background image

EKI-6333AC-4GP User Manual

6

2.1.2

Rear View

Figure 2.2 Rear View

2.1.3

Top View

Figure 2.3 Top View

No. Item

Description

1

DIN rail mounting 
plate

Mounting plate used for the installation to a standard DIN rail

1

No. Item

Description

1

Wall mounting holes

Screw holes (x4) used in the installation of a wall mounting plate

2

Ground terminal

Screw terminal used to ground chassis

3

Terminal block

Connect cabling for power and alarm wiring

DO

DO+

DI

DI+

PWR2

GND

GND

PWR1

1

3

2

Summary of Contents for EKI-6333AC-4GP

Page 1: ...User Manual EKI 6333AC 4GP Idustrial IEEE 802 11 a b g n ac Wi Fi AP with PoE ...

Page 2: ...nstallation Advantech assumes no liability under the terms of this warranty as a consequence of such events Because of Advantech s high quality control standards and rigorous testing most of our customers never need to use our repair service If an Advantech product is defective it will be repaired or replaced at no charge during the warranty period For out of warranty repairs you will be billed ac...

Page 3: ... can be determined by turning the equipment off and on the user is encouraged to try to correct the interference by one of the following measures Reorient or relocate the receiving antenna Increase the separation between the equipment and receiver Connect the equipment into an outlet on a circuit different from that to which the receiver is connected Consult the dealer or an experienced radio TV t...

Page 4: ...e problem The exact wording of any error messages Warnings Cautions and Notes Document Feedback To assist us in making improvements to this manual we would welcome comments and constructive criticism Please send all such in writing to support advantech com Warning Warnings indicate conditions which if not observed can cause personal injury Caution Cautions are included to help you avoid damaging h...

Page 5: ...openings on the enclosure are for air convection Protect the equipment from overheating DO NOT COVER THE OPENINGS Make sure the voltage of the power source is correct before connecting the equipment to the power outlet Position the power cord so that people cannot step on it Do not place anything over the power cord All cautions and warnings on the equipment should be noted If the equipment is not...

Page 6: ...aution Static Electricity Static electricity can cause bodily harm or damage electronic devices To avoid damage keep static sensitive devices in the static protective packaging until the installation period The following guidelines are also recommended Wear a grounded wrist or ankle strap and use gloves to prevent direct contact to the device before servicing the device Avoid nylon gloves or work ...

Page 7: ...3 2 2 7 Power Connection 14 2 3 Reset Button 18 Chapter 3 Web Interface 19 3 1 Log In 20 3 1 1 Password 21 3 2 Status 21 3 2 1 Dashboard 21 3 2 2 Basic Network 22 3 2 3 Administration 27 3 2 4 Statistics Reports 28 3 3 Basic Network 30 3 3 1 WAN Uplink 30 3 3 2 LAN VLAN 41 3 3 3 WiFi 54 3 3 4 IPv6 62 3 3 5 QoS 65 3 4 Object Definition 69 3 4 1 Scheduling 69 3 4 2 Grouping 71 3 4 3 External Server ...

Page 8: ...ork WAN Uplink WAN Interface IPv6 Network Status 23 Figure 3 9 Status Basic Network WAN Uplink LAN Interface Network Status 24 Figure 3 10 Status Basic Network WAN Uplink Interface Traffic Statistics 24 Figure 3 11 Status Basic Network LAN VLAN 25 Figure 3 12 Status Basic Network WiFi WiFi Module Virtual AP List 25 Figure 3 13 Status Basic Network WiFi WiFi Module IDS Status 26 Figure 3 14 Status ...

Page 9: ... DHCP Server DHCP Server Option Configuration 52 Figure 3 59 Basic Network LAN VLAN DHCP Server DHCP Server Option List 53 Figure 3 60 Basic Network LAN VLAN DHCP Server DHCP Relay Configuration List 53 Figure 3 61 Basic Network WiFi WiFi Module One Two 54 Figure 3 62 Basic Network WiFi WiFi Module One Two 2 4G WiFi Configuration 54 Figure 3 63 Basic Network WiFi WiFi Module One Two 2 4G VAP List ...

Page 10: ...d Certificate Certificate Signing Request CSR Import from a PEM 80 Figure 3 106 Field Communication Bus Protocol Port Configuration 81 Figure 3 107 Field Communication Bus Protocol Port Configuration 81 Figure 3 108 Field Communication Bus Protocol Virtual COM 82 Figure 3 109 Field Communication Bus Protocol Virtual COM 82 Figure 3 110 Field Communication Bus Protocol Virtual COM Data Packing for ...

Page 11: ... 3 153 Administration System Operation Password MMI Username 107 Figure 3 154 Administration System Operation Password MMI Username 107 Figure 3 155 Administration System Operation Password MMI Password 107 Figure 3 156 Administration System Operation Password MMI MMI 108 Figure 3 157 Administration System Operation System Information 109 Figure 3 158 Administration System Operation System Time 10...

Page 12: ...gure 3 185 Service Event Handling Configuration Remote Host List 126 Figure 3 186 Service Event Handling Configuration Remote Host Configuration 126 Figure 3 187 Service Event Handling Managing Events Configuration 126 Figure 3 188 Service Event Handling Managing Events Managing Event List 127 Figure 3 189 Service Event Handling Managing Events Managing Event Configuration 127 Figure 3 190 Service...

Page 13: ...Chapter 1 1Introduction ...

Page 14: ...A2 Enterprise Provides Web based configuration Support Dual band 2 4G 5G concurrently 4 x Gigabit Ethernet Port with PoE 802 3at PSE support 1 3 Specifications Specifications Description Interface I O Port 4 x RJ45 1 x RJ45 for WAN Power Connector Terminal block Physical Enclosure Metal shell with solid mounting kits Mounting DIN rail and wall Dimensions W x H x D 62 x 160 x 125 mm 2 44 x 6 3 x 4 ...

Page 15: ...all SPI firewall with stealth mode IPS Access Control Packet filter URL blocking MAC filter Event Handling Management Notifying Events Syslog Email Alart Diagnostic Packet Analyzer Diagnostic Tools Regulatory Approvals EMC CE FCC Part 15 Subpart B Class B Specifications Description 4 50 0 18 65 84 2 59 62 38 2 46 160 6 30 200 7 87 180 7 09 125 08 4 92 133 32 5 25 47 1 85 56 50 2 22 17 22 0 68 17 0...

Page 16: ...Chapter 2 2Getting Started ...

Page 17: ... reset 3 Serial port 4 ETH port RJ45 ports x 1 to configure WAN 5 System LED panel See LED Indicators on page 7 for further details 6 ETH port RJ45 ports x 4 7 Antenna connector Connector for 2 4G 5G antenna 8 Antenna connector Connector for 5G antenna EKI 6333AC 4GP Reset PWR WIFI CELL LAN 1 LAN 2 LAN 3 LAN 4 WAN Seirial 1 2 5G 2 4G WAN Signal 2 4G 5G WIFI 5G WIFI 1 3 2 4 5 6 7 8 ...

Page 18: ...nting plate Mounting plate used for the installation to a standard DIN rail 1 No Item Description 1 Wall mounting holes Screw holes x4 used in the installation of a wall mounting plate 2 Ground terminal Screw terminal used to ground chassis 3 Terminal block Connect cabling for power and alarm wiring DO DO DI DI PWR2 GND GND PWR1 1 3 2 ...

Page 19: ...age or the connected device Off No PoE power is supplied through the Ethernet Port LAN1 LAN4 Solid green Ethernet connection of LAN or WAN is established Blinking Data packets are transferring Off No Ethernet cable attached or the device is not linked Serial Solid blue Connect to a serial device Off Not connect to a serial device Status Solid blue Device is powered on Off Device is powered off 2 4...

Page 20: ...he DIN rail clip hooks over the top of the DIN rail as shown in the following illustration Make sure the DIN rail is inserted behind the spring mechanism 2 Once the DIN rail is seated correctly in the DIN rail clip press the front of the device to rotate the device down and into the release tab on the DIN rail clip If seated correctly the bottom of the DIN rail should be fully inserted in the rele...

Page 21: ...he device is correctly installed Otherwise re attempt the installation process from the beginning 2 2 1 2 Removing the DIN Rail Kit 1 Ensure that power is removed from the device and disconnect all cables and connectors from the front panel of the device 2 Push down on the top of the DIN rail clip release tab with your finger As the clip releases lift the bottom of the device as shown in the follo...

Page 22: ... screw holes on the device and the brackets align if seated correctly 5 Secure the wall brackets to the device with M3 screws see the following figure Figure 2 8 Installing Wall Mount Plates Once the wall mounting brackets are secured on the device mark the screw hole location on the wall area 6 On the installation site place the device firmly against the wall Make sure the device is vertically an...

Page 23: ...nt Repeat for the remaining locations see the following figure Figure 2 9 Wall Mount Installation 12 Once the device is installed on the wall tighten the screws to secure the device 2 2 3 Wireless Connection 1 Connect the antenna by screwing the antenna connectors in a clockwise direction Figure 2 10 Installing the Antenna 2 2 1 EKI 6333AC 4GP Res et PW R WIFI CEL L LA N 1 LA N 2 LA N 3 LA N 4 WAN...

Page 24: ...e shielded cabling Shielded cabling may be used to provide further protection Figure 2 12 Ethernet Plug Connector Pin Position Maximum cable length 100 meters 328 ft for 10 100BaseT Note The location and position of the antenna is crucial for effective wireless connectivity EKI 6333AC 4GP Res et PW R WIFI CEL L LA N 1 LA N 2 LA N 3 LA N 4 WAN Seirial 1 2 5G 2 4G WAN Sign al 2 4G 5G WIFI 5G WIFI L ...

Page 25: ...are one DI and one DO ports together with power terminal block Please refer to the following specification to connect DI and DO devices Figure 2 14 Example of Connection Diagram Pin1 Pin2 Pin3 Pin4 RS 232 GND RXD TXD GND RS 485 GND DATA DATA GND 4 1 Mode Specification Digital Input Trigger Voltage high Logic level 1 5V 30V Normal Voltage low Logic level 0 0V 2V Digital Output Voltage Relay Mode De...

Page 26: ...sult of power loss EKI 6333AC 4GP support 12 to 48 VDC Dual power inputs are supported and allow you to connect a backup power source Figure 2 15 Power Wiring for EKI 6333AC 4GP Warning Power down and disconnect the power cord before servicing or wiring the device Caution Do not disconnect modules or cabling unless the power is first switched off The device only supports the voltage outlined in th...

Page 27: ...ling to the various devices for more effective management and servicing 2 2 7 3 Grounding the Device Note Routing communications and power wiring through the same conduit may cause signal interference To avoid interference and signal degradation route power and communications wires through separate conduits Caution Do not disconnect modules or cabling unless the power is first switched off The dev...

Page 28: ...relay output The terminal block on the EKI 6333AC 4GP is wired and then installed onto the terminal receptor located on the EKI 6333AC 4GP Figure 2 17 Terminal Receptor Relay Contact The terminal receptor includes a total of six pins two for PWR1 two for PWR2 and two for a fault circuit Caution Do not block air ventilation holes Note Before applying power to the grounded device it is advisable to ...

Page 29: ...inal block receptor 2 Remove the terminal block from the device Figure 2 19 Removing a Terminal Block 3 Insert a small flat bladed screwdriver in the V1 V1 wire clamp screws and loosen the screws 4 Insert the negative positive DC wires into the V V terminals of PW1 If setting up power redundancy connect PW2 in the same manner Caution Do not disconnect modules or cabling unless the power is first s...

Page 30: ... screws on the terminal block to secure it to the terminal block receptor If there is no gap between the terminal block and the terminal receptor the terminal block is seated correctly Figure 2 21 Securing a Terminal Block to a Receptor 2 3 Reset Button Reset configuration to factory default Press and hold Reset button for 6 seconds System reboot Press and hold Reset button for 2 seconds Loosening...

Page 31: ...Chapter 3 3Web Interface ...

Page 32: ...o make sure your network environment supports the device setup before connecting it to the network 1 Launch your web browser on a computer 2 In the browser s address bar type in the device s default IP address 192 168 1 1 The login screen displays 3 Enter the default user name and password admin admin to log into the management interface You can change the default password after you have successfu...

Page 33: ... enter the new password under the Password field 5 Click Save to change the current account settings Figure 3 2 Administration System Operation Password MMI 3 2 Status 3 2 1 Dashboard To access this page click Status Dashboard The System Information screen shows the device Up time and the resource utilization for the CPU Memory and Connection Sessions Figure 3 3 Status Dashboard System Information...

Page 34: ...ink screen shows the current status for different network type including network configuration connecting information modem status and traffic statistics The display will be refreshed on every five seconds Figure 3 7 Status Basic Network WAN Uplink WAN Interface IPv4 Network Status The following table describes the items in the previous figure Item Description ID It displays corresponding WAN inte...

Page 35: ...tion Renew button allows user to force the device to request an IP address from the DHCP server Note Renew button is available when DHCP WAN Type is used and WAN connection is disconnected Release button allows user to force the device to clear its IP address setting to disconnect from DHCP server Note Release button is available when DHCP WAN Type is used and WAN connection is connected Connect b...

Page 36: ...lays the current IPv4 IP address of the gateway This is also the IP address user use to access Router s Web based Utility IPv4 Subnet Mask It displays the current mask of the subnet IPv6 Link local Address It displays the current LAN IPv6 Link Local address This is also the IPv6 IP address user use to access router s Web based utility IPv6 Global Address It displays the current IPv6 global IP addr...

Page 37: ...ansmitted Packets Mb It displays the statistics of upstream packets Mb It is reset when the device is rebooted Action Reset button when pressed allows user to reset the downstream upstream packets Item Description Item Description LAN Interface Client record of LAN interface String format IP Address Client record of IP address type and the IP address Type is string format and the IP address is IPv...

Page 38: ...ode for quick connect to the VAP by scanning the QR code Item Description Authentication Frame It displays the receiving authentication frame count Association Request Frame It displays the receiving association request frame count Re association Request Frame It displays the receiving re association request frame count Probe Request Frame It displays the receiving probe request frame count Disass...

Page 39: ...on Configure Manage SNMP Trap Information The following table describes the items in the previous figure Action Click Reset to clear individual VAP statistics Refresh Click Refresh to update the entire VAP traffic statistic instantly Item Description Item Description User Name It displays the user name for authentication This is only available for SNMP version 3 IP Address It displays the IP addre...

Page 40: ...ics Reports Connection Session The Internet Surfing List shows the connection tracks on this router Figure 3 19 Status Statistics Reports Connection Session The following table describes the items in the previous figure Item Description Link Status It displays the current connection status with the TR 068 server The connection status is either On when the device is connected with the TR 068 server...

Page 41: ...tistics The Login Statistics screen shows the login information Figure 3 21 Status Statistics Reports Login Statistics The following table describes the items in the previous figure Item Description Previous Click Previous to see the previous page of login statistics Next Click Next to see the next page of login statistics First Click First to see the first page of login statistics Last Click Last...

Page 42: ...ble describes the items in the previous figure Note Numbers of available WAN Interfaces can be different for the purchased gateway Item Description Physical Interface Select one expected interface from the available interface drop down menu It can be Ethernet or WiFi Module Depending on the gateway model Disable and failover options will be available only to multiple WAN gateways Operation Band If...

Page 43: ...ration mode of the interface Select Always on to make this WAN always active Select Disable to disable this WAN interface Select Failover to make this WAN a failover WAN when the primary or the secondary WAN link failed Then select the primary or the existed secondary WAN interface to switch failover from Note For WAN 1 only Always on option is available VLAN Tagging Check Enable checkbox to enter...

Page 44: ... Transmission Unit limit and specify the MTU for the 3G 4G connection MTU Maximum Transmission Unit specifies the largest packet size permitted for Internet transmission Value Range 1200 1500 NAT Enable NAT to apply NAT on the WAN connection Uncheck the box to disable NAT function IGMP Enable IGMP Internet Group Management Protocol would enable the router to listen to IGMP packets to discover whic...

Page 45: ...time Connect Manually allows user to connect to Internet manually Internet connection will be inactive after it has been inactive for specified idle time MTU Setup Check Enable checkbox to enable the MTU Maximum Transmission Unit limit and specify the MTU for the 3G 4G connection MTU Maximum Transmission Unit specifies the largest packet size permitted for Internet transmission Value Range 1200 15...

Page 46: ...y allows user to connect to Internet manually Internet connection will be inactive after it has been inactive for specified idle time Service Name Enter the service name if your ISP requires it Assigned IP Address Enter the IP address assigned by your service provider MTU Setup Check Enable checkbox to enable the MTU Maximum Transmission Unit limit and specify the MTU for the 3G 4G connection MTU ...

Page 47: ...Enter the PPTP server name or IP Address PPTP Account Enter the PPTP username provided by your service provider PPTP Password Enter the PPTP connection password provided by your service provider Connection ID Enter a name to identify the PPTP connection Connection Control There are three connection modes Auto reconnect enables the router to always keep the Internet connection on Connect on demand ...

Page 48: ...n enter the IP address provided by your service provider WAN IP Alias is used by the device router and is treated as a second set of WAN IP to provide dual WAN IP address to your LAN network Save Click Save to save the settings Undo Click Undo to cancel the settings Item Description IP Mode Select either Static or Dynamic IP address for L2TP Internet connection When Static IP Address is selected y...

Page 49: ...here are three options can be selected Auto Port will be automatically assigned 1701 For Cisco Set service port to port 1701 to connect to CISCO server User defined enter a service port provided by your service provider MPPE Check Enable checkbox enable MPPE Microsoft Point to Point Encryption security for PPTP connection NAT Enable NAT to apply NAT on the WAN connection Uncheck the box to disable...

Page 50: ...dwidth is fully occupied This is to prevent false link down status Query Interval Defines the transmitting interval between two DNS Query or ICMP checking packets Latency Threshold Defines the tolerance threshold of responding time Fail Threshold Specifies the detected disconnection before the router recognize the WAN link down status Enter a number of detecting disconnection times to be the thres...

Page 51: ... load balance strategies Select the preferred one By Smart Weight System will operate load balance function automatically based on the embedded Smart Weight algorithm By Specific Weight System will adjust the ratio of transferred sessions among all WANs based on the specified weights for each WAN By User Policy System will route traffics through available WAN interface based on user defined rules ...

Page 52: ...xxx xxx xxx e g 192 168 123 101 Destination IP Address There are five options can be selected Any No specific destination IP is provided The traffic may come to any destination Subnet Specify the Subnet for the traffics come to the subnet Input format is xxx xxx xxx xxx xx e g 192 168 123 0 24 IP Range Specify the IP Range for the traffics come to the IPs Single IP Specify a unique IP Address for ...

Page 53: ...ed the LAN IP mode can be Dynamic IP mode LAN IP Address Enter the local IP address of this device The network device s on your network must use the LAN IP address of this device as their Default Gateway You can change it if necessary Note It s also the IP address of web UI If you change it you need to type new IP address in the browser to see web UI Subnet Mask Select the subnet mask for this gat...

Page 54: ...an be lo or br0 IP Address Enter the addition IP address for this device Subnet Mask Select the subnet mask for this gateway from the drop down menu Subnet mask defines how many clients are allowed in one network or subnet The default subnet mask is 255 255 255 0 24 and it means maximum 254 IP addresses are allowed in this subnet However one of them is occupied by LAN IP address of this gateway so...

Page 55: ...AN VLAN Port based VLAN Configuration The following table describes the items in the previous figure System Reserved VLAN ID Specify the start ID 1 4091 and end ID for the reserved VLAN Apply Click Apply to save the settings Item Description Name Define the Name of this rule It has a default text and cannot be modified VLAN ID Define the VLAN ID number range is 1 4094 VLAN Tagging The rule is acti...

Page 56: ... the DHCP server settings Disable Select Disable to disable the DHCP server function for the VLAN group DHCP Server IP Address If you select Relay type of DHCP server assign a DHCP server IP address that the gateway will relay the DHCP requests to the assigned DHCP server DHCP Server Name Define name of the DHCP Server for the specified VLAN group IP Pool Define the IP Pool range There are Startin...

Page 57: ...ribes the items in the previous figure Item Description MAC Address Define the MAC address target that the DHCP server wants to match IP Address Define the IP address that the DHCP server will assign If there is a request from the MAC Address filled in the above field the DHCP server will assign this IP Address to the client whose MAC address matched the rule Enable Click Enable checkbox to activa...

Page 58: ...llow to access WAN interface If uncheck a certain VLAN ID box it means the VLAN ID member can t access Internet anymore Note VLAN ID 1 is available always it is the default VLAN ID of LAN rule The other VLAN IDs are available only when they are enabled Inter VLAN Group Routing Click the expected VLAN IDs box to enable the Inter VLAN access function By default members in different VLAN IDs can t ac...

Page 59: ...le The PoE design is compliant to IEEE802 3af at standard The PSE can auto detect the type of connected PD Powered Device and provide adequate power to it The maximum allowed continuous output power per cable is 15 4W for IEEE 802 3af PD device and 30W for IEEE802 3at PD device However to make the PoE cellular gateway provide required power through the Ethernet cables you have to prepare required ...

Page 60: ...s in the previous figure Figure 3 49 Basic Network LAN VLAN PoE Click the Edit button to edit the settings for each PoE port Figure 3 50 Basic Network LAN VLAN PoE The following table describes the items in the previous figure Item Description PoE Power Budget Specify the PoE power budget It can be 120Watts 60Watts or Manual If you select Manual you have to enter the power budget With specified po...

Page 61: ... or Power off on Select Power off on to restart the PD device if required PD Power Overload Specify the action to take when the PD Power overflow occurs for a certain port It can be No Action or Power Long Time Off On If the Power overload occurs PD consumes more power than the value specified in the Power Limit setting the PSE function for the PoE port will be disabled for 30 minutes That is PD d...

Page 62: ... you to understand LAN IP Address The LAN IP Address of this DHCP server Subnet Mask The Subnet Mask of this DHCP server IP Pool The IP Pool of this DHCP server It composed of Starting Address entered in this field and Ending Address entered in this field Lease Time The lease time of this DHCP server Value Range 300 604800 seconds Domain Name The domain name of this DHCP server Primary DNS The pri...

Page 63: ... the items in the previous figure The DHCP Server Options setting allows user to set DHCP OPTIONS 66 72 or 114 Figure 3 56 Basic Network LAN VLAN DHCP Server The following table describes the items in the previous figure Item Description MAC Address The MAC address of this mapping rule IP Address The IP address of this mapping rule Rule Click Enable checkbox to activate this rule Save Click Save t...

Page 64: ... option from the drop down menu It can be Option 66 Option 72 Option 144 Option 42 Option 150 or Option 160 Option 42 for ntp server Option 66 for tftp Option 72 for www Option 144 for url Type Each different options has different value types Option 66 Single IP Address and Single FQDN Option 72 IP Addresses List separated by Option 144 Single URL Option 42 IP Addresses List separated by Option 15...

Page 65: ... is easy for you to understand Value Range 1 64 characters LAN interface Select a LAN Interface for the drop down menu to apply with the DHCP Relay function WAN interface Select a WAN Interface for the drop down menu to apply with the DHCP Relay function It can be the available WAN interface s and L2TP connection Server IP Assign a DHCP server IP address that the gateway will relay the DHCP reques...

Page 66: ...e is integrated into the product However there is some module with selectable band for user to select according to his network environment Under such situation you can specify which operation band is suitable for the application Save Click Save to save the settings Undo Click Undo to cancel the settings Item Description WiFi Module Check Enable checkbox to activate WiFi function Channel Select a r...

Page 67: ...AP MAC addresses Green AP Check Enable checkbox to activate Green AP function VAP Isolation Check Enable checkbox to activate this function By default the box is checked it means that stations which associated to different VAPs cannot communicate with each other Time Schedule Apply a specific time schedule to this rule otherwise leave it as 0 Always If the drop down menu is empty ensure Time Sched...

Page 68: ...n or Shared by requesting of client automatically The check box named 802 1x shows up next to the drop down menu 802 1x The box is unchecked by default When 802 1x is enabled it means the client stations will be authenticated by RADIUS server RADIUS Server IP The default IP is 0 0 0 0 RADIUS Server Port The default value is 1812 RADIUS Shared Key When WPA or WPA2 is selected They are implementatio...

Page 69: ... characters AES The newest encryption system in WiFi it also designed for the fast 802 11n high bitrates schemes Enter a pre shared key for it The length of key is from 8 to 63 characters You are recommended to use AES encryption instead of any others for security TKIP AES TKIP AES mixed mode It means that the client stations can associate with this device via TKIP or AES Enter a pre shared key fo...

Page 70: ...is self filled by client Host Name It shows the host name of client MAC Address It shows the MAC address of client Mode It shows what kind of WiFi system the client used to associate with this device Rate It shows the data rate between client and this device RSSI0 It shows the RX sensitivity RSSI value for each radio path RSSI1 It shows the RX sensitivity RSSI value for each radio path Signal The ...

Page 71: ...improve performance in the presence of RF interference at the limits of RF coverage WMM WiFi Multimedia WMM can help control latency and jitter when transmitting multimedia content over a wireless connection Short GI Short Guard Interval GI is defined to set the sending interval between each packet Note that lower Short GI could increase not only the transition rate but also error rate TX Rate It ...

Page 72: ... option is hidden Operation Band Specify the intended operation band for the WiFi module Basically this setting is fixed and cannot be changed once the module is integrated into the gateway product However there are some module with selectable band for user to select according to his network environment Under such situation you can specify which operation band is suitable for the application Prior...

Page 73: ... and client stations will associate with AP according to SSID If the broadcast SSID option is enabled it means the SSID will be broadcasted and the stations can associate with this device by scanning SSID Channel Select a radio channel for the VAP Each channel is corresponding to different radio band The permissible channels depend on the Regulatory Domain There are two available options when Auto...

Page 74: ... The length of key is from 8 to 63 characters You are recommended to use AES encryption instead of any others for security MAC Address Specify the MAC address of the access point with the network ID to be connected to Priority Specify a priority setting for the uplink profile when the By User defined methodology is selected The priority value can be 1 16 1 is the highest priority and 16 is the low...

Page 75: ...nter the WAN subnet prefix Length for the router Default Gateway Enter the WAN default gateway IPv6 address Primary DNS Enter the WAN primary DNS server Secondary DNS Enter the WAN secondary DNS server MLD Snooping Enable disable the MLD snooping function Save Click Save to save the settings Undo Click Undo to cancel the settings Item Description DNS Select Specific DNS to active primary DNS and s...

Page 76: ...ore information please contact your ISP Service Name Enter the service name for setting up PPPoEv6 connection If you want more information please contact your ISP Value Range 0 45 characters Connection Control The value is Auto reconnect Always on MTU Enter the MTU for setting up PPPoEv6 connection If you want more information please contact your ISP Value Range 1280 1492 MLD Snooping Enable disab...

Page 77: ...tion of network bandwidth for all users to access It is indeed required that an access gateway satisfies the requirements of latency critical applications minimum access right guarantee fair bandwidth usage Item Description Auto configuration Check to enable the auto configuration feature Auto configuration Type Define the selected IPv6 WAN connection type to establish the IPv6 connectivity Select...

Page 78: ...c adjusting algorithm Figure 3 78 Basic Network QoS Configuration System Resource Configuration The following table describes the items in the previous figure Item Description QoS Types Select the QoS type from the drop down menu and then click Enable checkbox to activate the QoS function The default QoS type is set to Software QoS For some models there is another option for Hardware QoS Flexible ...

Page 79: ...the previous figure Item Description Bandwidth of Upstream Specify total upload bandwidth of the selected WAN Value Range For Gigabit Ethernet 1 1024000 Kbps or 1 1000 Mbps For Fast Ethernet 1 102400 Kbps or 1 100 Mbps For 3G 4G 1 153600 Kbps or 1 150 Mbps Bandwidth of Downstream Specify total download bandwidth of the selected WAN Value Range For Gigabit Ethernet 1 1024000 Kbps or 1 1000 Mbps For...

Page 80: ...m the drop down menu as well Select User defined Service for user defined packets only You have to define the port range and protocol as well Select Well known Service for specific application packets only You have to select the required service from the drop down menu as well Resource and Control Function Specify the Resource Type and corresponding Control function for the QoS rule The available ...

Page 81: ... to prioritize the traffics coming from the Internet via the specified interface Under such situation the hosts specified in the Group field is a destination group Both Select Both to prioritize the traffics passing through the specified interface both Inbound and Outbound are considered Under such situation the hosts specified in the Group field can be a source or destination group Time Schedule ...

Page 82: ...guration Time Period Definition The following table describes the items in the previous figure Item Description Rule Name Set rule name Rule Policy Inactivate activate the function been applied to in the time period below Save Click Save to save the settings Undo Click Undo to cancel the settings Item Description Week Day Select everyday or one of weekday Start Time hh mm Start time in selected we...

Page 83: ...ted rule s Refresh Click Refresh to refresh the host group list Item Description Group Name Enter a group name for the rule It is a name that is easy for you to understand Group Type Select the group type for the host group It can be IP Address based MAC Address based or Host Name based When IP Address based is selected only IP address can be added in Member to Join When MAC Address based is selec...

Page 84: ... firewall service Same as by enable QoS and communication bus Note The supported service type can be different for the purchased product Group Check Enable checkbox to activate the host group rule So that the group can be bound to selected service s for further configuration Save Click Save to save the settings Undo Click Undo to cancel the settings Item Description Item Description Add Click Add ...

Page 85: ...ol By default CHAP is selected Session Timeout By default 1 The values must be between 1 and 60 Idle Timeout By default 1 The values must be between 1 and 15 FTP SFTP Server When FTP SFTP Server is selected the following settings are also required User Name String format any text Password String format any text Protocol Select FTP or SFTP Encryption Select Plain Explicit FTPS or Implicit FTPS Tran...

Page 86: ...figuration screen appears The required information to be filled for the root CA includes the name key subject name and validity Figure 3 90 Object Definition Certificate Configuration Root CA Certificate Configuration The following table describes the items in the previous figure Item Description Name Enter a Root CA certificate name It will be a certificate file name Key This field is to specify ...

Page 87: ...items in the previous figure Save Click Save to save the settings Back Click Back to return the previous screen Item Description Item Description Name Enter a certificate name It will be a certificate file name If Self signed is checked it will be signed by root CA If Self signed is not checked it will generate a certificate signing request CSR Key This field is to specify the key attributes of ce...

Page 88: ... request certificate revocation in the future Unstructured Name for additional information Save Click Save to save the settings Back Click Back to return the previous screen Item Description Choose File Click Choose File to select a certificate file from user s computer Apply Click Apply to import the specified certificate file to the gateway Cancel Click Cancel to discard the import operation and...

Page 89: ...ibes the items in the previous figure Figure 3 97 Object Definition Certificate Trusted Certificate Trusted CA Certificate Import from a PEM The following table describes the items in the previous figure Item Description Choose File Click Choose File to select a CA certificate file from user s computer Apply Click Apply to import the specified CA certificate to the gateway Cancel Click Cancel to d...

Page 90: ...icate Trusted Certificate Trusted Client Certificate Import from a PEM The following table describes the items in the previous figure Item Description Choose File Click Choose File to select a certificate file from user s computer Apply Click Apply to import the specified certificate to the gateway Cancel Click Cancel to discard the import operation and the screen will return to the Trusted Certif...

Page 91: ...ed Client Key Import from a PEM The following table describes the items in the previous figure Item Description Choose File Click Choose File to select a certificate key file from user s computer Apply Click Apply to import the specified certificate key to the gateway Cancel Click Cancel to discard the import operation and the screen will return to the Trusted Certificates page Item Description Te...

Page 92: ...re Figure 3 105 Object Definition Certificate Issued Certificate Certificate Signing Request CSR Import from a PEM The following table describes the items in the previous figure Item Description Sign When root CA is exist click Sign sign and issue the imported certificate by root CA Choose File Click Choose File to select a certificate signing request file you re your computer for importing to the...

Page 93: ...n The following table describes the items in the previous figure Item Description Serial Port It displays the serial port ID of the serial port The number of serial ports varies from the purchased model Operation Mode It displays the current selected operation mode for the serial interface Depending on the purchase model the available modes can be Disable Virtual COM and Modbus Interface Select RS...

Page 94: ...tems in the previous figure Item Description Serial Port It displays the serial port ID of the serial port The number of serial ports varies from the purchased model Operation Mode Select TCP Client mode Connection Control Select Always on for a TCP full time connection Otherwise select On Demand to initiate TCP connection only when required to transmit and disconnect at idle timeout Connection Id...

Page 95: ...iter Character 1 Check Enable checkbox to activate the delimiter character 1 and enter the Hex code for it Value Range 0x00 0xFF Delimiter Character 2 Check Enable checkbox to activate the delimiter character 2 and enter the Hex code for it Value Range 0x00 0xFF Data Timeout Transmit Enter the data timeout interval for transmitting serial data through the port By default it is set to 0 and the tim...

Page 96: ...s varies from the purchased model Operation Mode Select TCP Server mode Listen Port Indicate the listening port of TCP connection Value Range 1 65535 Trust Type Select Allow All to allow any TCP clients to connect Otherwise select Specific IPs to limit certain TCP clients Max Connection Set the maximum number of concurrent TCP connections Up to 128 simultaneous TCP connections can be established V...

Page 97: ...erver The UDP mode provides connectionless communications which enable you to multicast data from the serial device to multiple host computers and vice versa making this mode ideal for message display applications Figure 3 118 Field Communication Bus Protocol Virtual COM When Edit button is applied a screen similar to this appears Figure 3 119 Field Communication Bus Protocol Virtual COM The follo...

Page 98: ... Enable Check Enable checkbox to activate the corresponding serial port in specified operation mode Save Click Save to save the settings Undo Click Undo to cancel the settings Item Description Remote Host Press Edit button to enter IP address range of remote UDP hosts Remote Port Indicate the UDP port of peer UDP hosts Value Range 1 65535 Serial Port Apply the UDP hosts for a selected serial port ...

Page 99: ...ased model Operation Mode Select RFC 2217 mode Listen Port Indicate the listening port of RFC 2217 connection Value Range 1 65535 Trust Type Select Allow All to allow any clients to connect Otherwise select Specific IPs to limit certain clients Connection Idle Timeout Enter the idle timeout in minutes The idle timeout is used to disconnect the TCP connection when idle time elapsed Idle timeout is ...

Page 100: ...as a Modbus gateway and allow access among Modbus TCP devices which are connected to Ethernet network and Modbus RTU ASCII devices which are connected to the Serial Port of the gateway Once completed the Modbus settings in this section ensure to select Modbus Operation Mode in Port Configuration screen to enable Modbus communication on the serial port Figure 3 126 Field Communication Bus Protocol ...

Page 101: ...de from a SCADA management system Supported Modbus commands are listed in the following table Value Range 1 247 Listen Port Specify the listen port number if Slave device s is attached to the selected serial port It is a don t care setting if a Master device is attached Value Range 1 65535 Note Use different port number among the serial ports for the product with multiple serial ports Serial Proto...

Page 102: ...ore the idle timeout elapsed the TCP session will be terminated automatically Value Range 1 65535 Maximum TCP Connections Enter the allowed maximum simultaneous TCP connections Value Range 1 4 TCP Keep alive Check Enable checkbox to ensure to keep the TCP session connected Modbus Master IP Access Specify authorized masters on the TCP network Select Allow All to allow any Modbus Master to reach the...

Page 103: ...coming from serially attached Master or based on Function Code Modbus Priority Definition The function is only available when Message Buffering is Enable Click Edit to fill in the priority settings Modbus Priority A Priority List for setting the priority of specified Modbus identity Modbus Priority 1 Modbus Priority 4 Priority Base User can specify a Modbus identity with IP Address Slave ID or Fun...

Page 104: ...ommunication Data Logging Configuration The following table describes the items in the previous figure ID Range Enter the Modbus ID range for the Modbus TCP Slave s that will respond to the Master s request In addition to specify the Slave IP and Port for accessing those Remote Modbus RTU Salve s located behind another Modbus gateway user has to specify the Modus ID range of the Modbus RTU Slave s...

Page 105: ...ial Port for local attached Modbus RTU ASCII Slaves Value Range 1 65535 for port number Slave ID Specify the ID range for the Slave device s to apply with the Modbus proxy rule Value Range 1 247 Function Code Specify a certain read function for the data logging proxy to issue and record the responses from device s Start Address Specify the start address of registers to apply with the specified fun...

Page 106: ...s Sniffer Full Time Proxy This is a mixed mode for both Sniffer and Full Time Proxy modes Master Type Specify the Modbus Master device to apply with the data logging rule It can be IP address for Modbus TCP Master or local serial port for local attached Modbus RTU ASCII Master Master Query Timeout sec Specify the timeout value for querying Modbus Master If no response from the master for the speci...

Page 107: ...he data logs into a series of files Value Range 1 99999 Auto Upload Check Enable checkbox to activate the auto upload function for logged files Once been enabled user has to specify an external FTP server from the drop down menu for auto uploading the log files to the server Refer to Object Definition External Server External Server or create the FTP server with the Add Object button Log File Comp...

Page 108: ...scription Command Script Check Enable checkbox to activate the command script function Backup Script Click Via Web UI or Via Storage to backup the existed command script in a txt file You can specify the script file name in Script Name below Upload Script Click Via Web UI or Via Storage to Upload the existed command script from a specified txt file Script Name Specify a script file name for script...

Page 109: ...t will be set as 1194 automatically OPENVPN_PORT A must filled setting Specify the port for the OpenVPN client to use OPENVPN_REMOTE_IPADDR IP or FQDN Specify the Remote IP FQDN of the peer OpenVPN server for this OpenVPN client tunnel Fill in the IP address or FQDN OPENVPN_PING_INTVL seconds Specify the time interval for OpenVPN keep alive checking OPENVPN_PING_TOUT seconds Specify the timeout va...

Page 110: ...ry packets to the destination specified in PPP_PING_IPADDR With ICMP Query the system will check connection by sending ICMP request packets to the destination specified in PPP_PING_IPADDR PPP_PING_IPADDR IP Specify an IP address as the target for sending DNS query ICMP request PPP_PING_INTVL seconds Specify the time interval for between two DNS query or ICMP checking packets STARTUP Script file Fo...

Page 111: ...ibes the items in the previous figure Item Description TR 069 Check Enable checkbox to activate TR 069 function Interface When you finish set basic network WAN 1 WAN n you can select WAN 1 WAN n When you finish set Security VPN IPSec OpenVPN PPTP L2TP GRE you can select IPSec OpenVPN PPTP L2TP GRE tunnel the interface just like IPSec 1 Data model Select the TR 069 dat model for the remote manageme...

Page 112: ...elect an expected certificate and key from the drop down menu Refer to Object Definition Certificate for the Certificate configuration Save Click Save to save the settings Undo Click Undo to cancel the settings Item Description STUN Check Enable checkbox to activate STUN function Server Address Specify the IP address for the expected STUN server Server Port Specify the port number for the expected...

Page 113: ...y version 2c When check the v3 box It means you can access SNMP by version 3 Remote Access IP Specify the remote access IP for WAN Select Specific IP Address and fill in a certain IP address It means only this IP address can access SNMP from LAN WAN side Select IP Range and fill in a range of IP addresses It means the IP address within specified range can access SNMP from LAN WAN side If you left ...

Page 114: ...cify the password for this version 3 user Value Range 8 64 characters Authentication When your Privacy Mode is authNoPriv or authPriv you must specify the authentication types for this version 3 user Selected the authentication types MD5 SHA 1 to use Encryption When your Privacy Mode is authPriv you must specify the encryption protocols for this version 3 user Selected the encryption protocols DES...

Page 115: ...Click Back to return the previous screen Item Description Server IP Specify the trap Server IP or FQDN The DUT will send trap to the server IP FQDN Server Port Specify the trap server port You can fill in any port number But you must ensure the port number is not to be used Value Range 1 65535 SNMP Version Select the version for the trap Selected the v1 The configuration screen will provide the ve...

Page 116: ...ion 3 trap Selected the authentication types MD5 SHA 1 to use Encryption The function is only available when SNMP Version is v3 When your Privacy Mode is authPriv you must specify the encryption protocols for this version 3 trap Selected the encryption protocols DES AES to use Privacy Key The function is only available when SNMP Version is v3 When your Privacy Mode is authPriv you must specify the...

Page 117: ...with A Z a z 0 9 _ Enterprise Number Specify the enterprise number for the particular private MIB Value Range 1 2080768 Enterprise OID Specify the Enterprise OID for the particular private MIB The range of the each OID number is 1 2080768 The maximum length of the enterprise OID is 31 The seventh number must be identical with the enterprise number Save Click Save to save the settings Undo Click Un...

Page 118: ... in the previous figure Item Description root Type old password and specify new password to change root password Note You are highly recommended to change the default telnet password with yours before the device is deployed Note If you have trouble for the default password for previous FW version please check the corresponding User Manual to get the correct one Save Click Save to save the settings...

Page 119: ...y Figure 3 155 Administration System Operation Password MMI Password The following table describes the items in the previous figure Item Description Username Display the current MMI login account username New Username Enter new username to replace the current setting Password Enter current password to verify if you have the permission to change the username setting Save Click Save to save the sett...

Page 120: ...ill be used for GUI access It can be http https http only or https only HTTPs Certificate Setup If the https access protocol is selected the HTTPs Certificate Setup option will be available for further configuration You can leave it as default or select a expected certificate and key from the drop down menu Refer to Object Definition Certificate for the Certificate configuration HTTP Compression C...

Page 121: ...ce Serial Number It displays the serial number of this product Kernel Version It displays the Linux kernel version of the product FW Version It displays the firmware version of the product System Time It displays the current system time that you browsed this web page Device Up Time It displays the statistics for the device up time since last boot up Refresh Click Refresh to update the system Infor...

Page 122: ...es Daylight Saving Time Check Enable checkbox to activate the daylight saving function When you enabled this function you have to specify the start date and end date for the daylight saving time duration Set Date Time Manually Manually set the date Year Month Day and time Hour Minute Second as the system time NTP Service Check Enable checkbox to activate the NTP Service function When you enabled t...

Page 123: ... events and to display in the Web Log List window Attacks Check to log attack events and to display in the Web Log List window Drop Check to log packet drop events and to display in the Web Log List window Login message Check to log system login events and to display in the Web Log List window Debug Check to log debug events and to display in the Web Log List window Email Alert Enable Check Enable...

Page 124: ...ct the type of event to log and be sent to the destined syslog server Available events are System Attacks Drop Login message and Debug Log to Storage Enable Check Enable checkbox to enable sending log to storage Select Device Select internal or external storage Log file name Enter log file name to save logs in designated storage Split file Enable Check Enable checkbox to split file whenever log fi...

Page 125: ... policy please check Accept unofficial firmware Backup Configuration Settings You can backup or restore the device configuration settings by clicking the Via Web UI button Download for backup the device configuration to a config bin file Upload for restore a designated configuration file to the device Via Web UI to retrieve the configuration file via Web GUI Auto Restore Configuration Check Enable...

Page 126: ...ocation of the upgrade files HTTP S FTP S Updates are downloaded from the Base URL address below Used protocol is specified by the address HTTP HTTPS FTP or FTPS Base URL IP address from which the configuration file will be downloaded This option also specifies the communication protocol example http example com Unit ID Name of configuration file name of the file without extension If not filled th...

Page 127: ...le Now Reboot immediately Time Schedule Select a pre defined auto reboot time schedule rule to reboot the auto device on a designated time To define a time schedule rule go to Object Definition Scheduling Configuration Reset to Default Click Reset to reset the device configuration to its default value Save Click Save to save the settings Item Description FTP Check Enable checkbox to activate the e...

Page 128: ...alue Range 1024 65535 Auto Report External IP in PASV Mode Check Enable checkbox to activate the support of overriding the IP address advertising in response to the PASV command ASCII Transfer Mode Check Enable checkbox to activate the support of ASCII mode data transfers Binary mode is supported by default FTPS FTP over SSL TLS Check Enable checkbox to activate the support of secure connections v...

Page 129: ...ccount The following table describes the items in the previous figure Item Description User Name Enter the user account for login to the FTP server Value Range 1 15 characters Password Enter the user password for login to the FTP server Directory Select a root directory after user login Permission Select the read write permission Note The embedded FTP server is only for log downloading so no any w...

Page 130: ...les option is also enabled the file name will be appended with an index code _ index The extension file name is pcap Split Files Check Enable checkbox to split file whenever log file reaching the specified limit If the Split Files option is enabled you can further specify the File Size and Unit for the split files Value Range 10 99999 Note File Size cannot be less than 10 KB Packet Interfaces Defi...

Page 131: ...ured when match any one IP in the rule Source Ports Define the filter rule with source ports which means the source port of packets The packets will be captured when match any port in the rule Up to 10 ports are supported but they must be separated with e g 80 53 Value Range 1 65535 Destination MACs Define the filter rule with destination MACs which means the destination MAC address of packets Pac...

Page 132: ...ton A test result window will appear beneath it Tracert Test Trace route tracert command is a network diagnostic tool for displaying the route path and measuring transit delays of packets across an IP network Trace route proceeds until all three sent packets are lost for more than twice then the connection is lost and the route cannot be evaluated First you need to specify an IP FQDN the test inte...

Page 133: ...unts Figure 3 175 Service Event Handling Configuration Email Service List When Add button is applied the Email Service Configuration screen appears Figure 3 176 Service Event Handling Configuration Email Service Configuration The following table describes the items in the previous figure Item Description Event Management Check Enable checkbox to activate the event management function Save Click Sa...

Page 134: ...for the profile DI Source Specify the DI source It could be ID1 or ID2 The number of available DI source could be different for the purchased product Continues Update Status Click Enable checkbox to enable the function Specify the interval for the DI event If the event condition is active for an extended period of time the gateway sends repeated notification events for each interval Value Range 0 ...

Page 135: ...re Item Description DO Profile Name Specify the DO profile name Value Range 1 32 characters Description Specify a brief description for the profile DO Source Specify the DO Source It could be ID1 Normal Level Specify the normal level It could be Low or High Total Signal Period Specify the total signal period Value Range 10 10000 ms Repeat Counter Check Enable checkbox to activate the repeated Digi...

Page 136: ...ile name Value Range 1 32 characters Description Specify a brief description for the profile Read Function Specify the read function for Notifying Events Modbus Mode Specify the Modbus mode It could be Serial or TCP IP Specify the IP for TCP on Modbus mode IPv4 format Port Specify the port for TCP on Modbus mode Value Range 1 65535 Device ID Specify the device ID of the Modbus device Value Range 1...

Page 137: ...ion Modbus Name Specify the Modbus profile name Value Range 1 32 characters Description Specify a brief description for the profile Write Function Specify the write function for Managing Events Modbus Mode Specify the Modbus mode It could be Serial or TCP IP Specify the IP for TCP on Modbus mode IPv4 format Port Specify the port for TCP on Modbus mode Value Range 1 65535 Device ID Specify the devi...

Page 138: ...rigger handlers and response Figure 3 187 Service Event Handling Managing Events Configuration The following table describes the items in the previous figure Item Description Host Name Specify the name of the host Host IP Specify the host IP address Protocol Type Select type of protocol TCP or UDP Port Number Specify TCP UDP port number Prefix Message Enter message prefix Suffix Message Enter mess...

Page 139: ...Specify the trigger type Period or Once Period Event will be executed in a period set by Interval below Once Event will be executed just once Interval The function is only available when Trigger Type is Period Time interval for event execution in period Value Range 0 86400 seconds Description Enter a brief description for the Managing Event Action Specify network status or at least one rest action...

Page 140: ...ice On Off TR 069 On Off the gateway will change the settings as the action for the event Administration Select Administration checkbox and the interested sub items Backup Config Restore Config Reboot Save Current Setting as Default the gateway will change the settings as the action for the event Digital Output Select Digital Output checkbox and a DO profile you defined as the action for the event...

Page 141: ...in WAN Event LAN VLAN Select LAN VLAN and a trigger condition to specify a certain LAN VLAN Event WiFi Select WiFi and a trigger condition to specify a certain WiFi Event DDNS Select DDNS and a trigger condition to specify a certain DDNS Event Administration Select Administration and a trigger condition to specify a certain Administration Event Modbus Select Modbus and a Modbus Notifying Event pro...

Page 142: ...l Alert Select Email Alert and the gateway will send out an Email to the defined Email accounts as the action for the event Modbus Select Modbus and a Modbus Notifying Event profile you defined as the action for the event Remote Host Select Remote Host and a Remote Host profile you defined as the action for the event Note The available event type could be different for the purchased product Time S...

Page 143: ...ations are subject to change without notice No part of this publication may be reproduced in any form or by any means electronic photocopying recording or otherwise without prior written permission of the publisher All brand and product names are trademarks or registered trademarks of their respective companies Advantech Co Ltd 2019 ...

Reviews: