Geneko GWR-I series User Manual Download Page 6

USER MANUAL

  

 

GWR-I Cellular Router Series

 

 

 

 

List of Tables 

Table 1 - Technical parameters ....................................................................................................................................10

 

Table 2 – GWR-I Router features.................................................................................................................................11

 

Table 3 - Network parameters .....................................................................................................................................21

 

Table 4 - DHCP Server parameters .............................................................................................................................22

 

Table 5 - WAN parameters...........................................................................................................................................25

 

Table 6 – Advanced WAN Settings.............................................................................................................................27

 

Table 7 – Routing parameters ......................................................................................................................................29

 

Table 8 – RIP parameters ..............................................................................................................................................31

 

Table 9 – GRE parameters ............................................................................................................................................34

 

Table 10 - IPSec Summary for second firmware version .........................................................................................36

 

Table 11 - IPSec Parameters for second firmware version.......................................................................................40

 

Table 12 - IPSec Summary for first firmware version...............................................................................................42

 

Table 13 - IPSec Parameters for first firmware version ............................................................................................46

 

Table 14 – OpenVPN parameters ................................................................................................................................48

 

Table 15 - IP filtering parameters ................................................................................................................................51

 

Table 16 – DynDNS parameters ..................................................................................................................................54

 

Table 17 – Ser2IP parameters .......................................................................................................................................56

 

Table 18 - Serial port parameters.................................................................................................................................57

 

Table 19 – Modbus gateway parameters....................................................................................................................58

 

Table 20 – GPIO parameters ........................................................................................................................................61

 

Table 21 - Device Identity parameters ........................................................................................................................62

 

Table 22 - Administrator password ............................................................................................................................63

 

Table 23 - Date/time parameters ................................................................................................................................64

 

Table 24 – Command Line Interface parameters ......................................................................................................68

 

Table 25 – Remote Management parameters.............................................................................................................69

 

Table 26 - SNMP parameters .......................................................................................................................................73

 

Table 27 - Syslog parameters .......................................................................................................................................74

 

 

Summary of Contents for GWR-I series

Page 1: ...GWR I Cellular Router Series User Manual version 1 0 date 10 08 2012 WWW INFOPULSAS LT info infopulsas lt...

Page 2: ...tion Protocol RIP 29 RIP routing engine for the GWR I Router 31 Settings VPN Settings 33 Generic Routing Encapsulation GRE 33 GRE Keepalive 34 Internet Protocol Security IPSec 35 Default firmware vers...

Page 3: ...GRE Tunnel configuration between two GWR I Routers 76 GRE Tunnel configuration between GWR I Router and third party router 80 IPSec Tunnel configuration between two GWR I Routers 83 IPSec Tunnel conf...

Page 4: ...Filtering settings 52 Figure 25 DynDNS settings 53 Figure 26 Serial Port Settings initial menu 54 Figure 27 Serial Port Settings 1 PINOUT 54 Figure 28 Serial Port configuration page 56 Figure 29 Modb...

Page 5: ...SEC configuration page III for GWR I Router 1 92 Figure 78 IPSec start stop page for GWR I Router 1 92 Figure 79 Network configuration page for GWR I Router 2 93 Figure 80 IPSEC configuration page I f...

Page 6: ...cond firmware version 40 Table 12 IPSec Summary for first firmware version 42 Table 13 IPSec Parameters for first firmware version 46 Table 14 OpenVPN parameters 48 Table 15 IP filtering parameters 51...

Page 7: ...rail mounting kit is part of standard equipment for GWR I series Many useful features make GWR I cellular routers a perfect solution for wide variety of industrial applications Dual SIM card support i...

Page 8: ...upervision Extra high voltage equipment monitoring Running water gas pipe line supervision Centralized heating system supervision Environment protection data collection Flood control data collection A...

Page 9: ...output 700mA 60VDC 1 5KV isolation GWR I202 GPRS Tri band 900 1800 1900 GPRS multi slot class 10 mobile station class B GPRS DL 85 6Kbps UL 42 8Kbps GWR I252 GPRS EDGE Quad band GSM 850 900 1800 1900M...

Page 10: ...twork attached devices for conditions that warrant administrative attention NTP RFC1305 The Network Time Protocol is a protocol for synchronizing the clocks of router DynDNS Dynamic DNS DDNS is a doma...

Page 11: ...Application HTTP based Command Line Interface Serial console telnet and SSH GWR connection wizard Initial setup utility SMS Control Control the basic router functionalities by SMS Remote management an...

Page 12: ...r Description 1 Reset red LED on the GWR I Router reset state 2 Power status green LED on Power supply Power status LED will blink when the GWR Router is in initializing state 3 Link red LED will blin...

Page 13: ...reset to factory defaults Warm reset If the GWR I Router is having problem connecting to the Internet press and hold the reset button for a second using the tip of a pen Reset to Factory Defaults To...

Page 14: ...inserted And finally device should have powered up external power supply NOTE Since the router is dedicated for operation in rough environments SIM card slots are located within the router chassis In...

Page 15: ...s 15 Figure 4 Inserting the SIM card SIM card must not be changed installed or taken out while device operates This procedure is performed when power supply is not connected In order to open the route...

Page 16: ...USER MANUAL GWR I Cellular Router Series 16 Declaration of conformity...

Page 17: ...instructions Device configuration using web application The GWR I Router s web based utility allows you to set up the Router and perform advanced configuration and troubleshooting This chapter will e...

Page 18: ...tton By clicking Reload previous settings will be loaded in the form Status Information The GWR I Router s Status menu provides general information about router as well as real time network informatio...

Page 19: ...information is shown in Figure 7 Status WAN Information WAN Information Tab provides information about GPRS EDGE HSPA connection and traffic statistics WAN information menu has three submenus which pr...

Page 20: ...USER MANUAL GWR I Cellular Router Series 20 Figure 8 WAN Information...

Page 21: ...ry default IP address Subnet Mask The subnet mask specifies the network number portion of an IP address The GWR I Router support sub netting You must specified subnet mask for your LAN TCP IP settings...

Page 22: ...pecifies the first of the contiguous addresses in the IP address pool IP Ending Address To This field specifies last of the contiguous addresses in the IP address pool Lease Duration This field specif...

Page 23: ...USER MANUAL GWR I Cellular Router Series 23 Figure 10 DHCP Server configuration page...

Page 24: ...M UMTS ISP You can setup any name for provider Authentication This field specifies password authentication protocol Select the appropriate protocol from drop down list PAP CHAP PAP CHAP Username This...

Page 25: ...ies the time interval of advanced ping proofing Advanced ping wait for a response This field specifies the timeout for advanced ping proofing Maximum number of failed packets This field specifies maxi...

Page 26: ...peer using PAP Require PAP Require the peer to authenticate using PAP Password Authentication Protocol authentication Refuse CHAP With this option pppd will not agree to authenticate itself to the pe...

Page 27: ...his option pppd will not transmit LCP packets to initiate a connection until a valid LCP packet is received from the peer as for the passive option with ancient versions of pppd Append domain name App...

Page 28: ...nside the network Routing Settings Label Description Routing Table Enable This check box allows you to activate deactivate this static route Source IP Source IP address from which portforwarding is al...

Page 29: ...e WAN interface to inside LAN interface is done on PPP and in reverse direction on Ethernet interface Add Click Add to insert add new item in table to the GWR I Router Remove Click Remove to delete se...

Page 30: ...ork stability guaranteeing that if one network connection goes down the network can quickly adapt to send packets through another connection Click RIP Tab to open the Routing Information Protocol scre...

Page 31: ...able 8 RIP parameters RIP routing engine for the GWR I Router Use telnet to enter in global configuration mode telnet 192 168 1 1 2602 telnet to eth0 at TCP port 2602 To enable RIP use the following c...

Page 32: ...ne routing protocol performance to better suit your internetwork needs Use following command to setup RIP timer router timers basic UPDATE INTERVAL INVALID TIMEOUT GARBAGE COLLECT router no timers bas...

Page 33: ...to create VPN tunnels For example if you configure Microsoft VPN tunnels by default you use PPTP which uses GRE Solution where you can use GRE protocol You need to encrypt multicast traffic GRE tunne...

Page 34: ...ge GRE Keepalive GRE tunnels can use periodic status messages known as keepalives to verify the integrity of the tunnel from end to end By default GRE tunnel keepalives are disabled Use the keepalive...

Page 35: ...ion as more reliable and secure solution Only with this version you have option to define IKE retry failover mechanism and log level of IPSec system messages If you cannot use IP address as a peer ide...

Page 36: ...ct IPSec tunnel initiating side in negotiation process Wait IPSec tunnel responding side in negotiation process Log level Set IPSec log level Delete Click on this link to delete the tunnel and all set...

Page 37: ...USER MANUAL GWR I Cellular Router Series 37 Figure 16 IPSec Settings for second firmware version...

Page 38: ...same encryption method Phase 1 Authentication Select a method of authentication MD5 or SHA1 The authentication method determines how the ESP packets are validated MD5 is a one way hashing algorithm th...

Page 39: ...om Peer ID Authentication identity for one of the participant Can be an IP address or fully qualified domain name preceded by IP Address From Select SIM card over which the tunnel is established Local...

Page 40: ...er will disconnect the tunnel so the connection can be re established Specify the interval between HELLO ACK messages how often you want the messages to be sent The default interval is 20 seconds NAT...

Page 41: ...d IPSec tunnels Enc Auth Grp This field shows both Phase 1 and Phase 2 details Encryption method DES 3DES AES Authentication method MD5 SHA1 and DH Group number 1 2 5 that you have defined in the IPSe...

Page 42: ...on this button to refresh the Status field in the Summary table Table 12 IPSec Summary for first firmware version To create a tunnel click Add New Tunnel button Depending on your selection the Local...

Page 43: ...DH Group Phase 1 is used to create the SA DH Diffie Hellman is a key exchange protocol used during Phase 1 of the authentication process to establish pre shared keys There are three groups of differen...

Page 44: ...produces a 128 bit digest SHA1 is a one way hashing algorithm that produces a 160 bit digest SHA1 is recommended because it is more secure Both ends of the IPSec tunnel must use the same Phase 2 Auth...

Page 45: ...terval between advanced ping packets Advanced Ping Wait For A Response Advanced ping proofing timeout Maximum numbers of failed packets Set percentage of failed packets until failover action is perfor...

Page 46: ...onger has access to the original SA s and their associated keying material Back Click Back to return on IPSec Summary screen Reload Click Reload to discard any changes and reload previous settings Sav...

Page 47: ...creation a static key must be generated on one side and the same key must be uploaded on the opposite side Figure 19 OpenVPN example OpenVPN Label Description IP Filtering Tunnel Number Automatically...

Page 48: ...e If you select UDP protocol whether in connect or wait mode you must specify Max Fragment Size default is 1300 bytes Renegotiate interval Specify renegotiate interval if username password is selected...

Page 49: ...USER MANUAL GWR I Cellular Router Series 49 Figure 20 OpenVPN configuration page Figure 21 OpenVPN network topology...

Page 50: ...er at the same time In the other words this setting allows one local user to be exposed to the Internet to use a special purpose services such as Internet gaming Video conferencing and etc It is recom...

Page 51: ...the GWR I Router Add Click Add to insert add new item in table to the GWR I Router Remove Click Remove to delete selected item from table Demilitarized Zone Host Settings DMZ Private IP Address This c...

Page 52: ...Series 52 IP Filtering configuration example This example configuration demonstrates how to secure a network with a combination of routers and a GWR I Router Figure 23 IP Filtering configuration examp...

Page 53: ...DynDNS Client Service The type of service that you are using try one of dhs pgpow dyndns dyndns static dyndns custom ods easydns dyns justlinux and zoneedit Custom Server IP The server IP to connect...

Page 54: ...e to perform serial to ethernet conversion Serial port over TCP UDP and ModbusRTU to TCP conversion Modbus gateway Initial Serial Port Settings page is shown in figure bellow By default above describe...

Page 55: ...indicates the end of transmission The default is 1 Flow control Flow control manages data flow between devices in a network to ensure it is processed efficiently Too much data arriving before a devic...

Page 56: ...Save button to save your changes back to the GWR I Router and activate deactivate serial to Ethernet converter Table 17 Ser2IP parameters Click Serial Port Tab to open the Serial Port Configuration s...

Page 57: ...op bit follows the data and parity bits in serial communication It indicates the end of transmission The default is 1 Flow control Flow control manages data flow between devices in a network to ensure...

Page 58: ...transmission Valid stop bits are 1 and 2 The default is 1 Flow control Flow control manages data flow between devices in a network to ensure it is processed efficiently Too much data arriving before a...

Page 59: ...settings related to Serial Port 2 are equivalent to the Serial Port 1 settings The only difference is in type of connector and serial port standard Namely serial port 2 supports RS232 and RS485 4W sta...

Page 60: ...ntaining following string PPP RECONNECT After the command is executed router sends a confirmation SMS with OK if the command is executed without errors or ERROR if something went wrong during the exec...

Page 61: ...between sending an SMS alert on input change to LOW or setting up the digital output HIGH or LOW High Action1 Action2 Setup required action when router detects high level on digital input It is possib...

Page 62: ...Router Only for information purpose Location This field specifies location of the GWR I Router Only for information purpose Save Click Save button to save your changes back to the GWR I Router Reload...

Page 63: ...outer New Password Enter a new password for GWR I Router Your password must have 20 or fewer characters and cannot contain any space Confirm Password Re enter the new password to confirm it Save Click...

Page 64: ...ging parameters Sync Clock With Client Date and time setting on the basis of PC calendar Time Protocol Choose the time protocol Time Server Address Time server IP address Time Zone Select your time zo...

Page 65: ...on If you need to download the latest version of the GWR I Router firmware please visit Geneko support site Follow the on screen instructions to access the download page for the GWR I Router If you ha...

Page 66: ...eed to import the configuration file that you previously exported Figure 38 Export Import the configuration on the router Import Configuration File To import a configuration file first specify where y...

Page 67: ...ettings Only use this feature if you wish to discard all the settings and preferences that you have configured Click Default Setting to have the GWR I Router with default parameters Keep network setti...

Page 68: ...e Interface Label Description CLI Settings Enable Enable or disable CLI CLI on Telnet SSH Serial View Mode Username Login name for View mode View Mode Password Password for View mode Confirm Password...

Page 69: ...sername Specify the username Password Specify the password Save Click Save to save your changes back to the GWR I Router Reload Click Reload to discard any changes and reload previous settings Table 2...

Page 70: ...net mask GWR I router s Ethernet port and GPRS EDGE HSPA network connection Selecting this option you can configure parameters for LAN and WAN interface Figure 45 Connection Wizard Initial Step Select...

Page 71: ...on When you select one of the routers from the list and click Next you will get to the following screen Figure 47 Connection Wizard LAN Settings If you selected to configure LAN and WAN interface clic...

Page 72: ...interface Management Simple Management Protocol SNMP SNMP or Simple Network Management Protocol is a network protocol that provides network administrators with the ability to monitor the status of the...

Page 73: ...load previous settings Save Click Save button to save your changes back to the GWR I Router and enable disable SNMP Table 26 SNMP parameters Management Logs Syslog is a standard for forwarding log mes...

Page 74: ...nt The default is 514 You can specify port by marking on user defined and specify port you want Syslog data to be sent User defined Set manually port number Default Use standard port number for this s...

Page 75: ...ges Use SIM card with a dynamic static IP address obtained from Mobile Operator Note the default gateway may show or change to an address such as 10 0 0 1 this is normal as it is the GSM UMTS provider...

Page 76: ...TS APN Type For GSM UMTS networks GWR I Router connections may require a Custom APN A Custom APN allows for various IP addressing options particularly static IP addresses which are needed for most VPN...

Page 77: ...ion 10 251 49 3 select HOST from drop down menu if you want to use host name as peer identifier KeepAlive enable no Period none Retries none Press ADD to put GRE tunnel rule into GRE table Press Save...

Page 78: ...connection WAN Settings Tab If disconnected please click Connect button Click VPN Settings GRE to configure GRE tunnel parameters Enable yes Local Tunnel Address 10 10 10 2 Local Tunnel Netmask 255 2...

Page 79: ...s 79 Figure 58 Routing configuration page for GWR I Router 2 Optionally configure IP Filtering and TCP service port settings to block any unwanted incoming traffic On the device connected on GWR I rou...

Page 80: ...t has two paths to the remote physical interface and the tunnel interface running through the tunnel This tunnel could then transmit unroutable traffic such as NetBIOS or AppleTalk The GWR I Router us...

Page 81: ...5 ip route 10 1 1 0 255 255 255 0 tunnel0 The GWR I Router Sample Configuration Click Network Tab to open the LAN NETWORK screen Use this screen to configure LAN TCP IP settings Configure IP address a...

Page 82: ...Figure 61 GRE configuration page Configure GRE Route Click Routing on Settings Tab Parameters for this example are Destination Network 10 2 2 0 Netmask 255 255 255 0 Figure 62 Routing configuration p...

Page 83: ...ve internet access GSM UMTS APN Type For GSM UMTS networks GWR I Router connections may require a Custom APN A Custom APN allows for various IP addressing options particularly static IP addresses whic...

Page 84: ...ct button Click VPN Settings IPSEC to configure IPSEC tunnel parameters Click Add New Tunnel button to create new IPSec tunnel Tunnel parameters are Add New Tunnel Tunnel Name test Enable true IPSec S...

Page 85: ...vanced Negotiation Mode Aggressive Compress Support IP Payload Compression Protocol IPComp false Dead Peer Detection DPD false NAT Traversal true Send Initial Contact true Figure 65 IPSEC configuratio...

Page 86: ...Security page to initiate IPSEC tunnel Figure 68 IPSec start stop page for GWR I Router 1 On the device connected on GWR I router 1 setup default gateway 10 0 10 1 The GWR I Router 2 configuration Cl...

Page 87: ...ase 1 DH group Group 2 Phase 1 Encryption 3DES Phase 1 Authentication MD5 Phase 1 SA Life Time 28800 Perfect Forward Secrecy true Phase 2 DH group Group 2 Phase 2 Encryption DES Phase 2 Authentication...

Page 88: ...Figure 70 IPSEC configuration page I for GWR I Router 2 Figure 71 IPSec configuration page II for GWR I Router 2 NOTE If option NAT Traversal is selected Aggressive mode is predefined Figure 72 IPSec...

Page 89: ...e of negotiation in IPSec tunnel configuration process Main mode Considering this both routers will be in main mode and there will not be displayed option for Negotiation mode in IPSec configurations...

Page 90: ...group Group 2 Phase 1 Encryption 3DES Phase 1 Authentication MD5 Phase 1 SA Life Time 28800 Perfect Forward Secrecy true Phase 2 DH group Group 2 Phase 2 Encryption DES Phase 2 Authentication MD5 Phas...

Page 91: ...USER MANUAL GWR I Cellular Router Series 91 Figure 75 IPSEC configuration page I for GWR I Router 1 Figure 76 IPSEC configuration page II for GWR I Router 1...

Page 92: ...de of IPSec tunnel which sends requests for establishing of the IPSec tunnel If connection mode Wait is selected that indicates side of IPSec tunnel which listens and responses to IPSec establishing r...

Page 93: ...sconnected please click Connect button Click VPN Settings IPSEC to configure IPSEC tunnel parameters Click Add New Tunnel button to create new IPSec tunnel Tunnel parameters are Add New Tunnel Tunnel...

Page 94: ...er Enable IKE failover false Enable Tunnel Failover false Advanced Compress Support IP Payload Compression Protocol IPComp false Dead Peer Detection DPD false NAT Traversal true Send Initial Contact t...

Page 95: ...e version used in this scenario also provides options for Connection mode of IPSec tunnel If connection mode Connect is selected that indicates side of IPSec tunnel which sends requests for establishi...

Page 96: ...s 96 Figure 83 IPSec start stop page for GWR I Router 1 Click Wait button and after that Start button on Internet Protocol Security page to initiate IPSEC tunnel On the device connected on GWR I route...

Page 97: ...to hostname with DynDNS service for synchronization with DynDNS server SIM card must have internet access GSM UMTS APN Type For GSM UMTS networks GWR I Router connections may require a Custom APN A C...

Page 98: ...Time 28800 Perfect Forward Secrecy true Phase 2 DH group Group 2 Phase 2 Encryption 3DES Phase 2 Authentication SHA1 Phase 2 SA Life Time 3600 Preshared Key 1234567890 Local Group Setup Local Security...

Page 99: ...MANUAL GWR I Cellular Router Series 99 Figure 86 IPSEC configuration page I for GWR I Router Figure 87 IPSec configuration page II for GWR I Router Figure 88 IPSec configuration page III for GWR I Ro...

Page 100: ...domain lookup Keyring that defines wildcard pre shared key crypto keyring remote pre shared key address 0 0 0 0 0 0 0 0 key 1234567890 ISAKMP policy crypto isakmp policy 10 encr 3des authentication p...

Page 101: ...ssh line vty 5 15 access class 23 in privilege level 15 login local transport input telnet ssh end Use this section to confirm that your configuration works properly Debug commands that run on the Cis...

Page 102: ...custom APN should also support mobile terminated data that may be required in most site to site VPNs The GWR I Router configuration Click Network Tab to open the LAN NETWORK screen Use this screen to...

Page 103: ...Security Gateway Type IP Only IP Address 150 160 170 1 Remote ID Type Custom Custom Peer ID 150 160 170 1 Remote Security Group Type IP IP Address 10 10 10 0 Subnet Mask 255 255 255 0 IPSec Setup Keyi...

Page 104: ...USER MANUAL GWR I Cellular Router Series 104 Figure 92 IPSEC configuration page I for GWR I Router Figure 93 IPSec configuration page II for GWR I Router...

Page 105: ...94 IPSec configuration page III for GWR I Router Click Start button on Internet Protocol Security page to initiate IPSEC tunnel Figure 95 IPSec start stop page for GWR I Router On the device connected...

Page 106: ...uration Step1 Create New Tunnel Interface Click Interfaces on Network Tab Figure 96 Network Interfaces list Bind New tunnel interface to Untrust interface outside int with public IP addresss Use unnum...

Page 107: ...Advanced tab Figure 98 AutoKey Advanced Gateway Click New button Enter gateway parameters Gateway name TestGWR Security level Custom Remote Gateway type Dynamic IP address because your GWR I router ar...

Page 108: ...Defined custom Phase 1 proposal pre g2 3des sha Mode Agressive must be aggressive because of NAT Nat Traversal enabled Click Return and OK Figure 100 Gateway advanced parameters Step 3 Create AutoKey...

Page 109: ...ateway Predefined Choose VPN Gateway from step 2 Figure 102 AutoKey IKE parameters Click Advanced button Security level User defined custom Phase 2 proposal pre g2 3des sha Bind to Tunnel interface tu...

Page 110: ...igure 103 AutoKey IKE advanced parameters Step 4 Routing Click Destination tab on Routing menu Click New button Routing parameters are IP Address 192 168 10 0 24 Gateway tunnel 3 tunnel interface from...

Page 111: ...trust to trust zone Source Address 192 168 10 0 24 Destination Address 10 10 10 0 24 Services Any Click OK Figure 105 Policies from untrust to trust zone Click Policies in main menu Click New button f...

Page 112: ...USER MANUAL GWR I Cellular Router Series 112 Figure 106 Policies from trust to untrust zone...

Page 113: ...ndow or to another location within the facility can result in optimum reception Another way of increasing throughput is by physically placing the device on the roof of the building in an environmental...

Reviews: