background image

 

163 

Packet Filter 

You can filter the packages by MAC address, IP address, Protocol, Port number and Application or 
URL.  
 

 

Packet Filter - IP & MAC Filter

 

 

Packet Filter 

Filter Type:

 There are three types 

IP & MAC Filter

 and 

URL Filter

 that user can select for this filter 

rule. Here we set 

IP & MAC Filter

 

IP & MAC Filter Editing 

Action: 

This is how to deal with the packets matching the rule. Allow please select White List or block 

selecting Black List. 

Rule Index: 

This is item number 

Individual Active:

 Select 

Yes

 to activate the rule. 

Interface: 

Select to determine which interface the rule will be applied to.

 

Direction: 

Select  to  determine  whether  the  rule  applies  to  outgoing  packets,  incoming  packets  or 

packets of both directions. 

Type:

 Choose type of field you want to specify to monitor. Select 

IPv4

 for IPv4 address, port number 

and protocol. Select 

IPv6

 for IPv6 address, port number and protocol. Select 

MAC

 for MAC address.  

Source IP Address: 

The source IP address of packets to be monitored.  0.0.0.0 means 

Don’t care

Summary of Contents for BiPAC 4700AZ

Page 1: ...Last revised date November 22 2017 BiPAC 4700AZ Wireless AC 4G LTE VPN Outdoor Router User Manual Version release 1 04 1 x...

Page 2: ...n 13 Installation Reference 14 Cabling 17 Default Settings 18 Information from Your ISP 19 Chapter 4 Device Configuration 20 Login to your Device 20 Status 22 Device Info 23 System Status 25 System Lo...

Page 3: ...102 Static DNS 107 Time Schedule 108 Mail Alert 109 VPN 110 IPSec 111 PPTP Server 121 PPTP Client 123 L2TP 132 GRE Tunnel 142 OpenVPN Server 147 OpenVPN Client 149 Access Management 154 Device Manage...

Page 4: ...3 Problems with the Router 182 Problem with LAN Interface 182 Recovery Procedures 182 Appendix Product Support Contact 184...

Page 5: ...nd the extreme weather conditions Also built in 6K surge K 21 and 15KV ESD EN 61000 4 5 protection design protects against storm lightning surges and ensuring robust and reliable operation Easy Instal...

Page 6: ...col stacks either independently or in a hybrid form The hybrid form is commonly implemented in modern operating systems supporting IPv6 Quick Start Wizard Support a WEB GUI page to install this device...

Page 7: ...ired Equivalent Privacy WEP support Wireless Hotspot Enterprise level routing functionality OSPF BGP Firewall Security with DoS Preventing and Packet Filtering Universal Plug and Play UPnP Compliance...

Page 8: ...twork VPN Secured IPSec VPN with powerful DES AES Secured PPTP VPN with Pap Chap MPPE authentication Secured L2TP VPN with Pap Chap authentication Secured GRE VPN tunnels Secured OpenVPN Server and Cl...

Page 9: ...or remote and local management Firmware upgrades and configuration data upload and download via web based GUI Supports DHCP server client relay Supports SNMP v1 v2 v3 MIB I and MIB II CWMP TR 069 1 su...

Page 10: ...card slot One 1 Gigabit Ethernet WAN for Cable Fiber xDSL high WAN throughput One 1 Gigabit Ethernet LAN with PoE can obtain power via 802 3at PoE equipped switch or power injector Four 4 detachable 5...

Page 11: ...7 Application Diagram BiPAC 4700AZ...

Page 12: ...uter Do not use the router in high humidity or high temperature Do not open or repair the case yourself If the device becomes too hot turn off the power immediately and have it repaired at a qualified...

Page 13: ...ors for the 802 11n 2 4GHz 2 Reset After the device is powered on press it 6 seconds or above to restore to factory default settings this is used when you cannot login to the router e g forgot your pa...

Page 14: ...99 dBm Poor signal condition Orange No signal and the 4G LTE module is in service Off No LTE module or LTE module fails 7 Power LED The Power dual colour LED behaves as shown below Green System is up...

Page 15: ...11 Index Item Description 12 WiFi Antenna Connectors for 5GHz Manually screw the two supplied wireless antennas 5G tight to the connectors for the 802 11ac 5GHz 12 12 12 12...

Page 16: ...re starting recovery process please configure the IP address of the PC as 192 168 1 100 and proceed with the following step by step guide 1 Power the router off 2 Press reset button and power on the r...

