©2016 Cradlepoint. All Rights Reserved.
|
+1.855.813.3385
cradlepoint.com
1
User Manual
/
IBR350
5/6/16
COR Series
Router
Page 1: ...2016 Cradlepoint All Rights Reserved 1 855 813 3385 cradlepoint com 1 User Manual IBR350 5 6 16 User Manual COR Series Router IBR350...
Page 2: ...ICATIONS 5 ACCESSORIES 6 BUSINESS GRADE MODEM SPECIFICATIONS 6 SUPPORT AND WARRANTY 8 HARDWARE 8 LEDS 9 QUICK START 10 BASIC SETUP 10 ACCESSING THE ADMINISTRATION PAGES 10 FIRST TIME SETUP WIZARD 11 U...
Page 3: ...29 ROUTING 38 QOS 39 DNS SERVERS 42 CLIENT DATA USAGE 44 SECURITY 45 IDENTITIES 45 ZONE FIREWALL 45 CONTENT FILTERING 50 CERTIFICATE MANAGEMENT 52 SYSTEM 55 ADMINISTRATION 55 ENTERPRISE CLOUD MANAGER...
Page 4: ...FEATURES WAN LTE only HSPA or LTE HSPA EVDO Advanced Modem Failure Check Standby LAN VLAN 802 1Q DHCP Server Client Relay DNS and DNS Proxy DynDNS UPnP DMZ Multicast Multicast Proxy QoS DSCP and Prior...
Page 5: ...ress Native support for authentication Authorization and accounting support through hotspot captive portal services 1 Enterprise Cloud Manager requires a subscription SPECIFICATIONS WAN Integrated LTE...
Page 6: ...erizon Technology LTE HSPA EVDO Rev A Downlink Rates LTE 100 Mbps HSPA 21 1 Mbps EVDO 3 1 Mbps theoretical Uplink Rates LTE 50 Mbps HSPA 5 76 Mbps EVDO 1 8 Mbps theoretical Frequency Bands LTE Band 2...
Page 7: ...Canada Technology LTE HSPA EVDO Rev A Downlink Rates LTE 100 Mbps HSPA 21 1 Mbps EVDO 3 1 Mbps theoretical Uplink Rates LTE 50 Mbps HSPA 5 76 Mbps EVDO 1 8 Mbps theoretical Frequency Bands LTE Band 2...
Page 8: ...ear limited hardware warranty available in the US and Canada two year limited hardware warranty for integrated EU products when purchased from an authorized EU distributor extend warranty to 2 3 or 5...
Page 9: ...power source connection Flashing Amber Attention Open the administration pages and check the router status ETHERNET LAN Indicates information about a data source connected to the Ethernet LAN port Gre...
Page 10: ...e antenna straight and twist the base of the antenna to connect folding the joint if needed NOTE Ensure that the router antennas are not near metal or other RF reflective surfaces 3 Connect the power...
Page 11: ...t s next generation management and application platform Enterprise Cloud Manager ECM integrates cloud management with your Cradlepoint devices to improve productivity increase reliability reduce costs...
Page 12: ...net LAN To quickly edit settings for any of these areas click on the pencil icon in the top right of the desired dialog box You may return to the Dashboard at any time by clicking on DASHBOARD from th...
Page 13: ...rnet is always maintained Availability Key Enable On Demand WAN Verify Data Usage Failback Standby STANDBY Standby is used to decrease failover time from one WAN interface to another When Standby is e...
Page 14: ...get out to the Internet and failed Idle Check Interval The amount of time between each check Default 30 seconds Range 10 3600 seconds Monitor while connected Default Off Select from the following dro...
Page 15: ...hen checked the WAN device will shutdown when the assigned usage is reached A cycle reset or a rule deletion will re enable the device Alert on Cap An email alert will be generated and sent when the a...
Page 16: ...IBR350 5 6 16 STATUS Internet Client List Tunnels Firewall Routing Ethernet GPS LLDP System Logs INTERNET CONNECTIONS Select your device to reveal detailed information about the following device prope...
Page 17: ...2016 Cradlepoint All Rights Reserved 1 855 813 3385 cradlepoint com 17 User Manual IBR350 5 6 16...
Page 18: ...2016 Cradlepoint All Rights Reserved 1 855 813 3385 cradlepoint com 18 User Manual IBR350 5 6 16...
Page 19: ...A USAGE Displays the following client information Name IP Address MAC Address Data Uploaded Data Downloaded Last Traffic To reset information click Reset Statistics STATISTICS Statistics can be gather...
Page 20: ...l Rights Reserved 1 855 813 3385 cradlepoint com 20 User Manual IBR350 5 6 16 QOS Displays packets and bytes transmitted and received by your Quality of Service QoS queues To enable and configure QoS...
Page 21: ...s of Wired Clients TUNNELS CP SECURE VPN Displays status of your CP Secure VPN Tunnels To add and configure CP Secure VPN Tunnels go to NETWORKING Tunnels CP Secure VPN IPSEC VPN Displays status of yo...
Page 22: ...ut your Firewall Connection Tracking States To configure your firewall select SECURITY from the left navigation ROUTING Displays information about your System GRE and NEMO Routes To configure these ro...
Page 23: ...rmation about your Ethernet ports To configure Ethernet ports go to NETWORKING Local Networks Ethernet Ports GPS Displays GPS location and status To enable and configure GPS go to SYSTEM Administratio...
Page 24: ...device directly to the router with an Ethernet cable Link Speed Default setting is Auto The Auto setting is preferred in most cases Auto 10Mbps Half Duplex 10Mbps Full Duplex 100Mbps Half Duplex 100M...
Page 25: ...is the DNS name associated with the router s local area network IP address IPv4 Settings IP Address This is the address used by the router for local area network communication Changes to this paramete...
Page 26: ...example the IPv6 address of 0001 0000 0234 5678 0000 0000 9abc 0def can be expressed as 1 0 234 5678 9abc def Interfaces Select the network interfaces which will be attached to this network by either...
Page 27: ...ation Altnet If multicast traffic originates outside the upstream subnet add address es to the altnet to define legal multicast sources IPv6 Addressing Address Configuration Mode SLAAC stands for Stat...
Page 28: ...or blacklist simply by inputting each device s MAC address NOTE Use caution when using the MAC Filter to avoid accidentally blocking yourself from accessing the router MAC Logging Configuration Enable...
Page 29: ...to create a new VLAN interface To edit an interface select the check box next to the desired interface TUNNELS CP SECURE VPN Configured deployed and managed from the cloud CP Secure VPN delivers a vir...
Page 30: ...in com or just a fully qualified domain name www mydomain com If the remote side of the tunnel is configured to expect an identifier then both must match in order for the negotiation to succeed If NAT...
Page 31: ...port on the router that you are plugging the modem into e g USB Port 2 Manufacturer Select by the modem manufacturer e g Cradlepoint Inc Model Set your rule according to the specific model of modem Ty...
Page 32: ...ut the default settings will be sufficient for most users To set up a tunnel with a remote site you need to match your tunnel s IKE negotiation parameters with the remote site By selecting several enc...
Page 33: ...rity list by clicking and dragging algorithms up or down Any selected algorithm may be used for IKE exchange but the algorithms on the top of the list are more likely to be used more often Add Edit Tu...
Page 34: ...ction page Under Failover Tunnel select the other tunnel you have created 3 Open the editor for the failover tunnel Make sure Tunnel Enabled is not selected On the Dead Peer Detection page set the Fai...
Page 35: ...a name that uniquely identifies it Tunnel Key Enables an ID key for a GRE tunnel which can be used as an identifier for mGRE Multipoint GRE Local Network This is the local side of the Glue Network a n...
Page 36: ...this tunnel when the specified WAN Binding device s are NOT connected Tunnel Enabled Select to activate the tunnel Add Edit Tunnel Routes Adding routes allows you to configure what types of network tr...
Page 37: ...5177 The protocol allows session continuity for every node in a mobile network as the network moves NOTE NEMO requires a feature license not included with ECM Prime Go to SYSTEM Administration Featur...
Page 38: ...e address range IP Network Address or IPv6 Address The IP address of the target network or host The IPv6 address field includes CIDR notation to declare a range of addresses Netmask Prefix The Netmask...
Page 39: ...our particular Internet connection for best results NOTE Upload speed is the speed at which data can be transferred to your ISP Download speed is the speed at which data can be transferred to you from...
Page 40: ...traffic Higher priority traffic is handled before lower priority traffic which can lead to shorter response times Also when spare bandwidth is available it is offered to higher priority queues first M...
Page 41: ...s TCP UDP TCP UDP or ICMP Select Any if your rule does not control a specific type of message that uses a specific protocol Queue Name Select a queue to associate this rule with Click Next to continue...
Page 42: ...the device has these distinct functions DNS Settings By default your router is set to automatically acquire DNS servers through your Internet provider Automatic DNS Settings allows you to specify DNS...
Page 43: ...nternet Service Providers assign dynamic changing IP addresses When you use a Dynamic DNS service provider you can enter your host name to connect to your server no matter what your IP address is Enab...
Page 44: ...this field IP address The address of the device within your network EXAMPLE a personal laptop with IP address 192 168 0 164 could be assigned the name MyLaptop Since the assigned name is mapped to an...
Page 45: ...FQDN addresses in the same identity IP addresses are entered using CIDR notation e g 1 2 3 4 32 and 0123 4567 CDEF 128 FQDN addresses are entered with at least one dot separating a top level domain f...
Page 46: ...rewall if none of the filter policy rules match the traffic being filtered Log When checked every rule in the policy will log matching packets as if the rule s Log option had been selected Click Add t...
Page 47: ...otocol Not needed for passive mode IRC For Direct Client to Client DCC transfer when using Internet Relay Chat You may wish to forward TCP port 113 for incoming identd RFC 1413 requests DMZ Demilitari...
Page 48: ...itioning from short prefix to a longer prefix such as from 48 to 64 is not without problems as some of the LANs may lose IPv6 connectivity REMOTE ACCESS RESTRICTION Add any IPv4 addresses that need ac...
Page 49: ...erfaces selectable via a Zone For example GRE interfaces can be used to port forward traffic from the GRE endpoints to local client thereby limiting exposure to the local LAN while still gaining the b...
Page 50: ...ebsite access Click Add Edit to change this setting for a MAC address MAC WEB FILTER RULES CONTENT FILTERING WEBFILTER SETTINGS General Settings Enbable Webfilter Selecting Enable Webfilter will enabl...
Page 51: ...be created by adding another rule with higher priority For example if access to maps example com is desired but example com is blocked with a priority of 50 The addition of an allow rule for maps exa...
Page 52: ...the Remove button Select a third party Cloud Provider from the dropdown list Umbrella by OpenDNS Umbrella by OpenDNS Umbrella by OpenDNS is a cloud based web filtering and security solution that prote...
Page 53: ...lf signed certificates for more information Generate a certificate signing request CSR by selecting a certificate from the dropdown list Certificate Name field and downloading the CSR The CSR can then...
Page 54: ...om the dropdown list and download it to your computer or local device in PKCS 12 format When you export this file you must create a passphrase to protect it This key is required for future use of the...
Page 55: ...s a user to enable incoming WAN pings or change settings for the router from the Internet using the router s Internet address Allow WAN pings When enabled the functionality allows an external WAN clie...
Page 56: ...ing an NTP server and adjusting the NTP server port Select the NTP server from the dropdown list Any of the given NTP servers will be sufficient unless for example you need to synchronize your router...
Page 57: ...sword to log in SSH Server Port Default 22 Automatically Set System Identifier This will automatically set the system ID to the name of the first client that gets a DHCP lease This feature cannot be u...
Page 58: ...modem Most modems have SMS enabled by default but the carrier may charge a fee for each text message sent or received Contact your carrier to review these fees and or to enable an SMS plan Important...
Page 59: ...24 and will treat the BOM as ASCII text which will appear as garbled characters in the log If this occurs disable this option Log to attached USB stick Only enable this option if instructed by a Cradl...
Page 60: ...ettings Advanced Enabled Enable the ECM client to contact the server While this box is unchecked the ECM client will never attempt to contact the server Default Enabled Server Host Port The DNS hostna...
Page 61: ...eekly and monthly reports Frequency You also choose the Time you want the alert sent SMTP Mail Server Since your router does not have its own email server to receive alerts you must enable an SMTP ser...
Page 62: ...to the WAN interfaces of the router WAN port Use the WAN port field to configure which publicly accessible port you wish to make SNMP services available on Default 161 SNMP Version SNMPv1 SNMP version...
Page 63: ...fields This password must be at least eight characters long Enable SNMP traps Enabling traps will allow you to configure a destination server community and port for trap notifications Trap notificatio...
Page 64: ...estore Settings Click on Restore Settings to restore your previous settings from a file on a computer Firmware Management Load new firmware and restore your previous settings from a file on a computer...
Page 65: ...tive image On multi firmware modems the carrier firmware is selected automatically Carrier Displays the carrier supported by the modem firmware For carriers not otherwise available Generic will be dis...
Page 66: ...Cradlepoint server WAN Device The WAN Device that is selected will have the test run on it If no device is selected then the highest priority connected device will be used Custom Server Type the Hostn...
Page 67: ...IS APN WIZARD if you have already configured an APN Any specific modem settings will not be overwritten by this generic APN setup Leave this setting as default and after finishing this Wizard go to th...
Page 68: ...the router takes no action to verify that it is still up On Modems will be set to use the Passive DNS failure check type Ethernet connections will be set to use Active Ping Ping IP Address This IP ad...
Page 69: ...o operate this equipment This device complies with Part 15 of the FCC Rules Operation is subject to the following two conditions 1 This device may not cause harmful interference and 2 this device must...
Page 70: ...E POWERED OFF AT ALL TIMES since the device otherwise could transmit signals that might interfere with various onboard systems on such aircraft Furthermore under no circumstances should the device be...
Page 71: ...UNDER OR IN CONNECTION WITH THE DEVICE REGARDLESS OF THE NUMBER OF EVENTS OCCURRENCES OR CLAIMS GIVING RISE TO LIABILITY EXCEED THE PRICE PAID BY THE ORIGINAL PURCHASER OF THE DEVICE PRIVACY Cradlepo...