background image

4. CONFIGURATION

The configuration file name consists of

Base URL

, hardware MAC address of ETH0 inter-

face and cfg extension. Hardware MAC address and cfg extension are added to the file name
automatically and it isn’t necessary to enter them. When the parameter

Unit ID

is enabled,

it defines the concrete configuration name which will be downloaded to the router, and the
hardware MAC address in the configuration name will not be used.

The firmware file name consists of

Base URL

, type of router and bin extension. For the

proper firmware filename, see the

Update Firmware

page in

Administration

section – it us

written out there. See Chapter

6.10

.

It is necessary to load two files (.bin and .ver) to the HTTP/FTP server. If only the .bin
file is uploaded and the HTTP server sends the incorrect answer of

200 OK

(instead of

the expected

404 Not Found

) when the device tries to download the nonexistent .ver file,

then there is a risk that the router will download the .bin file over and over again.

Firmware update can cause incompatibility with the user modules. It is recommended that
you update user modules to the most recent version. Information about the user modules
and the firmware compatibility is at the beginning of the user module’s Application Note.

4.24.1

Example of Automatic Update

In the following example the router checks for new firmware or configuration file each day

at 1:00 a.m. An example is given for the SmartFlex router.

Firmware file:

http://example.com/BIVIAS-v3LL.bin

Configuration file:

http://example.com/test.cfg

Figure 70: Example of Automatic Update 1

107

Summary of Contents for SmartMotion

Page 1: ...Twin Cellular Module Router SmartMotion CONFIGURATION MANUAL ...

Page 2: ... information of special interest Example example of function command or script Firmware version Current version of firmware is 6 0 0 May 31 2016 GPL licence Source codes under GPL licence are available free of charge by sending an email to cellularsales advantech bb com Advantech B B SmartWorx s r o Sokolska 71 562 04 Usti nad Orlici Czech Republic Manual Rev 1 released in CZ May 18 2016 i ...

Page 3: ...1 3 System Information 8 3 2 Mobile WAN Status 9 3 3 WiFi 12 3 4 WiFi Scan 13 3 5 Network Status 15 3 6 DHCP Status 18 3 7 IPsec Status 19 3 8 DynDNS Status 19 3 9 System Log 20 4 Configuration 22 4 1 LAN Configuration 22 4 1 1 DHCP Server 24 4 1 2 IPv6 Prefix Delegation 25 4 1 3 LAN Configuration Examples 26 4 2 VRRP Configuration 30 4 2 1 Example of VRRPv2 Configuration in IPv4 Network 31 4 3 Mo...

Page 4: ...Tunnel Configuration in IPv4 Network 77 4 14 GRE Tunnels Configuration 78 4 14 1 Example of the GRE Tunnel Configuration 80 4 15 L2TP Tunnel Configuration 81 4 15 1 Example of the L2TP Tunnel Configuration 82 4 16 PPTP Tunnel Configuration 83 4 16 1 Example of the PPTP Tunnel Configuration 84 4 17 DynDNS Configuration 85 4 18 NTP Configuration 86 4 19 SNMP Configuration 87 4 20 SMTP Configuration ...

Page 5: ...k SIM Card 114 6 7 Send SMS 115 6 8 Backup Configuration 115 6 9 Restore Configuration 115 6 10 Update Firmware 116 6 11 Reboot 117 7 Typical Situations 118 7 1 Access to the Internet from LAN 118 7 2 Backup Access to the Internet from LAN 120 7 3 Secure Networks Interconnection or Using VPN 124 8 Glossary and Acronyms 126 9 Index 131 10 Recommended Literature 134 iv ...

Page 6: ...Example of VRRP Configuration Main router 32 22 Example of VRRP Configuration Backup router 32 23 Switching and configuration pages structure 33 24 1st Mobile WAN Configuration 34 25 Example of Check Connection Configuration 38 26 Configuration for SIM card switching Example 1 41 27 Configuration for SIM card switching Example 2 42 28 Configuration for SIM card switching Example 3 42 29 Module Swi...

Page 7: ...ucture 88 58 SNMP Configuration Example 89 59 MIB Browser Example 90 60 SMTP Client Configuration Example 91 61 SMS Configuration 93 62 SMS Configuration for Example 1 97 63 SMS Configuration for Example 2 98 64 SMS Configuration for Example 3 98 65 USB configuration 101 66 Example 1 USB port configuration 101 67 Example 2 USB port configuration 102 68 Example of a Startup Script 103 69 Example of...

Page 8: ...ccess to the Internet LAN configuration 120 89 Backup access to the Internet WiFi configuration 121 90 Backup access to the Internet WLAN configuration 122 91 Backup access to the Internet Mobile WAN configuration 122 92 Backup access to the Internet Backup Routes configuration 123 93 Secure networks interconnection sample topology 124 94 Secure networks interconnection OpenVPN configuration 125 v...

Page 9: ... DHCP Server 25 17 Configuration of Static DHCP Server 25 18 IPv6 prefix delegation configuration 26 19 VRRP Configuration 30 20 Check connection 31 21 Mobile WAN Connection Configuration 36 22 Check Connection to Mobile Network Configuration 37 23 Data Limit Configuration 38 24 Switch between SIM cards configuration 40 25 Parameters for SIM card switching 41 26 Module Switching Configuration 45 2...

Page 10: ... DynDNS Configuration 85 52 NTP Configuration 86 53 SNMP Agent Configuration 87 54 SNMPv3 Configuration 87 55 SNMP Configuration R SeeNet 88 56 Object identifier for binary inputs and output 89 57 SMTP client configuration 91 58 SMS Configuration 94 59 Control via SMS and AT SMS over TCP 94 60 Control SMS 95 61 List of AT Commands 96 62 USB Port Configuration 1 99 63 USB Port Configuration 2 100 6...

Page 11: ...thernet 10 100 ports one USB 2 0 Host port two binary inputs one binary output I O connector four SIM card readers for 3 V and 1 8 V SIM cards two for every cellular module The router also has microSD memory card reader that increases the router s storage space by up to 64 GB when using SDXC card or up to 32 GB when using SDHC cards The router is provided in metal casing 1 2 Optional Features If d...

Page 12: ...ribed in this Configuration Manual Commands and scripts applicable in con figuration via SSH are described in Commands and Scripts for v2 and v3 Routers Application Note 1 Technical parameters and description of the router can be found in User s Manual of your router You can use additional software communication VPN server SmartCluster 2 and software for router monitoring R SeeNet 3 4 1 6 IPv6 Sup...

Page 13: ...ccording to the web interface chapters 3 to 6 Configuration in typical situations examples chapter 7 Access to the Internet from LAN Local Area Network via mobile network Ch 7 1 Backed up access to the Internet from LAN Ch 7 2 Secure networks interconnection or using VPN Virtal Private Network Ch 7 3 3 ...

Page 14: ...to the router Remove the power source before inserting the SIM card You may use the web interface to monitor configure and manage the router To do so enter the router s IP address in your browser The default address is 192 168 1 1 Only ac cess via secured HTTPS protocol is permitted So the syntax for the IP address must be Figure 1 Example of the Web Configuration 4 ...

Page 15: ...the green LED will be on during the reboot 2 1 Certificates and Preventing the Security Message There is the self signed HTTPS certificate in the router If you want to use your own certificate e g in combination with the dynamic DNS service you need to replace the etc certs https_cert and etc certs https_key files in the router If you decide to use the self signed certificate in the router to prev...

Page 16: ...nk local IPv6 address derived from MAC address of the interface It is generated and assigned the first time the interface is used e g cable is connected Mobile WAN connecting etc 3 1 1 Mobile Connection of 1st and 2nd Module Item Description SIM Card Identification of the SIM card 1st 2nd 3rd or 4th Interface Defines the network interface Flags Displays network interface flags IP Address IPv4 addr...

Page 17: ...d there is also information about it in the Primary LAN or Secondary LAN section see table below for description Item Description PoE PSE Status Disabled PoE PSE is disabled in the Primary LAN or Sec ondary LAN configuration form Undervoltage Undervoltage i e a lower voltage than the nominal operating voltage Overcurrent Overcurrent i e a higher current than the permissible positive difference of ...

Page 18: ...ile standard or alternative profiles profiles are used for example to switch between different modes of operation Power Board If the power board is installed in the router shows the type of power board PoE PD or PoE PSE Supply Voltage Supply voltage of the router Temperature Temperature in the router Time Current date and time Uptime Indicates how long the router is used Table 3 System Information...

Page 19: ...Signal Strength Signal strength of the selected cell Signal Quality Signal quality of the selected cell EC IO for UMTS it s the ratio of the signal received from the pilot channel EC to the overall level of the spectral density ie the sum of the signals of other cells IO RSRQ for LTE technology Defined as the ratio N RSRP RSSI The value is not available for the EDGE technology CSQ Cell Signal Qual...

Page 20: ...accounting period Table 5 Description of Periods Item Description Signal Min Minimal signal strength Signal Avg Average signal strength Signal Max Maximal signal strength Cells Number of switch between cells Availability Availability of the router via the mobile network expressed as a percent age Table 6 Mobile Network Statistics Tips for Mobile Network Statistics table Availability is expressed a...

Page 21: ...3 STATUS Figure 2 Mobile WAN status The last part Mobile Network Connection Log displays information about the mobile net work connections and any problems that occurred while establishing them 11 ...

Page 22: ...ing 802 11b in 802 11g BSS connection num_sta_no_short_slot_time Number of stations not supporting the Short Slot Time num_sta_no_short_preamble Number of stations not supporting the Short Preamble Table 8 Access Point State Information Detailed information is displayed for each connected client Most of them have an internal character Here are two examples Item Description STA MAC address of conne...

Page 23: ...Hz beacon interval Period of time synchronization capability List of access point AP properties signal Signal level of access point AP last seen Last response time of access point AP SSID Identifier of access point AP Supported rates Supported rates of access point AP DS Parameter set The channel on which access point AP broadcasts ERP Extended Rate PHY information element providing backward compa...

Page 24: ...3 STATUS WiFi Scan output may look like this Figure 4 WiFi Scan 14 ...

Page 25: ...GRE tunnel interface lo Local loopback interface nat64 Network interface of internal translator gateway between IPv6 and IPv4 addresses Table 11 Description of Interfaces in Network Status The following information can be displayed at every network interface Item Description HWaddr Hardware unique MAC address of a network interface inet addr IPv4 address of interface inet6 addr IPv6 address of int...

Page 26: ...ormation in Network Status You may view the status of the mobile network connection on the network status screen If the connection to the mobile network is active it will appear in the system information as an usb0 interface The Route Table is displayed at the bottom of the Network Status page There is IPv4 Route Table and IPv6 Route Table below If the router is connected to the Internet a default...

Page 27: ...3 STATUS Figure 5 Network Status 17 ...

Page 28: ...nally display two records for one IP address This may be caused by resetting the client network interface Records in the DHCP Status window are divided into separate parts according to LAN and WLAN interface and IPv4 DHCP and IPv6 DHCPv6 there are parts Active DHCP Leases LAN Active DHCPv6 Leases LAN Active DHCP Leases WLAN and Active DHCPv6 Leases WLAN if the router has WiFi and WLAN network inte...

Page 29: ...stablished If the tunnel has been built correctly the screen will display IPsec SA established highlighted in red in the figure below If there is no such text in log the tunnel was not created Figure 7 IPsec Status 3 8 DynDNS Status The router supports DynamicDNS using a DNS server on www dyndns org If Dynamic DNS is configured the status can be displayed by selecting menu option DynDNS Refer to w...

Page 30: ...ion correctly 3 9 System Log If there are any connection problems you may view the system log by selecting the System Log menu item Detailed reports from individual applications running in the router will be dis played Use the Save Log button to save the system log to a connected computer It will be saved as a text file with the log extension The Save Report button is used for creating de tailed r...

Page 31: ...e has to be remote logging enabled typically running syslogd R If it s the Windows OS there has to be syslog server installed e g Syslog Watcher To start syslogd with these options the etc init d syslog script can be modified via SSH or lines can be added into Startup Script accessible in Configuration section according to figure 10 Figure 9 System Log The following example figure shows how to sen...

Page 32: ...thernet interface ETH0 and Secondary LAN for the router s second Ethernet interface ETH1 LAN Configuration page is divided into IPv4 and IPv6 columns see Figure 11 There is dual stack support of IPv4 and IPv6 protocols they can run alongside you can configure either one of them or both If you configure both IPv4 and IPv6 other network devices will choose the communication protocol Configuration it...

Page 33: ... address is not found in the Routing Table the router forwards the request to DNS server specified here Use proper IP address notation in IPv4 and IPv6 column Table 14 Configuration of the Network Interface IPv4 and IPv6 The Default Gateway and DNS Server items are only used if the DHCP Client item is set to disabled and if the Primary or Secondary LAN is selected by the Backup Routes system as th...

Page 34: ...n the Ethernet cable disabled The router does not provide power on the Ethernet cable default Table 15 Configuration of the Network Interface global items 4 1 1 DHCP Server The DHCP server assigns the IP address gateway IP address IP address of the router and IP address of the DNS server IP address of the router to the connected clients If these values are filled in by the user in the configuratio...

Page 35: ...server MAC Address MAC address of a DHCP client IPv4 Address Assigned IPv4 address Use proper notation IPv6 Address Assigned IPv6 address Use proper notation Table 17 Configuration of Static DHCP Server 4 1 2 IPv6 Prefix Delegation This is an advanced configuration option IPv6 prefix delegation works automatically with DHCPv6 use only if different configuration is desired and if you know the con s...

Page 36: ...t ID Width depends on your Site Prefix it is the remainder to 64 bits Table 18 IPv6 prefix delegation configuration 4 1 3 LAN Configuration Examples Example 1 IPv4 Dynamic DHCP Server Default Gateway and DNS Server The range of dynamic allocated IPv4 addresses is from 192 168 1 2 to 192 168 1 4 The address is allocated for 600 second 10 minutes Default gateway IP address is 192 168 1 20 DNS server...

Page 37: ...CP server The range of allocated addresses is from 192 168 1 2 to 192 168 1 4 The address is allocated for 600 seconds 10 minutes The client with the MAC address 01 23 45 67 89 ab has the IP address 192 168 1 10 The client with the MAC address 01 54 68 18 ba 7e has the IP address 192 168 1 11 27 ...

Page 38: ...4 CONFIGURATION Figure 15 Network Topology for Example 2 Figure 16 LAN Configuration for Example 2 28 ...

Page 39: ... of dynamic allocated IPv6 addresses is from 2001 db8 1 to 2001 db8 ffff The address is allocated for 600 second 10 minutes The router is still accessible via IPv4 192 168 1 1 Figure 17 Network Topology for Example 3 Figure 18 LAN Configuration for Example 3 29 ...

Page 40: ... address This address must be the same for both the primary and backup routers Devices on the LAN will use this address as their default gateway IP address Virtual Server IPv6 Address Required in VRRPv3 mode inactive in VRRPv2 mode Same as above but IPv6 You can fill in both IPv6 and IPv4 addresses since it is a dual stack Virtual Server ID Numeric This parameter distinguishes one virtual router o...

Page 41: ... IP address for the Ping commands In VRRPv3 mode you can use IPv4 or IPv6 address You can not use a domain name Ping Interval Interval in seconds between the outgoing Pings Ping Timeout Time in seconds to wait for a response to the Ping Ping Probes Maximum number of failed ping requests Table 20 Check connection You may use the DNS server of the mobile carrier as the destination IP address for the...

Page 42: ...4 CONFIGURATION Figure 21 Example of VRRP Configuration Main router Figure 22 Example of VRRP Configuration Backup router 32 ...

Page 43: ...n where to configure decision making for modules and SIM cards The result of decision making which cellular module and SIM card is used is given by logical product AND of all their settings The subpages of Mobile WAN are explained below in order of appearance Figure 23 Switching and configuration pages structure 4 4 1st and 2nd Mobile WAN Configuration To configure the 1st cellular module 1st and ...

Page 44: ...4 CONFIGURATION Figure 24 1st Mobile WAN Configuration 34 ...

Page 45: ...v4 and IPv6 independent dual stack is enabled IP Address In IPv4 and IPv4 IPv6 mode only Specifies the IPv4 address of the SIM card You manually enter the IP address only when mobile network carrier assigned the IP address Phone Number Specifies the telephone number the router dials for a GPRS or CSD connection The router uses a default telephone number 99 1 Operator Specifies the carrier code You...

Page 46: ... the IP address field is left blank when the router establishes a connection then the mobile network carrier automatically assigns an IP address If you assign an IP address then the router accesses the network quicker If the APN field is left blank then the router automatically selects the APN using the IMSI code of the SIM card If the PLMN operator number format is not in the APN list then the ro...

Page 47: ...he basis of routing table Thus the requests may be sent through any available interface If you require each ping request to be sent through the network interface which was created when establishing a connection to the mobile operator it is necessary to set the Check Connection item to enabled bind The disabled option deactivates checking the connection to the mobile network Enabling the Check Conn...

Page 48: ...ifies the maximum expected amount of data transmitted sent and received over GPRS in one billing period month Warning Threshold Specifies the percentage of the Data Limit in the range of 50 to 99 If the data limit is exceeded the router sends an SMS in the following form Router has exceeded value of Warning Threshold of data limit Accounting Start Specifies the day of the month in which the billin...

Page 49: ...bled yes It is possible to use the SIM card no Never use the SIM card the usage of the SIM is for bidden Roaming Configure usage of SIM cards based on roaming The roaming has to be activated on SIM card where enabled don t care It is possible to use the SIM card everywhere home only Only use the SIM card if there was no roaming detected Data Limit Configure usage of SIM cards based on Data Limit s...

Page 50: ...st possible SIM card is used Attempts are made in order 1st SIM card 2nd SIM card Initial State Specifies the action of the cellular module after the SIM card was selected connected establish connection to the mobile network af ter SIM card was selected default off line Go to the off line mode after SIM card was se lected Note If off line you can change the initial state by SMS message only see SM...

Page 51: ...further attempts to change back to the default SIM card The length time is the sum of the time specified in the Subsequent Timeout pa rameter and the time specified in this parameter the range is from 1 to 10000 minutes Table 25 Parameters for SIM card switching The cellular module will fall into off line state if no SIM card can be selected In off line mode the Default SIM card is selected and th...

Page 52: ... period starts on the 18th day of the month Figure 27 Configuration for SIM card switching Example 2 Example 3 Timeout Recovery in Roaming The first default SIM card changes to the off line mode when roaming is detected by the router The other SIM card is disabled The first attempt to change back to the connected state on the default SIM card is executed after 60 minutes the second attempt is exec...

Page 53: ...f the logical product AND of the config uration on this page Figure 29 Module Switching Configuration Item Description Enabled Enable or disable the cellular module If you set all the cellular modules to no disabled the connection to cellular network is not attempted yes It is possible to use the cellular module if the connec tion to the cellular network was successfully established no Usage of th...

Page 54: ... The 1st cellular module is default 2nd The 2nd cellular module is default don t care The first possible cellular module is used At tempts are made in order 1st cellular module 2nd cellular module Switch to the other module when signal strength drops below weak level and is above fair level on target module This parameter enables automatic switching of cellular modules when the signal strength of ...

Page 55: ...onfiguration 4 5 1 PPPoE Bridge Mode Configuration If you mark the Enable PPPoE bridge mode check box the router activates the PPPoE bridge protocol PPPoE point to point over ethernet is a network protocol for encapsulating Point to Point Protocol PPP frames inside Ethernet frames The bridge mode allows you to create a PPPoE connection from a device behind the router For example a PC connected to ...

Page 56: ...the router obtains the IP address of the device to which it is connected The communications from a device behind the PPPoE server is forwarded to the router Figure 30 PPPoE Configuration Item Description Username Username for secure access to PPPoE Password Password for secure access to PPPoE Authentication Authentication protocol in GSM network PAP or CHAP The router selects the authentication me...

Page 57: ...n correct data transmission MTU Specifies the Maximum Transmission Unit The MTU identifies the maximum packet size that the router can transfer in a given envi ronment The default value is 1492 bytes Other settings can cause incorrect data transmission Get DNS addresses from server It is enabled to obtain the DNS addresses from the server by default Table 27 PPPoE configuration Setting a bad packe...

Page 58: ...r of WiFi network Broadcast SSID Method of broadcasting the unique identifier of SSID network in bea con frame and type of response to a request for sending the beacon frame Enabled SSID is broadcasted in beacon frame Zero length Beacon frame does not include SSID Requests for sending beacon frame are ignored Clear All SSID characters in beacon frames are replaced by 0 Original length is kept Requ...

Page 59: ...IEE 802 11a IEE 802 11a n Channel The channel where the WiFi AP is transmitting BW 40 MHz The option for HW mode 802 11n which allows transmission on two standard 20 MHz channels simultaneously The option is also avail able in the STA mode and it has to be enabled in both the AP and the STA mode if using the high throughput mode WMM Basic QoS for WiFi networks is enabled by checking this item This...

Page 60: ...ormat HEX WEP key in hexadecimal format WEP Default Key This item specifies the default WEP key WEP Key 1 4 Items for different four WEP keys WEP key in ASCII format must be entered in quotes This key can be specified in the following lengths 5 ASCII characters 40b WEP key 13 ASCII characters 104b WEP key 16 ASCII characters 128b WEP key WEP key must be entered in hexadecimal digits This key can b...

Page 61: ...cess Deny list is not used Accept Clients in Accept Deny list can access the network Deny Clients in Access Deny list cannot access the network Accept Deny List Accept or Denny list of client MAC addresses that set network ac cess Each MAC address is separated by new line Syslog Level Logging level when system writes to the system log Verbose debugging The highest level of logging Debugging Inform...

Page 62: ...4 CONFIGURATION Figure 31 WiFi Configuration 52 ...

Page 63: ... IPv4 and IPv6 columns It is the independent dual stack configuration of IPv4 and IPv6 protocols you can configure either one of them or both Configuration items and IPv6 to IPv4 differences are described in the tables below Figure 32 WLAN Configuration Item Description Operating Mode WiFi operating mode access point AP The router becomes an access point to which other devices in station STA mode ...

Page 64: ... default value WLAN network is not connected with LAN network of the router yes Bridged mode is allowed WLAN network is connected with one or more LAN networks of the router In this case the setting of most items in this table are ignored Instead the router uses the settings of the selected network interface LAN Table 29 WLAN Configuration Use Enable dynamic DHCP leases item at the bottom of this ...

Page 65: ...y con nection with alternative connections to the Internet mobile network or enable Multiple WANs mode It is also possible to prioritize each backup connection option Switching between connections is carried out according to order of priority and the state of the connections Figure 33 Backup Routes Configuration 55 ...

Page 66: ...the backup routes system mark the checkbox s of the following interface options Enable backup routes switching for Mobile WAN Enable backup routes switching for PPPoE Enable backup routes switching for WiFi STA Enable backup routes switching for Primary LAN or Enable backup routes switching for Secondary LAN En abled interfaces are then used for WAN access either in Single WAN mode only one interf...

Page 67: ...ackward compatibility mode The router selects the route based on the de fault priorities of the enabled settings for each of the network interfaces enabling appropriate services that comply with these network interfaces The following list contains the names of backup routes and corresponding network interfaces in order of default priorities Mobile WAN usbX PPPoE ppp0 WiFi STA wlan0 Secondary LAN e...

Page 68: ... have the same meaning in the IPv4 Firewall Configuration and IPv6 Firewall Configuration forms Figure 34 Firewall Configuration IPv6 Firewall You can specify the rules for IP addresses protocols and ports to allow or deny the access to the router and internal network connected behind the router To enable this function tick the Enable filtering of incoming packets check box located at the top of t...

Page 69: ...ltering of forwarded packets check box then packets are automatically accepted If you activate this function and a packet is addressed to another network interface then the router sends the packet to the FORWARD chain When the FORWARD chain accepts the packet and there is a rule for forwarding it the router sends the packet If a forwarding rule is unavailable then the router drops the packet This ...

Page 70: ...work Table 34 Forwarding filtering When you enable the Enable filtering of locally destined packets function the router drops the packets requesting an unsupported service The packet is dropped automatically without any information As a protection against DoS attacks the Enable protection against DoS attacks limits the number of allowed connections per second to five The DoS attack floods the targ...

Page 71: ...4 CONFIGURATION Figure 35 Topology for the IPv4 Firewall Configuration Example Figure 36 IPv4 Firewall Configuration Example 61 ...

Page 72: ... and IPv6 options and you can click IPv6 to enable and configure the IPv6 NAT see Figure below The configuration fields have the same meaning in the IPv4 NAT Configuration and IPv6 NAT Configuration forms Figure 37 NAT IPv6 NAT Configuration The router actually uses Port Address Translation PAT which is a method of mapping a TCP UDP port to another TCP UDP port The router modifies the information ...

Page 73: ...e options If you enable the following options and enter the port number the router allows you to remotely access to the router from WAN Mobile WAN interface Attention Enable remote HTTP access on port activates the redirect from HTTP to HTTPS protocol only The router doesn t allow unsecured HTTP protocol to access the web configuration To access the web configuration always check the Enable re mot...

Page 74: ...n is that you specify a default server in the De fault Server IPv4 IPv6 Address field The router can for ward incoming data from a GPRS to a computer with the assigned IP address Default Server IPv4 Address In IPv4 NAT Configuration only The IPv4 address Default Server IPv6 Address In IPv6 NAT Configuration only The IPv6 address Table 37 Configuration of Send all incoming packets to server 4 11 1 ...

Page 75: ... IP address Enter the address in the Server IPv Address field in the NAT dialog The devices are communicating on port 80 but you can set port forwarding using the Public Port and Private Port fields in the NAT dialog You have now configured the router to access the 192 168 1 2 80 socket behind the router when accessing the IP address 10 0 0 1 81 from the Internet If you send a ping request to the ...

Page 76: ...4 CONFIGURATION Figure 40 Topology for NAT Configuration Example 2 Figure 41 NAT Configuration for Example 2 66 ...

Page 77: ... OpenVPN Tunnels Overview Figure 42 OpenVPN Tunnels List Item Description Description Specifies the description or name of tunnel Protocol Specifies the communication protocol UDP The OpenVPN communicates using UDP TCP server The OpenVPN communicates using TCP in server mode TCP client The OpenVPN communicates using TCP in client mode UDPv6 The OpenVPN communicates using UDP over IPv6 TCPv6 server...

Page 78: ...erface IPv6 Address Specifies the IPv6 address of the interface of opposite side of the tunnel Ping Interval Time interval after which the router sends a message to opposite side of tunnel to verify the existence of the tunnel Ping Timeout Specifies the time interval the router waits for a message sent by the opposite side For proper verification of the OpenVPN tunnel set the Ping Timeout to great...

Page 79: ...ord and X 509 Certificate authentication modes DH Parameters Specifies the protocol for the DH parameters key exchange which you can use for X 509 Certificate authentication in the server mode Local Certificate Specifies the certificate used in the local device You can use this authentication certificate for the X 509 Certificate authentication mode Local Private Key Specifies the key used in the ...

Page 80: ...4 CONFIGURATION The changes in settings will apply after pressing the Apply button Figure 43 OpenVPN tunnel configuration 70 ...

Page 81: ...dress 10 0 0 2 10 0 0 1 Remote Subnet 192 168 2 0 192 168 1 0 Remote Subnet Mask 255 255 255 0 255 255 255 0 Local Interface IP Address 19 16 1 0 19 16 2 0 Remote Interface IP Address 19 16 2 0 19 18 1 0 Compression LZO LZO Authenticate mode none none Table 40 OpenVPN Configuration Example Examples of different options for configuration and authentication of OpenVPN tunnel can be found in the appl...

Page 82: ...remote subnets fields blank If you specify the protocol and port information in the Local Protocol Port field then the router encapsulates only the packets matching the settings Item Description Create Activates deactivates the individual IPsec tunnels Description Displays the name of the tunnel specified in the configuration of the tunnel Edit Opens the IPsec tunnel configuration form Table 41 IP...

Page 83: ...l Subnet IPv4 or IPv6 address of a local network based on Tunnel IP Mode above Local Subnet Mask Prefix IPv4 subnet mask of a local network or IPv6 prefix single num ber 0 to 128 Local Protocol Port Specifies Protocol Port of a local network The general form is protocol port for example 17 1701 for UDP protocol 17 and port 1701 It is also possible to enter only the number of protocol however the a...

Page 84: ...Encryption algorithm DES 3DES AES128 AES192 AES256 ESP Hash Hash algorithm MD5 SHA1 SHA256 SHA384 or SHA512 PFS Enables disables the Perfect Forward Secrecy function The function ensures that derived session keys are not compromised if one of the private keys is compromised in the future PFS DH Group Specifies the Diffie Hellman group number see IKE DH Group Key Lifetime Lifetime key data part of ...

Page 85: ... level of verbosity to System Log Silent default audit control control more raw private most verbose includ ing the private keys See strongSwan documentation for more details Table 42 IPsec Tunnel Configuration The IPsec function supports the following types of identifiers ID for both sides of the tunnel Remote ID and Local ID parameters IP address for example 192 168 1 1 DN for example C CZ O Com...

Page 86: ...4 CONFIGURATION Figure 46 IPsec Tunnels Configuration 76 ...

Page 87: ...uration in IPv4 Network Figure 47 Topology of IPsec Configuration Example IPsec tunnel configuration Configuration A B Host IP Mode IPv4 IPv4 Remote IP Address 10 0 0 2 10 0 0 1 Tunnel IP Mode IPv4 IPv4 Remote Subnet 192 168 2 0 192 168 1 0 Remote Subnet Mask 255 255 255 0 255 255 255 0 Local Subnet 192 168 1 0 192 168 2 0 Local Subnet Mas 255 255 255 0 255 255 255 0 Authenticate mode pre shared k...

Page 88: ... the GRE tunnel configuration form Table 44 GRE Tunnels Overview Figure 48 GRE Tunnels List Item Description Description Description of the GRE tunnel Remote IP Address IP address of the remote side of the tunnel Remote Subnet IP address of the network behind the remote side of the tunnel Remote Subnet Mask Specifies the mask of the network behind the remote side of the tunnel Local Interface IP A...

Page 89: ...ormat with this key the router sends the filtered data through the tunnel Specify the same key on both routers otherwise the router drops received packets Table 45 GRE Tunnel Configuration Attention the GRE tunnel does not pass through NAT The changes in settings will apply after pressing the Apply button Figure 49 GRE Tunnel Configuration 79 ...

Page 90: ...GRE tunnel configuration Configuration A B Remote IP Address 10 0 0 2 10 0 0 1 Remote Subnet 192 168 2 0 192 168 1 0 Remote Subnet Mask 255 255 255 0 255 255 255 0 Table 46 GRE Tunnel Configuration Example Examples of different options for configuration of GRE tunnel can be found in the application note GRE Tunnel 7 80 ...

Page 91: ...fy the IP address of the server Server IP Address IP address of the server Client Start IP Address IP address to start with in the address range The range is offered by the server to the clients Client End IP Address The last IP address in the address range The range is offered by the server to the clients Local IP Address IP address of the local side of the tunnel Remote IP Address IP address of ...

Page 92: ...on A B Mode L2TP Server L2TP Client Server IP Address 10 0 0 1 Client Start IP Address 192 168 2 5 Client End IP Address 192 168 2 254 Local IP Address 192 168 1 1 Remote IP Address Remote Subnet 192 168 2 0 192 168 1 0 Remote Subnet Mask 255 255 255 0 255 255 255 0 Username username username Password password password Table 48 L2TP Tunnel Configuration Example 82 ...

Page 93: ...ddress of the server Server IP Address IP address of the server Local IP Address IP address of the local side of the tunnel Remote IP Address IP address of the remote side of the tunnel Remote Subnet Address of the network behind the remote side of the tunnel Remote Subnet Mask The mask of the network behind the remote side of the tunnel Username Username for the PPTP tunnel login Password Passwor...

Page 94: ...of the PPTP tunnel Configuration A B Mode PPTP Server PPTP Client Server IP Address 10 0 0 1 Local IP Address 192 168 1 1 Remote IP Address 192 168 2 1 Remote Subnet 192 168 2 0 192 168 1 0 Remote Subnet Mask 255 255 255 0 255 255 255 0 Username username username Password password password Table 50 PPTP Tunnel Configuration Example 84 ...

Page 95: ...gistered on the www dyndns org server Username Username for logging into the DynDNS server Password Password for logging into the DynDNS server Server Specifies a DynDNS service other than the www dyndns org Possible other services www spdns de www dnsdynamic org www noip com Enter the update server service information in this field If you leave this field blank the default server members dyndns o...

Page 96: ...the router acts as a NTP client This means that the router automatically adjusts the internal clock every 24 hours Item Description Primary NTP Server Address IPv4 address IPv6 address or domain name of primary NTP server Secondary NTP Server Address IPv4 address IPv6 address or domain name of secondary NTP server Timezone Specifies the time zone where you installed the router Daylight Saving Time...

Page 97: ...v2 access check box It is also necessary to specify a password for access to the Community SNMP agent The default setting is public You can define a different password for the Read community read only and the Write community read and write for SNMPv1 v2 You can also define 2 SNMP users for SNMPv3 You can define a user as read only Read and another as read and write Write The router allows you to c...

Page 98: ... in minutes Table 55 SNMP Configuration R SeeNet Each monitored value is uniquely identified using a numerical identifier OID Object Iden tifier This identifier consists of a progression of numbers separated by a point The shape of each OID is determined by the identifier value of the parent element and then this value is complemented by a point and current number So it is obvious that there is a ...

Page 99: ...ollowing range of OID is used OID Description 1 3 6 1 4 1 30140 2 3 1 0 Binary input BIN0 values 0 1 1 3 6 1 4 1 30140 2 3 2 0 Binary output OUT0 values 0 1 1 3 6 1 4 1 30140 2 3 3 0 Binary input BIN1 values 0 1 Table 56 Object identifier for binary inputs and output The list of available and supported OIDs and other details can be found in the application note SNMP Object Identifier 8 Figure 58 S...

Page 100: ...SNMP agent field The dialog displayed the internal variables in the MIB tree after entering the IP address Furthermore you can find the status of the internal variables by entering their OID The path to the objects is iso org dod internet private enterprises conel protocols The path to information about the router is iso org dod internet mgmt mib 2 system 90 ...

Page 101: ... The following special characters are not allowed Own E mail Address Address of the sender Table 57 SMTP client configuration The mobile service provider can block other SMTP servers then you can only use the SMTP server of the service provider Figure 60 SMTP Client Configuration Example You can send e mails from the Startup script The Startup Script dialog is located in Scripts in the Configurati...

Page 102: ...ending an e mail email t john doe com s System Log m Attached a var log messages The command above sends an e mail to address john doe com with the subject System Log body message Attached and attachment messages file with System Log of the router directly from the directory var log 92 ...

Page 103: ...n power up Activates deactivates the sending of an SMS mes sage automatically on power up Send SMS on connect to mobile network Activates deactivates the sending of an SMS mes sage automatically when the router is connected to a mobile network Send SMS on disconnect to mo bile network Activates deactivates the sending of an SMS mes sage automatically when the router is disconnection from a mobile ...

Page 104: ...tion After you enter a phone number in the Phone Number 1 field the router allows you to configure the control of the device using an SMS message You can configure up to three numbers for incoming SMS messages To enable the function mark the Enable remote control via SMS check box The default setting of the remote control function is active Item Description Phone Number 1 Specifies the first phone...

Page 105: ... is the same for every SMS control message To control the router using an SMS send only message text containing the control com mand You can send control SMS messages in the following form SMS Description go online sim 1 The router changes to SIM1 go online sim 2 The router changes to SIM2 go online sim 3 The router changes to SIM3 go online sim 4 The router changes to SIM4 go online Changes the r...

Page 106: ... a certain status from a message storage area AT CMGR Reads a message from a message storage area AT CMGS Sends a short message from the device to entered tel number AT CMGW Writes a short message to the SIM storage AT CMSS Sends a short message from the SIM storage location AT COPS Identifies the mobile networks available AT CPIN Used to query and enter a PIN code AT CPMS Selects the SMS memory s...

Page 107: ...ter Unit ID has been powered up Signal strength xx dBm After connecting to mobile network the phone with the number entered in the dialog receives an SMS in the following form Router Unit ID has established connection to mobile network IP address xxx xxx xxx xxx After disconnecting from the mobile network the phone with the number entered in the dialog receives an SMS in the following form Router ...

Page 108: ...N Example 2 Control the Router Sending SMS from any Phone Number Figure 63 SMS Configuration for Example 2 Example 3 Control the Router Sending SMS from Two Phone Numbers Figure 64 SMS Configuration for Example 3 98 ...

Page 109: ... stop bit Split Timeout Time to rupture reports If the gap between two characters exceeds the parameter in milliseconds any buffered characters will be sent over the Ethernet port Protocol Communication protocol TCP communication using a linked protocol TCP UDP communication using a unlinked protocol UDP Mode Mode of connection TCP server The router will listen for incoming TCP connection requests...

Page 110: ...ies that another device is connected to the other side of the cable CD Description Active TCP connection is enabled Nonactive TCP connection is disabled Table 64 CD Signal description When you mark the Use DTR as control of TCP connection check box the router uses the data terminal ready DTR single to control the TCP connection The remote device sends a DTR single to the router indicating that the...

Page 111: ...4 CONFIGURATION Figure 65 USB configuration 4 22 1 Examples of USB Port Configuration Figure 66 Example 1 USB port configuration 101 ...

Page 112: ...4 CONFIGURATION Figure 67 Example 2 USB port configuration 102 ...

Page 113: ...nds see the Application Note Commands and Scripts 1 4 23 1 Startup Script Use the Startup Script window to create your own scripts which will be executed after all of the initialization scripts are run right after the router is turned on or rebooted The changes in settings will apply after pressing the Apply button Any changes to the Startup Script will take effect the next time the router is powe...

Page 114: ... stack implemented in the router so there is independent IPv4 and IPv6 Up Down script IPv4 Up Down Script runs only on the IPv4 WAN connection established lost IPv6 Up Down Script runs only on the IPv6 WAN connection established lost Any scripts entered into the Up Script window will run after a WAN connection is established Script commands entered into the Down Script window will run when the WAN...

Page 115: ...ork the router sends an email with information about the connection state It is necessary to configure SMTP before Add this line to the Up Script field email t name domain com s Router m Connection up Add this line to the Down Script field email t name domain com s Router m Connection down 105 ...

Page 116: ...ook for a new firmware file and update its firmware if necessary Item Description Source Select the location of the update files HTTP S FTP S server Updates are downloaded from the Base URL address below Used protocol is specified by that ad dress HTTP HTTPS FTP or FTPS USB flash drive The router finds the current firmware or con figuration in the root directory of the connected USB device Both Lo...

Page 117: ...d ver to the HTTP FTP server If only the bin file is uploaded and the HTTP server sends the incorrect answer of 200 OK instead of the expected 404 Not Found when the device tries to download the nonexistent ver file then there is a risk that the router will download the bin file over and over again Firmware update can cause incompatibility with the user modules It is recommended that you update us...

Page 118: ...outer checks for new firmware or configuration each day at 1 00 a m An example is given for the SmartFlex router with MAC address 00 11 22 33 44 55 Firmware file http example com BIVIAS v3LL bin Configuration file http example com 00 11 22 33 44 55 cfg Figure 71 Example of Automatic Update 2 108 ...

Page 119: ...the module contains an index html or index cgi page the module name serves as a link to this page The module can be deleted using the Delete button Updating a module is done the same way Click the Add button and the module with the higher newer version will replace the existing module The current module configuration is left in the same state Programming and compiling of modules is described in th...

Page 120: ...d saves contents of these messages to an XML file pduSMS Sends short messages SMS to specified number GPS Allows the router to provide location and time information in all weather anywhere on or near the Earth where there is an unobstructed line of sight to four or more GPS satellites Pinger Allows you to manually or automatically verify the functionality of the connection between two network inte...

Page 121: ...ser Delete Deletes the corresponding user account Table 68 Users Overview Be careful If you lock every account with the permission role Admin you can not unlock these accounts This also means that the Users dialog is unavailable for every user because every admin account is locked and the users do not have sufficient permissions The second block contains configuration form which allows you to add ...

Page 122: ...e the settings to and ensure that the Copy settings from current profile to selected profile box is checked The current settings will be stored in the alternate profile after the Apply button is pressed Any changes will take effect after restarting router through the Reboot menu in the web administrator or using an SMS message Example of using profiles Profiles can be used to switch between differ...

Page 123: ...e default password You can not enable remote access to the router for example in NAT until you change the password Figure 76 Change Password 6 4 Set Real Time Clock You can set the internal clock directly using the Set Real Time Clock dialog in the Ad ministration section of in the main menu You can set the Date and Time manually When entering the values manually use the format yyyy mm dd as seen ...

Page 124: ...with an international prefix 420 xxx xxx xxx If you are unable to send or receive SMS messages contact your carrier to find out if this parameter is required Figure 78 Set SMS Service Center Address 6 6 Unlock SIM Card This feature works on the 1st cellular module only 1st or 2nd SIM card It is not possible to unlock SIM card in 2nd cellular module this way If your SIM card is protected using a 4 ...

Page 125: ...pduSMS user module Figure 80 Send SMS It is also possible to send an SMS message using CGI script For details of this method see the application note Commands and Scripts 1 6 8 Backup Configuration You can save the configuration of the router using the Backup Configuration function If you click on Backup Configuration in the Administration section of the main menu then the router allows you to sel...

Page 126: ...he filename written out as Firmware Name when updating the firmware Figure 82 Update Firmware During the firmware update the router will show the following messages The progress is shown in the form of adding dots After the firmware update the router will automatically reboot Uploading firmware intended for a different device can cause damage to the router Starting with FW 5 1 0 a mechanism to pre...

Page 127: ...6 ADMINISTRATION 6 11 Reboot To reboot the router select the Reboot menu item and then press the Reboot button Figure 83 Reboot 117 ...

Page 128: ...uter or switch and computers to the router s eth0 interface LAN Wait a moment after turning on the router The router will connect to the mobile network and the Internet This will be indicated by the LEDs on the front panel of the router WAN and DAT Additional configuration can be done in the LAN and Mobile WAN items in the Configura tion section of the web interface LAN configuration The factory d...

Page 129: ... the Internet from LAN Mobile WAN configuration To check whether the connection is working properly go to the Mobile WAN item in the Status section You will see information about operator signal strength etc At the bottom you should see the message Connection successfully established In problems check also the Module Switching page there has to be Create connection to mobile network enabled too Th...

Page 130: ...o the Internet sample topology The configuration form on the Backup Routes page lets you back up the primary connection with alternative connections to the Internet mobile network Each backup connection can be assigned a priority Figure 88 Backup access to the Internet LAN configuration 120 ...

Page 131: ... you will need to enable the wlan0 network interface in the WLAN item as shown in Fig 90 Check the Enable WLAN interface set the Operating Mode to station STA enable the DHCP client and fill in the default gateway and DNS server Click the Apply button to confirm the changes For details see Chapter 4 8 Use the WiFi item to configure a connection to a WiFi network See Fig 89 Check the Enable WiFi bo...

Page 132: ...ctor Depending on the SIM card you are using To set up backup routes you will need to enable Check Connection in the Mobile WAN item See Fig 91 Set the Check connection option to enabled bind and fill in an IP address of the mobile operator s DNS server or any other reliably available server and enter the time interval of the check For detailed configuration see Chapter 4 4 1 Figure 91 Backup acce...

Page 133: ...92 Backup access to the Internet Backup Routes configuration You can verify the configured network interfaces in the Status section in the Network item You will see the active network interfaces eth0 connection to LAN eth1 wired connection to the Internet wlan0 WiFi connection to the Internet and usb0 mobile connection to the Internet IP addresses and other data are included At the bottom of the p...

Page 134: ...configuration item in the web interface of the router see chapter 4 12 or Application Note 5 IPsec it is also configuration item in the web interface of the router see chapter 4 13 or Application Note 6 You can also create non encrypted tunnels GRE PPTP and L2TP You can use GRE or L2TP tunnel in combination with IPsec to create VPNs There is an example of an OpenVPN tunnel in Fig 93 To establish t...

Page 135: ... remote subnet and mask not necessary The important items are Local and Remote Interface IP Address where the information regarding the interfaces of the tunnel s end must be filled in In the example shown the pre shared secret is known so you would choose this option in the Authentication Mode item and insert the secret key into the field Confirm the configuration clicking the Apply button For de...

Page 136: ...custom hostname This client monitors the router s IP address and updates it whenever it changes GRE Generic Routing Encapsulation GRE is a tunneling protocol that can encapsulate a wide variety of network layer protocols inside virtual point to point links over an Internet Protocol net work It is possible to create four different tun nels HTTP The Hypertext Transfer Protocol HTTP is an application...

Page 137: ...pproaching 1 IPv6 addresses are represented as eight groups of four hexadecimal digits separated by colons 2001 0db8 85a3 0042 1000 8a2e 0370 7334 but methods of abbreviation of this full notation exist L2TP Layer 2 Tunnelling Protocol L2TP is a tunnelling protocol used to support virtual private networks VPNs or as part of the delivery of ser vices by ISPs It does not provide any encryption or co...

Page 138: ...509 Router A router is a device that forwards data packets between computer networks creating an overlay internetwork A router is connected to two or more data lines from different net works When a data packet comes in one of the lines the router reads the address information in the packet to determine its ultimate destina tion Then using information in its routing ta ble or routing policy it dire...

Page 139: ...tor abbreviated URL also known as web address is a spe cific character string that constitutes a refer ence to a resource In most web browsers the URL of a web page is displayed on top in side an address bar An example of a typi cal URL would be http www example com index html which indicates a protocol http a hostname www example com and a file name index html A URL is technically a type of uni f...

Page 140: ...inesses gov ernments organizations and individuals for al most any purpose imaginable X 509 In cryptography X 509 is an ITU T standard for a public key infrastructure PKI and Privilege Management Infrastructure PMI X 509 specifies amongst other things standard formats for public key certificates certificate re vocation lists attribute certificates and a certifi cation path validation algorithm 130...

Page 141: ...efault SIM card 40 Default username 5 DHCP 18 23 54 126 DHCPv6 24 Dynamic 24 Static 24 DHCPv6 18 23 54 DNS 126 DNS server 23 36 54 DNS64 16 Domain Name System see DNS DoS attacks 60 Dynamic Host Configuration Protocol see DHCP DynDNS 19 85 DynDNSv6 19 85 F Firewall 58 Filtering of Forwarded Packets 59 Filtering of Incoming Packets 58 Protection against DoS attacks 60 Firmware update 106 116 Firmwa...

Page 142: ...cess 63 Restore Configuration 115 Router 1 Accessing 5 Advantages 1 Equipment 1 Optional Features 1 S Save Log 20 Save Report 20 Security certificate 5 Send SMS 115 Serial number 8 Set internal clock 113 Signal Quality 9 Signal Strength 9 Simple Network Management Protocol see SNMP SMS 93 SMS Service Center 114 SMTP 91 128 SNMP 87 128 Startup Script 103 Switch between modules 43 Switch between SIM...

Page 143: ...User Datagram Protocol see UDP User Module 109 Users 111 V Virtual private network see VPN VPN 129 VRRP 30 129 W Web interface 5 WiFi 48 Authentication 49 HW Mode 49 Operating mode 48 WLAN 53 Operating mode 53 133 ...

Page 144: ...ication Note 4 Advantech B B SmartWorx R SeeNet Admin Application Note 5 Advantech B B SmartWorx OpenVPN Tunnel Application Note 6 Advantech B B SmartWorx IPsec Tunnel Application Note 7 Advantech B B SmartWorx GRE Tunnel Application Note 8 Advantech B B SmartWorx SNMP Object Identifier Application Note 9 Advantech B B SmartWorx AT Commands Application Note 10 Advantech B B SmartWorx Programming o...

Reviews: