworkofenterpriseheadquarterthroughavirtualtunnelbypublicnetworkremotely.
Fromnavigationpanel,selectVPN/L2TP,thenenter“L2TPClientpage,asshowninFigure381.
Figure381L2TPClient
PagedescriptionisshowninTable350.
Table350L2TPClientDescription
ParametersDescriptionDefault
L2TPClass
NameUserdifineL2TPClassNameNone
AuthenticationClickEnable,peerauthenticationisrequiredtonetwork
connectionwhenenable.Disable
HostNameNetworkconnectiontolocalhostname,notto
configure.None
Tunnel
Authenticationkey
Whenthetunnelmustbeconfiguredtoenablethe
authentication,clickauthenticationkey,oryouwillnot
needtoconfigure.
None
PseudowireClass
Name UserdifinePseudowireClassNameNone
L2TPClassL2TPClassnameNone
SourceInterfaceSeclectsourceinterfacenamecellular1
L2TPTunnel
Enable Clicktoenable Enable
IndexAutomaticgenerated1
L2TPServerSetL2TPServeraddressNone
PseudowireClassPseudowireClassnameNone
AuthenticationType SelectAuthenticationType Auto
UsernamePeerServerusername None
PasswordPeerServerpasswordNone
LocalIPAddress SetlocalIPaddress,orautomaticallyallocatedbypeer
server.
None
RemoteIPAddressSetremoteIPaddres,ornotNone
3.11.4OPENVPN
SinglepointparticipatingintheestablishmentofVPNisallowedtocarryoutIDverificationby
presetprivatekey,thirdpartycertificateorusername/password.OpenSSLencryptionlibraryand
SSLv3/TLSv1protocolaremassivelyused.
InOpenVpn,ifauserneedstoaccesstoaremotevirtualaddress(addressfamilymatchingvirtual
networkcard),thenOSwillsendthedatapacket(TUNmode)ordataframe(TAPmode)tothe
visualnetworkcardthroughroutingmechanism.Uponthereception,serviceprogramwill
receiveandprocessthosedataandsendthemoutthroughouternetbySOCKET,owingtowhich,
theremoteserviceprogramwillreceivethosedataandcarryoutprocessing,thensendthemto
thevirtualnetworkcard,thenapplicationsoftwarereceiveandaccomplishacomplete
unidirectionaltransmission,viceversa.
Fromnavigationpanel,selectVPN/OPENVPN,thenenter“OPENVPNClient”page,asshownin
Figure382.
Figure382OPENVPNClient
PagedescriptionisshowninTable351.
Table351OPENVPNOPENVPNClientDescription
ParameterDescriptionDefault
EnableClickEnableEnable
IDSetchannelIDNone
ServerIPAddressSetpeerserverIPaddresssNone
PortNumberSetpeerserverportnumber1194
AuthenticationType Selectandconfigureauthenticationtypeparameters
oftypecertification
User
name/Password
UsernameKeepconsistencywithserver None
Password KeepconsistencywithserverNone
Channeldescription userdefinechanneldescriptionNone
AdvancedOptions
SourcePortSelectsourceportnameNone
NetworkTypeSelectnetworktypenet30
PortTypeSelectdataformissuedfromtheinterface.tun‐
packet,tap‐dataframetun
ProtocolType Keepconsistencywithserverprotocoludp
AdvancedOptions
Encryption
AlgorithmkeepconsistencywithserverDefault
LZOCompressionClickEnableOff
ConnectionTesting
Interval
Setconnectingtestingtimeinterval
None
ConnectionTesting
Overtime
Setconnectingtestingovertime
None
Expert
Configuration
Setexpertoption:blankadvisable
None
Importconfigurationscanbedirectlyimportedintotheconfigureddocumentsgeneratedfrom
backendserverandmanualconfigurationofOPENVPNcustomerendparameterisinnoneed
afterimport.
3.11.5CertificateManagement
Fromnavigationpanel,selectVPN/CertificateManagement,thenenter“Certificate
Management”page,asshowninFigure383.
Figure383CertificateManagement
PagedescriptionisshowninTable352.
Table352CertificateManagementDescription
ParameterDescriptionDefault
Forcedtoreapply
Ifthecertificatehasnotexpired,butneedtoreapply,click
forcedtoreapply,reconfigurethecertificaterequest
parameter.
Disable
RequestStatussuccessfulapplication,"RequestStatus"shows:
CompletionInitiation
Certificate
ProtectionKey
Setcertificateprotectionkey
None
Certificate
ProtectionKey
Confirmation
Confirmcertificateprotectionkey None
ServerURLSetcertificateserverIPNone
CertificatenameSetcertificatenameNone
FQDNSetfulldomainnameNone
UnitName1Setunitname1None
UnitName2Setunitname2None
DomainName SetdomainnameNone
SerialNumberSetapplicationcertificateserialnumberNone
Authentication
PasswordSetauthenticationpasswordNone
Authentication
Password
Confirmation
Confirmauthenticationpassword
None
HostIPSetrouteraddressintheuseofcertificateapplicationNone
RSAKeylengthSetRSAkeylength1024
QueryIntervalSetqueryinterval60sec
QueryTimeoutSetquerytimeout3600sec
3.12ConfigurationWizard
AfterlogintheconfigurationpageviaWeb,click“ConnectInternet”toenterconfigurationpage
below:
Figure3121ConnectInternet
Pagedescription:
Table3121ConnectInternetConfigurationDescription
ParametersDescriptionDefault
InterfaceType:3G/LTE,ADSL,DHCPandStaticIPAddress
3G/LTE
APNProvidedbylocaloperator3gnet
UsernameProvidedbylocaloperatorgprs
PasswordProvidedbylocaloperatorgprs
DialedNumbersProvidedbylocaloperator*99***1#
ADSL
UsernameProvidedbylocaloperatorN/A
PasswordProvidedbylocaloperatorN/A
NoconfigurationforDHCP
StaticIPAddress
IPAddress Userdefine N/A
SubnetmaskUserdefine255.255.255.0
GatewayUserdefineN/A
PrimaryDNSUserdefineN/A
SecondaryDNSUserdefineN/A
Savetheconfigurationandclick<NextStep>toenter“CloudPlatform”configurationpageas
shownbelow:
Figure3122CloudManagementPlatform
Table3122CloudManagementPlatformConfigurationDescription
ParametersDescriptionDefault
Platform
Address
Theaddressandportnumberofcloud
platformrainbow.inhand.com.cn80
DemoModeClicktoenableDisable
4.ApplicationScenarios
PlaceonabusoneInhandIPortal3000server,usingWIFIwirelesscoverageinsidethecar,built
3G/4GmoduletoaccesstheInternet.Passengers’smartphones,tabletandnotebooksandother
intelligentterminalaccesstotheWIFIhotspot,WIFUN1050withPortalauthenticationmethod
pushspecifiedpagetothemobileterminal,toprovideinformation,downloads,entertainment
andotherinformationservicesandInternetservices.Informationservicesavailableatthelocal
storeWIFUN1050enhanceuseraccessexperience,synchronousupdateCenterandlocalcontent
via3G/4G.

Appendix1Troubleshooting
Thismanualdescribesonlyasimpleroutertroubleshootingmethod,ifstillcannotruleout,you
cangettheservicethroughTable11.
1) CannotlogonlocallyrouterthroughWebsettingpage?
useMSDOSPingcommandtocheckthenetworkconnection
a.Ping127.0.0.1usedtocheckthecomputermanagementTCP/IPprotocolisinstalled.
b.PingcollectiontoFEinterfaceIPaddresswhichdirectlyconnectedtorouter,usedto
checkwhethercollectionofmanagementcomputertorouter.
Numberofusersallowedtomanagetherouterhasreachedthemaximum(foruptofour
userstosimultaneouslylog),pleasetryagainlater.
PleasechecktheWebbrowserissetupaproxyserverordialupconnection,ifany,unset.
SeeabovePCfirewallsettingsareusedtoconfiguretherouter,whethershieldingfunction.
PleasecheckwhetherIEisequippedwiththirdpartyplugins(eg:3721,IEpartner,etc.)itis
recommendedtoconfigureafteruninstalling.
2) WIFUN1050ispoweredon,butcannotaccessInternet?
Pleasecheck
WhethertheWIFUN1050isinsertedwithaSIMcard.
WhethertheSIMcardisenabledwithdataservice,whethertheserviceoftheSIMcardis
suspendedbecauseofanoverduecharge.
Whetherthedialupparameters,e.g.APN,dialupnumber,account,andpasswordare
correctlyconfigured.
WhethertheIPAddressofyourcomputeristhesamesubnetwithWIFUN1050andthe
gatewayaddressisWIFUN1050LANaddress.
3) LANusersdroppedcable,cannotaccesstheInternet?
Checkswitchcablecollectedtorouter,andWANportnetworkcable,ifthereisloosening.
Logintotherouter'sWebsetuppage,checkaccesscontrollist,tocheckwhethertheIP
addressofasegmentisnotallowedtoaccesstheInternet.
4) WIFUN1050ispoweredon,haveapingtodetectWIFUN1050fromyourPCandfindpacket
loss?
Pleasecheckifthenetworkcrossovercableisingoodcondition.
5) ForgetthesettingafterrevisingIPaddressandcannotconfigureWIFUN1050?
Method1:connectWIFUN1050withserialcable,configureitthroughconsoleport.
Method2:WIFUN1050ispoweredon,pressandholdRESETResetbutton(untilERRORlights),
releasetheRESETbutton(ERRORlampisoff),pressandholdtheRESETbuttonagain(untilthe
ERRORindicatorblinks),andyoucanrestorethefactorydefaultsettings.
Afterapplyingtheabovetwomethods,configuretheWIFUN1050.
6) AfterWIFUN1050ispoweredon,itfrequentlyautorestarts.Whydoesthishappen?
Pleasecheck:
Whetherthemoduleworksnormally.
WhethertheWIFUN1050risinsertedwithaSIMcard.
WhethertheSIMcardisenabledwithdataservice,whethertheserviceoftheSIMcardis
suspendedbecauseofanoverduecharge.
Whetherthedialupparameters,e.g.APN,dialupnumber,account,andpasswordare
correctlyconfigured.
Whetherthesignalisnormal.
Whetherthepowersupplyvoltageisnormal.
7) WIFUN1050ispoweredon,butthePowerLEDisnoton?
Pleasecheck:
Checkthefuseisburnedout.
Checksupplyvoltage,andthepolarityisconnectedcorrectly.
8) WIFUN1050ispoweredon,connectedtothePC,WhyEthernetportlightisnoton?
Pleasecheck:
Checkthenetworkcableisnormal.
NICcharacteristiconthePCissetto10/100M,fullduplex.
9) WIFUN1050ispoweredon,whenconnectedwithPC,theNetworkLEDisnormalbut
cannothaveapingdetectiontotheWIFUN1050?
CheckiftheIPAddressofthePCandWIFUN1050areinthesamenetworksegmentand
WIFUN1050IPasgatewayaddress.
10) WIFUN1050dialupalwaysfails,Icannotfindoutwhy?
PleaserestoreWIFUN1050tofactorydefaultsettingsandconfiguretheparametersagain.
Table11SalesService
TroubleDescriptionObtainservice
Hardware
failure
Forexample:WIFUN1050doesnotappear
normalpower,didnotplugthenetworkcable
whileEthernetportlightwaslitandother
issues.
PleasecontactInhand
TechnicialSupportHotline
forhelp:01064391099
Software
Prolem
Forexample:WIFUN1050featureisunavailable,
abnormalorconfigurationadvice.
PleasecontactInhand
TechnicialSupportHotline
forhelp:01064391099

Appendix2InstructionofCommandLine
OperatingstatusLED:
POWERSTATUSWARNERROR
Description
Thepower
LED(red)
StatusLED
(green)
AlarmLED
(yellow)
Error
LED(red)
onononoffPowerstatus
onblinkonoffPowerSuccess
onblinkblinkoffDialing
onblinkoffoffDialingSuccess
onblinkblinkblinkBeingupgraded
onblinkonblinkResetSuccess
SignalStatusLEDandDescription:
Signal
Status
GreenLED1
Signal
Status
GreenLED2
Signal
Status
GreenLED3
Description
offoffoffNosignalwasdetected
onoffoff
19signalcondition(inthiscasesignalconditions
describeproblems,pleasechecktheantennais
installedintact,thesignalsituationintheregionis
good)
ononoff
1019signalcondition(inthiscaseillustratesignal
statusisnormal,WIFUN1050canbeusednormally)
ononon
2031signalcondition(inthiscaseillustratethe
signalingoodcondition)
EthernetPortStatusLEDandDescription:
GreenLEDDescription
onThenetworkportis100M,inanormalstate,nodatatransmission
blinkThenetworkportis100M,inanormalstate,indatatransmission
offNoconnection
MODEMLEDandDescription
MODEMGreenLEDDescription
onAlreadydialed
blinkNotdailed
POWERLEDandDescription
POWERRedLEDDescription
onNomalpowerconnection
offNopowerconnection
WLANLEDandDescription
WLANGreenLEDDescription
onWLANonfunction
offWLANofffunction
FCCSTATEMENT
1.ThisdevicecomplieswithPart15oftheFCCRules.Operationissubjecttothefollowingtwo
conditions:
(1)Thisdevicemaynotcauseharmfulinterference.
(2)Thisdevicemustacceptanyinterferencereceived,includinginterferencethatmaycause
undesiredoperation.
2.Changesormodificationsnotexpresslyapprovedbythepartyresponsibleforcompliance
couldvoidtheuser'sauthoritytooperatetheequipment.
NOTE:ThisequipmenthasbeentestedandfoundtocomplywiththelimitsforaClassBdigital
device,pursuanttoPart15oftheFCCRules.Theselimitsaredesignedtoprovidereasonable
protectionagainstharmfulinterferenceinaresidentialinstallation.
Thisequipmentgeneratesusesandcanradiateradiofrequencyenergyand,ifnotinstalledand
usedinaccordancewiththeinstructions,maycauseharmfulinterferencetoradio
communications.However,thereisnoguaranteethatinterferencewillnotoccurinaparticular
installation.Ifthisequipmentdoescauseharmfulinterferencetoradioortelevisionreception,
whichcanbedeterminedbyturningtheequipmentoffandon,theuserisencouragedtotryto
correcttheinterferencebyoneormoreofthefollowingmeasures:
Reorientorrelocatethereceivingantenna.
Increasetheseparationbetweentheequipmentandreceiver.
Connecttheequipmentintoanoutletonacircuitdifferentfromthattowhichthereceiveris
connected.
Consultthedealeroranexperiencedradio/TVtechnicianforhelp.
UnitedBusTechnology
778BlanchardWay,Sunnyvale
CA,940873118
USA
T:+1‐4086634958
info@ubt.io
http://www.ubt.io/
UnitedBusTechnology
UBT(UnitedBusTechnology),asiliconvalleybasedhigh
techcompany,isfocusingonhowtoimprovebusride
experience,togeneratemorerevenueformotocoach
operators,toprovidebettermanagementforoperatorsand
tomaximizethevalueofcoachlineindustrybythepowerof
Internet+technology.Ourmissionistoprovidethebest
internet+servicetoallmotocoachoperatorswith
cuttingedgeproductlinesthatcoversfromdailybus
businessoperationtopassengersridingexperience.

Navigation menu