Page 17: ...ress in the range of 192 168 1 1 to 192 168 1 253 The best and easiest way is to configure the PC to get an IP address automatically from the router using DHCP If you encounter any problems accessing...

Page 18: ...n Reference IMPORTANT It is recommended to put the Gigabit PoE Injector on an UPS or Surge Protector Use the supplied grounding wire to ground your BiPAC 4700ZU 4700ZUL ODU is REQUIRED I Grounding the...

Page 19: ...the mental contacts gold plate facing down to the SIM slot then push it all the way in until you hear the clicking sound 3 Screw the cap back tightly Attention Please power off the device before inser...

Page 20: ...f D 2 2 clip B on C 2 3 keep B close to D 2 4 then tighten A Step 3 Insert the other end of outdoor Ethernet cable RJ 45 to the supplied Gigabit PoE injector Data Power port Connect another Ethernet c...

Page 21: ...uses of problems is bad cabling Make sure that all connected devices are turned on On the front panel of the product is a bank of LEDs Verify that the LAN Link and LEDs are lit If they are not verify...

Page 22: ...Settings IP Address 192 168 1 254 Subnet Mask 255 255 255 0 DHCP Server DHCP server is enabled Start IP Address 192 168 1 100 IP pool counts 20 Attention If you ever forget the username password to lo...

Page 23: ...ion from Your ISP Before configuring this device you have to check with your ISP Internet Service Provider what kind of service is provided such as 4G LTE or EWAN Dynamic IP address Static IP address...

Page 24: ...IP address of your router which by default is 192 168 1 254 and click Go a user name and password window prompt appears The default username and password is admin and admin respectively for the Admin...

Page 25: ...includes Status Device Info System Status System Log 4G LTE Status Wireless Status Hotspot Status Statistics DHCP Table IPSec Status PPTP Status L2TP Status GRE Status OpenVPN Status ARP Table VRRP S...

Page 26: ...n check the router working status including Device Info System Status System Log 4G LTE Status Wireless Status Hotspot Status Statistics DHCP Table IPSec Status PPTP Status L2TP Status GRE Status Open...

Page 27: ...e current date and time System Up Time The duration since system is up Physical Port Status Here the page shows the status of physical port of 4G LTE EWAN Ethernet Wireless 2 4G and Wireless 5G WAN In...

Page 28: ...th Subnet mask for IPv4 or Prefix length for IPv6 on LAN DHCP Server LAN port DHCP information Wireless 2 4G Wireless 5G Mode The wireless mode in use SSID The SSID Channel The current channel Securit...

Page 29: ...rent system CPU and Memory loading CPU Usage To show the current CPU Usage Memory Total To show the total memory of the system in KB Memory Free To show the current free memory or avalavle memory in K...

Page 30: ...Log In system log you can check the operations status and any glitches to the router Refresh Press this button to refresh the statistics Backup Back up the current system log file and save it to your...

Page 31: ...ength and is calculated based on both RSRP and RSSI SINR Signal to Interference plus Noise Ratio is also a measure of signal quality as well It is widely used by the operators as it provides a clear r...

Page 32: ...ce the biling begins each month the beginning day counted Clean To clear the usage statistics Save Press to save the usage statistics to FLASH else the usage will be cleared after reboot Refresh Press...

Page 33: ...eless connection information MAC The MAC address of wireless client SSID Index The SSID index which wireless client connects to RSSI The received signal strength indication Connected Time Connection t...

Page 34: ...connect in IP Address The IP assigned to the client Authenticated Show the client is authorized or not User Name The username of the logined client in agreement mode no username showed Duration Time...

Page 35: ...tted until the latest second since system is up Receive Frames of Current Connection This field displays the number of frames received until the latest second for the current connection Receive Bytes...

Page 36: ...Receive Frames This field displays the number of frames received until the latest second Receive Multicast Frames This field displays the number of multicast frames received until the latest second R...

Page 37: ...eive Frames This field displays the number of frames received until the latest second Receive Multicast Frames This field displays the number of multicast frames received until the latest second Recei...

Page 38: ...the latest second Receive Frames This field displays the number of frames received until the latest second Receive Error Frames This field displays the number of error frames received until the latest...

Page 39: ...he latest second Receive Frames This field displays the number of frames received until the latest second Receive Error Frames This field displays the number of error frames received until the latest...

Page 40: ...ith clear information Index The index identifying the connected devices Host Name Show the hostname of the PC IP Address The IP allocated to the device MAC Address The MAC of the connected device Expi...

Page 41: ...l is active for connection Connection State Show the IPSec phase 1 and phase 2 connecting status Statistics Display the upstream downstream traffic per session in KB The value clears when session disc...

Page 42: ...tion Connection State Show the connecting status Connection Type Remote Access or LAN to LAN Assigned IP Address Show the IP assigned to the client by PPTP Server Server IP Address Show the IP of remo...

Page 43: ...Active Show if the tunnel is active for connection Connection State Show the connecting status Connection Mode The L2TP mode is dialin or dialout Connection Type Remote Access or LAN to LAN Tunnel Re...

Page 44: ...on Name Display the user defined GRE connection name Active Show if the tunnel is active for connection Remote Gateway IP The IP of the remote GRE gateway Remote Network Display the remote network Ref...

Page 45: ...to demosntrate the rule is active or not Service Port Show the service port protocl Tunnel Network The virtual tunnel subnet of the server Status The status of the rule Remote Server Show the remote s...

Page 46: ...le which shows the mapping of IP addresses to Ethernet MAC addresses Index The Index of the ARP rule item IP Address Shows the IP Address of the device that the MAC address maps to MAC Address Shows t...

Page 47: ...43 VRRP Status Show the VRRP status Current Status Show VRRP current status Master or Backup Current Master Show the IP address of current master...

Page 48: ...e For detailed instructions on configuring WAN settings see refer to the Interface Setup section Click Next to move on to Step 1 Step 1 Password Set new password of the admin account to access for rou...

Page 49: ...xt to continue Input all relevant 3G 4G LTE parameters from your ISP 4 2 If selected EWAN If selected PPPoE please enter PPPoE account information provided by your ISP Click Next to continue Or others...

Page 50: ...46 Step 5 Quick Start Completed The Setup Wizard has completed Click on Back to modify changes or mistakes Click Next to save the current settings Step 6 Quick Start Completed...

Page 51: ...on Click to access and configure the available features in the following Interface Setup Dual WAN Hotspot Advanced Setup VPN Access Management and Maintenance These functions are described in the foll...

Page 52: ...48 Interface Setup Here are the features under Interface Setup Internet LAN Wireless Wireless MAC Filter and Loopback...

Page 53: ...er this circumstance often only one PC is connected to the device Network Mode There are some options of service standards Automatic UMTS 3G only GSM 2G Only LTE Only If you are not sure which mode to...

Page 54: ...on Keep Alive IP Enter the IP address whic is used for ping and router will ping the IP to find whether the connection is on or not if not router will recover the connection Default Route Select Yes...

Page 55: ...priate operator SMS Control SMS Short Message Service allows users to send short message using your smartphone to the SIM card s number to control the device remotely SMS Control Check to enable the S...

Page 56: ...52 EWAN...

Page 57: ...er will not accept the IP address if it is not in this format PPPoE Select this option if your ISP requires you to use a PPPoE connection Bridge Select this mode if you want to use this device as an O...

Page 58: ...um Segment Size MSS IP Options Default Route Select Yes to use this interface as default route interface TCP MTU Option Enter the maximum packet that can be transmitted Default MTU is set to 1492 IPv4...

Page 59: ...up Multicast Protocol is a network layer protocol used to establish membership in a Multicast group Choose whether enable IGMP proxy IPv6 Options only when choose IPv4 IPv6 or just IPv6 in IP version...

Page 60: ...56 LAN A Local Area Network LAN is a shared communication system to which many computers are attached and is limited to the immediate area usually the same building or floor of a building...

Page 61: ...at have members of that group Dynamic Route Select the RIP version from RIP1 or RIP2 DHCPv4 Server DHCP Dynamic Host Configuration Protocol allows individual clients to obtain TCP IP configuration at...

Page 62: ...example 00 0A F7 45 6D ED When added you can see the ones listed as showed below IPv6 parameters The IPv6 address composes of two parts thus the prefix and the interface ID Interface Address Prefix L...

Page 63: ...prefix message and generate an address using a combination of locally available information MAC address and information prefix advertised by routers but they can obtain such information like DNS from...

Page 64: ...tion introduces the wireless LAN and some basic configurations Wireless LANs can be as complex as a number of computers with wireless LAN cards communicating through access points which bridge network...

Page 65: ...e between 20 and 1000 A beacon is a packet broadcast by the Router to synchronize the wireless network RTS CTS Threshold The RTS Request To Send threshold number of bytes for enabling RTS CTS handshak...

Page 66: ...reless access point AP to be distinguished from another For security propose change the default wlan ap to a unique ID name to the AP which is already built in to the router s wireless interface Make...

Page 67: ...A There are five alternatives to select from WEP 64 bit WEP 128 bit WPA PSK WPA2 PSK and Mixed WPA WPA2 PSK If you require high security for transmissions please select WPA PSK WPA2 PSK or WPA WPA2 PS...

Page 68: ...or 64 hexadecimal characters Key Renewal Interval The time interval for changing the security key automatically between wireless client and AP WDS Settings WDS Wireless distributed system is a wirele...

Page 69: ...S 3 Launch the wireless client s WPS utility Set the Config Mode as Enrollee press the WPS button on the top bar select the AP e g Billion_AP from the WPS AP List column Then press the PIN button loca...

Page 70: ...66...

Page 71: ...less client s WPS utility Set the Config Mode as Registrar Enter the PIN number in the PIN Code column then choose the correct AP e g Billion_AP from the WPS AP List before pressing the PIN button to...

Page 72: ...e that the setup is correctly done cross check to see if the SSID and the security setting of the registrar setting match with the parameters found on both Wireless Configuration and Wireless Security...

Page 73: ...ddress of the devices you wish to filter SSID Index Select the targeted SSID you want the MAC filter rules to apply to Active Select Activated to enable MAC address filtering Action Define the filter...

Page 74: ...s dual band 2 4G and 5G wireless router support 11b g n a ac wireless standards It allows multiple wireless users on 2 4G and 5G radio bands to surf the Internet You can choose the optimum radio band...

Page 75: ...tween 1500 and 2347 Fragmentation Threshold The threshold number of bytes for the fragmentation boundary for directed messages It is the maximum data fragment size that can be sent Enter a value betwe...

Page 76: ...rity is OPEN and to allow all wireless stations to communicate with the access points without any data encryption To prevent unauthorized wireless stations from accessing data transmitted over the net...

Page 77: ...nd communication with other access point It is easy to be installed just define the peer s MAC of the connected AP WDS Mode select Activated to enable WDS feature and Deactivated to disable this featu...

Page 78: ...BB 00 00 02 You need to know the MAC address of the devices you wish to filter Active Select Activated to enable MAC address filtering Action Define the filter action for the list of MAC addresses in...

Page 79: ...disconnect every now and then The lookback interface can have its own IP and subnet mask It is often used for router management as Telnet management IP and involved in BGP as BGP Update Source involv...

Page 80: ...ays on internet connection Users can set a WAN1 main WAN and WAN 2 backup WAN and when WAN1 fails it will switch to WAN2 and when WAN1 restores it will switch to WAN1 again General Setting Select Fail...

Page 81: ...ry link WAN1 fails and vise versa Example Auto failover takes place after straight 3 consecutive failures in every 30 seconds meaning all traffic will hand over to backup link WAN2 after primary link...

Page 82: ...onnectivity Decision Probe Cycle Set a number of times and time in seconds to determine when to turn off the Load Balancing service Example Disable Load Balance after straight 3 consecutive failures i...

Page 83: ...nd less delay User can distribute outbound traffic based on Session Mechanism or IP Hash Mechanism Base on Session Mechanism Balance by Session Round Robin Balance session traffic based on a round rob...

Page 84: ...the WAN interface the to be set rule will apply to and what type of traffic is to be bound to forward to the which WAN interface Source IP Address Enter the source IP address featuring the traffic ori...

Page 85: ...llion Industrial LTE Router HotSpot Gateway provides authentication for clients before access to public networks It also allows users to access some web pages without authentication using Walled Garde...

Page 86: ...WLAN1 it can be select in the future IP Address IP Subnet Mask The IP Subnet assigned to this Hotspot network The IP can be changed according to different user s need Primary Secondary DNS The DNS inf...

Page 87: ...fered by UAM server Shared Secret Set the shared secret password offered NAS ID An assigned string for identification Location Name An assigned string for identification Authentication Authentication...

Page 88: ...nt This part is to configure the account database for Built in UAM Server Up to 16 accounts can be created Rule Index 1 16 the valid user identifier index User Name Password Enter the username passwor...

Page 89: ...y unlimited Upload Download Bandwidth These privilegd clients can be added by MACs Authorized of Client Activate or Deactivate the feature Rule Index 1 16 trusted users can be added each identified by...

Page 90: ...es can be added Active Select Yes to activate the rule If activated the domain name or IP will be open without authentication to access Allow Type Choose between Host Network and Domain Host Domain En...

Page 91: ...uccessfully logged in Advertisement Activate or deactivate the Advertisement feature Mode The mode the propaganda advertisement is shown in Rule Index The rule index identifying the URL 1 15 URLs can...

Page 92: ...ped by Mail Alert How often to record the session log and to mail can be set here Session Log Activate session log or not Log Session data every Set how often to record the session log By default sess...

Page 93: ...rs to customize their desired authenticate page strings if not default settings are showed on the authentication page Places where strings are to be shown are listed in the following screenshots in re...

Page 94: ...tspot is running on SSID1 WLAN1 Change SSID to Billion Hotspot and set Security Type to Open 2 Move to Configuration Hotspot General Setting to set Hotspot Interface Captive Portal Authentication and...

Page 95: ...r authtication create a valid client account Wireless Client Connection 1 Connect to the SSID M500 Hotspot on the laptop 2 Launch the web brower the hotspot welcome and authentication page pops up 3 I...

Page 96: ...92...

Page 97: ...is running on SSID1 WLAN1 Change SSID to Billion Hotspot and set Security Type to Open 2 Move to Configuration Hotspot General Setting to set Hotspot Interface Captive Portal Authentication and Sessio...

Page 98: ...94 4 Add a new hotspot to SOCIFI dashboard https socifi doc atlassian net wiki display SC Billion M500 4G LTE...

Page 99: ...95 Wireless Client Connection 1 Connect to the SSID Billion Hotspot on the smart phone 2 Launch the web browser the hotspot welcome and authentication page pops up...

Page 100: ...96...

Page 101: ...97 Advanced Setup Advanced Step provides advanced features including Firewall Routing Dynamic Routing NAT VRRP Static DNS Time Schedule and Mail Alert for advanced users...

Page 102: ...nnot be directly accessed from the Internet Firewall To automatically detect and block Denial of Service DoS attacks such as Ping of Death SYN Flood Port Scan and Land Attack Enabled It activates your...

Page 103: ...ts the cost of transmission for routing purposes The number need not be precise but it must be between 1 and 15 Interface Media channel selected to append the route Edit Edit the route this icon is no...

Page 104: ...h will be our next topic the pricipal routing protocol between autonomous systems on the itnernet OSPF Enable to actiavte OSPF routing Rule Index A totoal 10 OSPF rules are allowed ranging from 0 to 9...

Page 105: ...to 9 Neighbor IP Set your neighbor IP Neighbor AS Number Set your neghbor AS number Allowas in Enable to allow inter communication between devices in the same AS If the local and neighbor AS number ar...

Page 106: ...communications In this session there are VPN Passthrough SIP ALG DMZ and Virtual Server provided to solve these nasty problems NAT Status Enabled It depends on ISP Connection Type in Internet setting...

Page 107: ...activates your DMZ function Disabled It disables the DMZ function DMZ Host IP Address Give a static IP address to the DMZ Host when Enabled radio button is checked Be aware that this IP will be expose...

Page 108: ...al service request to the appropriate server within the LAN network Virtual Server for Indicate the related WAN interface which allows outside network to connect in and communicate Protocol Choose the...

Page 109: ...twork For this reason you are advised to use specific Virtual Server entries just for the ports your application requires instead of using DMZ As doing so will result in all connections from the WAN a...

Page 110: ...and go to Configuration Advanced Setup NAT Virtual Server FTP server uses TCP protocol with port 21 Enter 21 to Start and End Port Number M100 will accept port 21 requests from WAN side Eneter the st...

Page 111: ...erical identifiers associated with networking equipment for the purpose of locating and addressing these devices worldwide An often used analogy to explain the Domain Name System is that it serves as...

Page 112: ...ol SNTP to get the current time from an SNTP server from the Internet Rule Index The rule index 0 15 for identifying each timeslot Rule Name User defined identification for each time period Day of Wee...

Page 113: ...ord Enter the password of your email account Sender s Email Enter your email address SSL TLS Check to whether to enable SSL encryption feature Port the port default is 25 Account Test Press this butto...

Page 114: ...mmunication infrastructures such as the Internet VPNs provide security through tunneling protocols and security procedures such as encryption For example a VPN could be used to securely connect the br...

Page 115: ...ween agents at the beginning of the session and negotiation of cryptographic keys to be used during the session IPSec is an end to end security scheme operating in the Internet Layer of the Internet P...

Page 116: ...blishing a VPN tunnel Local Access Range Set the IP address or subnet of the local network Single IP The IP address of the local host for establishing an IPSec connection between a security gateway an...

Page 117: ...are IP addresses IPv4 and IPv6 supported Encryption Algorithm Select the encryption algorithm from the drop down menu There are several options DES and AES 128 192 and 256 3DES and AES are more powerf...

Page 118: ...l i e over the Internet MODP stands for Modular Exponentiation Groups IPSec SA Lifetime SA Lifetime Specify the number of minutes that a Security Association SA will stay active before new encryption...

Page 119: ...m 0 to 3600 second 0 second disables the function Ping to the IP Interval sec Ping to the IP Action 0 0 0 0 0 No 0 0 0 0 2000 No xxx xxx xxx xxx A valid IP Address 0 No xxx xxx xxx xxx A valid IP Addr...

Page 120: ...116 Example How to establish an IPSec Tunnel 1 LAN to LAN connection Two VPN router want to setup a secure IPSec VPN tunnel Note The IPSec Settings shall be consistent between the two routers...

Page 121: ...1 0 Local Netwrok Netmask 255 255 255 0 Remote Access Range Subnet Branch office network Remote Netwrok IP Address 192 168 0 0 Remote Netwrok Netmask 255 255 255 0 IPSec Proposal IKE Mode Main Securi...

Page 122: ...8 0 0 Local Netwrok Netmask 255 255 255 0 Remote Access Range Subnet Branch office network Remote Netwrok IP Address 192 168 1 0 Remote Netwrok Netmask 255 255 255 0 IPSec Proposal IKE Mode Main Secur...

Page 123: ...119 2 Host to LAN Router servers as VPN server and host should install the IPSec client to connect to head office through IPSec VPN...

Page 124: ...92 168 1 0 Local Netwrok Netmask 255 255 255 0 Remote Access Range Signal IP Host Remote Netwrok IP Address 69 121 1 30 Remote Netwrok Netmask 255 255 255 255 IPSec Proposal IKE Mode Main Security Pla...

Page 125: ...client When passed the authentication with MS CHAPv2 the MPPE encryption is supported Encryption Ley Length Available when using MS CHAPv2 authentication mode The data can be encrypted by MPPE algori...

Page 126: ...N for remote gateway Private IP Address Assigned to Dial in User Specify the private IP address to be assigned to dialin clients and the IP should be in the same subnet as local LAN but not occupied R...

Page 127: ...en using MS CHAPv2 authentication mode The data can be encrypted by MPPE algorithm with 40 bits or 128 bits Default is Auto it is negotiated when establishing a connection 128 bit keys provide stronge...

Page 128: ...as Default Route Check to select the tunnel as the default route for traffic If selected all outgoing traffic will be forwarded to this tunnel and routed to the next hop Click Save button to save you...

Page 129: ...tablishes a PPTP VPN tunnel with head office to connect two private networks over the Internet The routers are installed in the head office and branch offices accordingly Note Both office LAN networks...

Page 130: ...ption Connection Name HS LL Give a name of PPTP conneciton Authentication Type MPPE 128bit Authentication type Username test Dial in authenticate user name Passwrod test Dial in authenticate user pass...

Page 131: ...Name BC LL Give a name of PPTP conneciton Authentication Type MPPE 128bit Authentication type Username test Dial in authenticate user name Passwrod test Dial in authenticate user password Conneciton T...

Page 132: ...Remote Access Dial in connection A remote worker establishes a PPTP VPN connection with the head office using Microsoft s VPN Adapter The router is installed in the head office connected to a couple o...

Page 133: ...sed in the office LAN Item Description Connection Name HS RA Give a name of L2TP conneciton Authentication Type MPPE 128bit Authentication type Username test Dial in authenticate user name Passwrod te...

Page 134: ...Remote Access Dial out connection A company s office establishes a PPTP VPN connection with a file server located at a separate location The router is installed in the office connected to a couple of...

Page 135: ...n head office Item Description Connection Name HC RA Give a name of PPTP conneciton Authentication Type MPPE 128bit Authentication type Username test Dial in authenticate user name Passwrod test Dial...

Page 136: ...el Conneciton Mode Connection Mode Select Dial In to operate as a L2TP server Authentication Type Default is Chap Pap CHAP Challenge Handshake Authentication Protocol PAP Password Authentication Proto...

Page 137: ...the username for this account Password Please input the password for this account Conneciton Type Connection Type Remote Access for single user Connection Type If LAN to LAN is selected enter the pee...

Page 138: ...elect Main or Aggressive mode IKE Local ID Type and Remote ID Type When the mode of IKE is aggressive Local and Remote peers can be identified by other IDs IKE Pre Shared Key This is for the Internet...

Page 139: ...stablishes a L2TP VPN tunnel with head office to connect two private networks over the Internet The routers are installed in the head office and branch office accordingly Note Both office LAN networks...

Page 140: ...HS LL Give a name of L2TP conneciton Connection Mode Dial in Operate as L2TP server Authentication Type Chap Pap Authentication type Username Test Dial in authenticate user name Passwrod Test Dial in...

Page 141: ...of L2TP conneciton Connection Mode Dial out Operate as L2TP client Server IP 69 121 1 33 Dialed server IP Authentication Type Chap Pap Authentication type Username test Dial in authenticate user name...

Page 142: ...Remote Access Dial in connection A remote worker establishes a L2TP VPN connection with the head office using Microsoft s VPN Adapter The router is installed in the head office connected to a couple o...

Page 143: ...em Description Connection Name HS RA Give a name of L2TP conneciton Connection Mode Dial in Operate as L2TP server Authentication Type Chap Pap Authentication type Username test Dial in authenticate u...

Page 144: ...Remote Access Dial out connection A company s office establishes a L2TP VPN connection with a file server located at a separate location The router is installed in the office connected to a couple of...

Page 145: ...2TP conneciton Connection Mode Dial out Operate as L2TP client Server IP 61 121 1 33 Dialed server IP Authentication Type Chap Pap Authentication type Username test Dial out authenticate user name Pas...

Page 146: ...tunnel Tunnel Network Netmask Please set the netmask for the local tunnel Tunnel Remote IP Address Set the peer IP address of the tunnel It is a virtual interface for the tunnel Remote Network IP Add...

Page 147: ...A Select Main or Aggressive mode IKE Local ID Type and Remote ID Type When the mode of IKE is aggressive Local and Remote peers can be identified by other IDs IKE Pre Shared Key This is for the Intern...

Page 148: ...blishes a GRE VPN tunnel with head office to connect two private networks over the Internet The routers are installed in the head office and branch office accordingly Note Both office LAN networks mus...

Page 149: ...1 1 30 Authentication type Tunnel Local IP Address Virtual Interface 192 168 100 11 The local virtual interface IP address for the tunnel Tunnel Remote IP Address Virtual Interface 192 168 100 10 The...

Page 150: ...1 1 3 Authentication type Tunnel Local IP Address Virtual Interface 192 168 100 10 The local virtual interface IP address for the tunnel Tunnel Remote IP Address Virtual Interface 192 168 100 11 The r...

Page 151: ...d being the most robust and feature rich It uses the OpenSSL encryption library extensively allowing OpenVPN to use all the ciphers available in the OpenSSL package as well as the SSLv3 TLSv1 protocol...

Page 152: ...ackage to encrypt both the data and channels Select the encryption method Hash To establish the integrity of the datagram and ensures it is not tampered with in transmission There are options Message...

Page 153: ...under this circumstance all outgoing packets will be forwarded to this tunnel and routed to the next hop Remote Subnet IP Address Set the network address of the remote peer Netmask Set the subnet mask...

Page 154: ...esistant to brute force attacks than MD5 However it is slower Keepalive Enable to allow the router to check the connectivity to the peer every 10 seconds can be changed based on need by sending ping p...

Page 155: ...tablishes a OpenVPN tunnel with head office to connect two private networks over the Internet The routers are installed in the head office and branch office accordingly Note Both office LAN networks m...

Page 156: ...ted in branch office The OpenVPN tunnel netwrok virtual interface is 192 168 100 0 24 Item Description Connection Name HS LL Give a name of GRE conneciton Tunnel Network Virtual Interface 192 168 100...

Page 157: ...s 69 1 121 3 is the Public IP address of the router located in head office Item Description Connection Name BC LL Give a name of GRE conneciton Server IP Address 69 121 1 3 The IP address of OpenVPN s...

Page 158: ...Management equipments the users with the ability of maintaining the access management including Device Management SNMP Remote Syslog Universal Plug Play Dynamic DNS Access Control Packet Filter CWMP...

Page 159: ...f needed HTTPS Port The HTTPS Port number change if needed HTTPS Server Certificate Index Choose the server security certificate Users need to upload the certificate for the https server See Certifica...

Page 160: ...anagement station Trap Manager IP Enter the IP of the server receiving the trap message when some exception occurs sent by this SNMP agent SNMPv3 Enable to activate the SNMPv3 Username Enter the name...

Page 161: ...ator can set up a remote system log server for receiving and monitoring the system information by enabling remote system log feature on the router Remote System Log Select whether to activate Remote S...

Page 162: ...natively support UPnP when the component is installed and Windows 98 users may install the Internet Connection Sharing client from Windows XP in order to support UPnP Windows 2000 does not support UPn...

Page 163: ...interfaces with different DNS es But note that first users have to go to the Dynamic DNS registration service provider to register an account Dynamic DNS Select this check box to activate Dynamic DNS...

Page 164: ...unt Note First users have to go to the Dynamic DNS registration service provider to register an account User test1 register a Dynamic Domain Names in DDNS provider http www dyndns org DDNS www hometes...

Page 165: ...low The maximum number of entries is 16 Access Control Select whether to make Access Control function available Rule Index This is item number Active Select to activate the rule Secure IP Address The...

Page 166: ...Default Rule 1 Index 0 a rule to allow only clients from LAN to have access to all embedded applications Web FTP etc Under this situation clients from WAN cannot access the router even from Ping Defa...

Page 167: ...e List or block selecting Black List Rule Index This is item number Individual Active Select Yes to activate the rule Interface Select to determine which interface the rule will be applied to Directio...

Page 168: ...that the rule applies to Time Schedule To determine when the rule takes effect The rule works always or winthin the set timeslot IP MAC Filter List Index Item number Active Whether the connection is...

Page 169: ...com please first press Activated in URL Filter field and also Yes in Individual Active field if some time you want to allow access to this URL you simply select No in individual active field In a word...

Page 170: ...ays set top box VoIP phones At the same time the configuration of this equipment became more complicated too complicated for end users For this reason TR 069 was developed It provides the possibility...

Page 171: ...to send an Inform message to the ACS automatically Interval s Specify the inform interval time sec which CPE used to periodically send inform message to automatically connect to ACS When the inform in...

Page 172: ...users Please get an account and configure at the selected Provider www opendns com in advance If activated the Parental Control has the top priority as DNS when accessing internet Host Name Username...

Page 173: ...e users with the ability of maintaining the device as well as examining the connectivity of the WAN connections including User Management Certificate Management Time Zone Firmware Configuration System...

Page 174: ...ment User Management controls the Router Web GUI permission to the specific account In factory setting the default accounts are admin admin The default root account admin has been authorized to web ac...

Page 175: ...etup Index User account index User Name Users can create account s to give it them access to router New Password Enter a new password for this user account Confirmed Password Re enter the new password...

Page 176: ...enance access Enable to have access to Interface Setup Advanced Setup and Access Management or disable to set the specifics yourself Interface Setup Enable to allowing access to Interface Setup with t...

Page 177: ...PKCS is disabled Enable PKCS12 to put Certificate Private Key in the same file like p12 pfx Check PKS 12 Check PKS 12 when the certificate and private key are packed into one file Browser to locate th...

Page 178: ...owse to locate the target file on PC before uploading it Click Save to submit the settings Trusted CA Listing Edit certificate Click move to Trusted CA editing page Index To identify the CA files 2 CA...

Page 179: ...o use Current Date Time To show the current time based on the time synchronization mechanism users choose below Synchronize time with Select the methods to synchronize the time NTP Server automaticall...

Page 180: ...ttings Restart the device with the current settings automatically when finishing upgrading Factory Default Settings Restart the device with factory default settings automatically when finishing upgrad...

Page 181: ...177 DO NOT turn off power off the device or interrupt the firmware upgrading while it is still in process Improper operation could damage your Industrial LTE Router...

Page 182: ...t settings for example after a firmware upgrade or if you have saved an incorrect configuration select Factory Default Settings to restore to factory default settings You may also restore your router...

Page 183: ...e current configuration of router for users in line with scheduled timetable settings Enable to set the time schedule for rebooting For example the router is scheduled to reboot at 22 00 every single...

Page 184: ...c Test page shows the test results for the connectivity of the physical layer and protocol layer for both LAN and WAN sides 4G LTE Click Start to begin to diagnose the connection Click Start Trace Rou...

Page 185: ...181...

Page 186: ...technical support You have forgotten your login username or password Try the default username admin and password admin If this fails you can restore your router to its factory settings by pressing the...

Page 187: ...reset button and power on the router once the Power flashes Red and Green keeping press reset button over 6 seconds 3 Internet LED flashes Green and Red router entering recovery procedure and router s...

Page 188: ...problems please contact the dealer from where you have purchased the product Contact Billion WORLDWIDE http www billion com MAC OS is a registered Trademark of Apple Computer Inc Windows XP Vista 7 8...

Page 189: ...uipment and receiver Connect the equipment into an outlet on a circuit different from that to which the receiver is connected Consult the dealer or an experienced radio TV technician for help FCC Caut...

Reviews: