background image

40 

3.6.2 IPSec Tunnels 

From navigation tree, select VPN>>IPSec Tunnels, enter "IPSec Tunnels" and click <add>. 

Table 3-6-2 Parameters of IPSec Tunnels   

IPSec Tunnels 

Function description: Configure IPSec tunnels 

Parameters 

Description 

Default 

Show Advanced Options 

Click to enable advanced options 

Disable(open advanced 

options after enabling) 

Basic parameters 

Tunnel Name 

User defines tunnel name 

IPSec_tunnel_1 

Destination Address 

Set  destination  IP  address  or  domain 

name 

0. 0. 0. 0 

Startup Modes 

Select  Auto  Activated/Triggered  by 

Data/Passive/Manually Activated 

Auto Activated 

Restart WAN when failed 

Click to enable 

Enable 

Negotiation Mode 

Select  main  mode  or  aggressive 

mode 

Main Mode 

IPSec  Protocol  (Advanced 

Option) 

Select ESP/AH 

ESP 

IPSec 

Mode 

(Advanced 

Option) 

Select 

tunnel 

mode/transmission 

mode 

Tunnel Mode 

VPN  over  IPSec  (Advanced 

Option) 

Select  L2TP  over  IPSec/GRE  over 

IPSec/None 

None 

Tunnel Type 

Select 

Host-Host/Host-Subnet/Subnet-Host/

Subnet-Subnet 

Subnet-Subnet 

Local subnet address 

Set local subnet IP address 

192. 168. 2. 1 

Local Subnet Mask 

Set local subnet mask 

255. 255. 255. 0 

Peer Subnet Address 

Set peer subnet IP address 

0. 0. 0. 0 

Peer Subnet Mask 

Set remote netmask 

255. 255. 255. 0 

Phase I Parameters 

IKE Strategy 

Multiple strategies available   

3DES-MD5-DH2 

IKE Life Cycle 

Set IKE life cycle 

86400 s 

Local ID Type 

Select IP address/User FQDN/FQDN 

Fill in the ID according to the ID type 

(USERFQDN  is  standard  email 

format) 

IP Address 

Peer ID Type 

Select IP address/User FQDN/FQDN 

IP Address 

Authentication method 

Select shared key/digital certificate 

Shared key 

Key 

Set IPSec VPN key 

N/A 

XAUTH Parameters (Advanced Option) 

Summary of Contents for InRouter305

Page 1: ...InRouter305 Industrial Router User Manual Issue V1 0 August 2021...

Page 2: ...d interpretation 2020 InHand Networks All rights reserved Conventions Symbol Indication Content in angle brackets indicates a button name For example the OK button indicates a window name or menu name...

Page 3: ...t are to be installed in an enclosure suitable for the environment and where the internal compartment is only accessible by the use of tool 2 Suitable foruse in class 1 division 2 groups A B C and D h...

Page 4: ...2 2 1 SIM UIM Card 5 2 2 2 Antenna 5 2 2 3 Power Supply 5 2 3 LOGIN ROUTER 5 III WEB CONFIGURATION 7 3 1 SYSTEM 7 3 1 1 Basic Setup 7 3 1 2 System Time 7 3 1 3 Admin Access 8 3 1 4 System Log 10 3 1 5...

Page 5: ...2 DNS 23 3 3 3 DNS Relay 24 3 3 4 DDNS 25 3 3 5 Device Manager 26 3 3 6 SNMP 27 3 3 7 SNMP Trap 29 3 3 8 I O 30 3 3 9 SMS 30 3 3 10 Traffic Manager 31 3 3 11 Alarm Settings 31 3 3 12 User Experience...

Page 6: ...cate Management 47 3 7 TOOLS 48 3 7 1 PING 49 3 7 2 Traceroute 49 3 7 3 Link Speed Test 49 3 7 4 TCPDUMP 50 3 8 APPLICATION 50 3 8 1 Smart ATM 50 3 8 2 Status Report 51 3 8 3 Smart EMS 51 3 9 STATUS 5...

Page 7: ...3 9 11 Third Party Software Notices 55 APPENDIX A FAQ 56 APPENDIX B INSTRUCTION OF COMMAND LINE 58...

Page 8: ...pment networking and provides high speed data access for equipment networking This product is suitable for the networking of unattended devices and sites It is embedded with watchdog and multi layer l...

Page 9: ...YS Green off System error Blink in Green System upgrading Steady in Green System working Wi Fi Green off Wi Fi disable Blink in Green Wi Fi connecting Steady in Green Wi Fi working NET Green off Netwo...

Page 10: ...press the reset button immediately and keep it for 10 seconds until the SYS is steady on 2 Loosen the Reset button the SYS will off 3 Immediately press and hold the Reset button SYS will flash then lo...

Page 11: ...igher Hard disk 6 4G higher Serial port At least one Ethernet port At least one 10M 100M IE version 10 0 higher Resolution 640 480 higher 1 or 2 SIM card Ensure the card is enabled with data service a...

Page 12: ...to 9 36V DC power and see if the Power LED on the panel of the device is on If not please contact technical support of InHand Networks immediately 2 3 LOGIN ROUTER Upon installation of hardware be su...

Page 13: ...enter LAN Settings window interface Please confirm if the option Use a Proxy Server for LAN is checked if it is checked please cancel and click the button OK IV Log in Exit Web Settings Page Open IE o...

Page 14: ...description Select display language of the router configuration interface and set personalized name Parameters Description Default Language Configure language of WEB configuration interface Chinese H...

Page 15: ...pages on Internet After enabling HTTP service on device users can log on via HTTP and access and control the device using a web browser HTTPS HTTPS Secure Hypertext Transfer Protocol is the secure ver...

Page 16: ...t Service port of HTTP HTTPS TELNET SSHD HTTP_API 80 443 23 22 4444 Local Access Enable Allow local LAN to administrate the router with corresponding service e g HTTP Disable Local LAN cannot administ...

Page 17: ...te log software such as Kiwi Syslog Daemon a necessity on the host Kiwi Syslog Daemon is free log server software for Windows It can receive record and display logs from host such as gateway exchange...

Page 18: ...ve program For configuring drive program of module N A Network Provider ISP For configuring APN username password and other parameters of the network providers across the world N A Validity and order...

Page 19: ...click OK to begin upgrade thirdly upgrade firmware succeed and click Reboot to restart the device 3 1 8 Reboot Please save the configurations before reboot otherwise the configurations that are not s...

Page 20: ...mobile carriers subject to local carrier gprs China Mobile China Unicom CARD China Telecom Password Relevant dialing parameters provided be mobile carriers subject to local carrier gprs China Mobile...

Page 21: ...umber of Dial Number of redial after disconnect 5 CSQ Threshold Set CSQ threshold the router will switch to another SIM if signal is below threshold 0 0 disabled Min Connected Time Set min connected t...

Page 22: ...Description Default Shared connection NAT Enable Local device connected to Router can access to the Internet via Router Disable Local device connected to Router cannot access to the Internet via Route...

Page 23: ...unction description Set ADSL dialing parameters Parameters Description Default Shared connection Enable Local device connected to Router can access to the Internet via Router Disable Local device conn...

Page 24: ...comprises a group of logical devices and users These devices and users are not limited by physical locations but can be organized base on functions departments applications and other factors They comm...

Page 25: ...on of wireless user Parameters Description Default SSID broadcast After turning on use can search the WLAN via SSID name Enable Mode Six type for options 802 11g n 802 11g 802 11n 802 11b 802 11b g 80...

Page 26: ...o wireless LAN as client Parameters Description Default Mode Support many modes including 802 11b g n 802 11b g n SSID Name of the SSID to be connected inhand Authentication method Keep consistent wit...

Page 27: ...he default gateway for the virtual router VRRP will bring together a set of routers in LAN It consists of multiple routers and is similar to a virtual router in respect of function According to the VL...

Page 28: ...ID of router group range 1 255 1 Priority Select a priority range 1 254 20 the larger the numerical value the higher the priority Advertisement Interval Set an advertisement interval 60 s Virtual IP S...

Page 29: ...Table 3 2 10 Static Route Parameters Static Route Function description Add delete additional static rote of router Generally it s unnecessary for users to set it Parameters Description Default Destina...

Page 30: ...3 3 1 Parameters of DHCP Service DHCP Service Function description If the host connected with router chooses to obtain IP address automatically then such service must be activated Static designation...

Page 31: ...0 0 0 Secondary DNS Set Secondary DNS 0 0 0 0 3 3 3 DNS Relay The device as a DNS Agent relays DNS request and response message between DNS Client and DNS Server to carry out domain name resolution in...

Page 32: ...s have to remember is the domain name assigned by the dynamic domain name registrar regardless of how it is achieved DDNS serves as a client tool of DDNS and is required to coordinate with DDNS Server...

Page 33: ...e platform to manage devices The device can be managed and operated via software platform For instance the operating status of device can be checked device software can be upgraded device can be resta...

Page 34: ...and low efficiency The network administrator can use the Simple Network Management Protocol SNMP to remotely configure and manage the devices and perform real time monitoring on them Figure 3 3 6 SNMP...

Page 35: ...irements and can be managed only by authorized network administrators For example SNMPv3 can be used if data between the NMS and managed device is transmitted over a public network v1 Contact Informat...

Page 36: ...uthenticati on Password This parameter is available only when the authentication mode is not None The length is 8 to 32 characters None Encryption Select the encryption mode The values are None AES an...

Page 37: ...Falling edge 3 3 9 SMS SMS permits message based reboot and manual dialing Configure Permit to Phone Number and click Apply and Save After that you can send reboot command to restart the device or sen...

Page 38: ...blems as early as possible When an abnormality occurs the router reports an alarm You can select system defined abnormalities and choose an appropriate inform way to obtain the abnormality information...

Page 39: ...e Click to enable alarm notification of the console Disabled 3 3 12 User Experience Plan InHand Networks User Experience Program is designed to improve the product user experience and customer service...

Page 40: ...et is implemented according to present strategy To enable Access Control from the navigation tree select Firewall Filtering then enter Filtering page Table 3 4 2 Filtering Parameters Access Control of...

Page 41: ...can enable the host of extranet to access to specific port of host corresponding to IP address of intranet To configure port mapping go into the navigation tree select Firewall Port Mapping then enter...

Page 42: ...rnal source IP addresses N A Enable Click to enable virtual IP address Enable Virtual IP Set virtual IP address of virtual IP mapping N A Real IP Set real IP address of virtual IP mapping N A Log Clic...

Page 43: ...NAT is the network address translation function including source address translation SNAT and destination address translation DNAT Source NAT refers to the communication between the internal network a...

Page 44: ...s 3 5 1 IP BW Limit Bandwidth control sets a limit on the upload and download speeds when accessing external networks From the navigation tree select QoS Bandwidth Control then enter the IP BW Limit p...

Page 45: ...g remote users company branches partners to the network of the headquarters via VPN so as to realize secure transmission of data It is shown in the figure below Enterprise Headquarter Embranchment Coo...

Page 46: ...ts between host and gateway and between gateways The security protocols of AH and ESP can ensure security and IKE is used for cipher code exchange IPSec can establish bidirectional Security Alliance o...

Page 47: ...Select ESP AH ESP IPSec Mode Advanced Option Select tunnel mode transmission mode Tunnel Mode VPN over IPSec Advanced Option Select L2TP over IPSec GRE over IPSec None None Tunnel Type Select Host Hos...

Page 48: ...et ICMP Detection Interval 60 s ICMP Detection Timeout Set ICMP detection timeout 5 s ICMP Detection Retries Set ICMP detection max retries 10 The security level of three encryption algorithms ranks s...

Page 49: ...other two similar networks GRE application example combined with IPSec to protect multicast data GRE can encapsulate and transmit multicast data in GRE tunnel but IPSec currently could only carry out...

Page 50: ...he network of enterprise headquarters L2TP through dial up network PSTN ISDN based on negotiation of PPP and could establish a tunnel between enterprise branches and enterprise headquarters so that re...

Page 51: ...sword Set server s password N A Server Name Set server name l2tpserver Startup Modes Select Auto Activated Triggered by Data Passive Manually Activated L2TPOverIPSec Auto Activated Authentication Meth...

Page 52: ...ive Manually Activated Auto Activated Authentication method Select Auto CHAP PAP MS CHAPv1 MS CHAPv2 Auto Local IP Address Set local IP address N A Remote IP Address Set remote IP address N A Remote S...

Page 53: ...ion Parameters OpenVPN Function description Configure OpenVPN parameters Parameters Description Default Tunnel Name OpenVPN tunnel name cannot be changed by the system OpenVPN_T_ 1 Enable Click to ena...

Page 54: ...management Enable Tunnel Name Set tunnel name OpenVPN_T_ 1 Username CommonName Set username commonname N A Password Set client password N A Client IP 4th byte must be 4n 1 Set client IP address N A L...

Page 55: ...0 s Poll Timeout Set poll timeout 3600 s Import Export Certificate Import CA Certificate Manually import local CA to the router N A Export CA Certificate Manually export CA to local computer N A Impor...

Page 56: ...s available N A 3 7 2 Traceroute To perform traceroute select Tools Traceroute menu in the navigation tree then enter the Traceroute page Table 3 7 2 Traceroute Parameters Traceroute Function descript...

Page 57: ...Function description configure parameters for docking intelligent ATM cloud platform Parameters Description Default Smart ATM Enable Smart ATM disable Server Configure parameters of server Click Edit...

Page 58: ...val 60 second Protocol Monitor protocol type TCP Log Enable Enable log Close HTTP API Enable HTTP API OPEN Show router report args settiong Setting status upload message Disable Router hostname show r...

Page 59: ...nt Bootloader version router time PC time UP time CPU load and memory consumption Technicians may click the Sync Time button to synchronize the router with the system time of the host as covered in th...

Page 60: ...dergoes a serious error that causes a system reboot CRIT The device undergoes an unrecoverable error WARN The device undergoes an error that affects system functions NOTICE The device undergoes an err...

Page 61: ...active route table including destination netmask gateway metric and interface 3 9 9 Device List From navigation tree select Status Device List then enter Device List page to inquire the device list Th...

Page 62: ...3 9 11 Third Party Software Notices From navigation tree select Status Third Party Software Notices then enter Third Party Software Notices page to check the third party software used in router syste...

Page 63: ...ff press and hold the button again until the ERROR LED blinks 6 times the InRouter is now restored to factory default settings You may configure it now 4 After InRouter is powered on it frequently aut...

Page 64: ...address 11 InRouter is powered on but can t configure through the web interface Whether the IP Address of your computer is the same subnet with InRouter and the gateway address is InRouter LAN address...

Page 65: ...urrent available command enter help show Display all the parameters of show command and using instructions thereof 2 View Switchover Command 2 1 Enable Command Enable 15 password Function Switchover t...

Page 66: ...ser View All views Parameter No Example Enter in configured view exit Return to super user view enter exit in ordinary user view exit Exit console 3 Check system state command 3 1 Show version Command...

Page 67: ...00 0 00 0 00 3 3 show clock Command Show clock Function Display the system time of router View All views Parameter No Example Enter show clock Display the following information For example Sat Jan 1 0...

Page 68: ...3 6 Show users Command Show users Function Display the user list of router View All views Parameter No Example Enter show users Displayed user list of system is as follows User adm Wherein user marked...

Page 69: ...ll ports 4 2 Show ip Command Show ip Function Display the information of port state of router View All views Parameter No Example Enter Show ip Display system ip status 4 3 Show route Command Show rou...

Page 70: ...elnet hostname port source ip Function Telnet logs in the appointed mainframe View All views Parameter hostname in need of the address or domain name of mainframe logged in port telnet port source ip...

Page 71: ...inal Switchover to configuration view 6 2 Hostname Command Hostname hostname default hostname Function Display or set the mainframe name of router View Configure view Parameter hostname new mainframe...

Page 72: ...or domain name of mainframe of time server Example Enter in configured view ntp server pool ntp org Set the address of Internet time server pool ntp org Enter in configured view no ntp server Disable...

Page 73: ...e of super user View Configure view Parameter name new super user username Example Enter in configured view enable username admin The username of super user is changed to admin 7 3 Enable password Com...

Page 74: ...igured view username abc password 123 Add an ordinary user the name is abc and the password is 123 Enter in configured view no username abc Delete the ordinary user with the name of abc Enter in confi...

Page 75: ...use harmful interference to radio or television reception which can be determined by turning the equipment off and on the user is encouraged to try to correct the interference by one or more of the fo...

Page 76: ...rie Canada applicables aux appareils radio exem pts de licence L exploitation est autoris e aux deux conditions suivantes 1 I appareil ne doit pas produire de brouillage et 2 I utillsateur de I appare...

Reviews: