background image

LANCOM 1751 UMTS

110584_LC-1751-UMTS-MANUAL-EN.book  Page 1  Tuesday, February 26, 2008  5:16 PM

Summary of Contents for 1751 UMTS

Page 1: ...LANCOM 1751 UMTS 110584_LC 1751 UMTS MANUAL EN book Page 1 Tuesday February 26 2008 5 16 PM ...

Page 2: ...e time of printing Trademarks Windows Windows Vista Windows XP and Microsoft are registered trademarks of Microsoft Corp The LANCOM Systems logo LCOS and the name LANCOM are registered trademarks of LANCOM Systems GmbH All other names mentioned may be trademarks or registered trademarks of their respective owners This product includes software developed by the OpenSSL Project for use in the OpenSS...

Page 3: ...S Security settings To maximize the security available from your product we recommend that you undertake all of the security settings e g firewall encryption access protec tion that were not already activated when you purchased the product The LANconfig Wizard Security Settings will help you with this task Further infor mation is also available in the chapter Security settings We would additionall...

Page 4: ...encounter any errors or just want to issue critics enhancements please do not hesitate to send an email directly to info lancom eu Our online services www lancom eu are available to you around the clock should you have any queries regarding the topics discussed in this manual or require any further support The area Support will help you with many answers to frequently asked questions FAQs Furtherm...

Page 5: ... LANCOM Systems website Information symbols Very important instructions Failure to observe this may result in damage Important instruction that should be observed Additional information that may be helpful but which is not required 110584_LC 1751 UMTS MANUAL EN book Page 5 Tuesday February 26 2008 5 16 PM ...

Page 6: ...ice connectors 22 2 4 Hardware installation 24 2 5 Software installation 25 2 5 1 Starting the software setup 25 2 5 2 Which software should I install 26 3 Basic configuration 27 3 1 Which information is necessary 27 3 1 1 TCP IP settings 27 3 1 2 Configuration protection 29 3 2 Instructions for LANconfig 29 3 3 Instructions for WEBconfig 30 3 4 TCP IP settings to workstation PCs 35 3 5 Location v...

Page 7: ...zard 51 5 2 2 Configuration under WEBconfig 51 6 Connecting two networks 52 7 Providing dial in access 54 8 Setting up the UMTS profile 56 8 1 Internet access 56 8 2 VPN site coupling 59 8 3 Other settings 61 8 3 1 Choosing the mobile telephone network 61 8 3 2 Activate UMTS GPRS profile 62 8 3 3 UMTS HSxPA only or automatic UMTS HSxPA GPRS selection 63 8 3 4 Set up a time limit 64 9 Troubleshooti...

Page 8: ...2 Contact assignment 68 10 2 1 ADSL interface 68 10 2 2 ISDN S0 interface 69 10 2 3 Ethernet interface 10 100Base TX 69 10 2 4 Configuration interface Outband 70 10 3 70 10 4 Declaration of conformity 70 11 Index 71 110584_LC 1751 UMTS MANUAL EN book Page 8 Tuesday February 26 2008 5 16 PM ...

Page 9: ...ge from construction work for example Provider s network may be disturbed or even fail LANCOM UMTS Routers of the type LANCOM 1751 UMTS are equipped with a UMTS modem and an ISDN interface to offer two integrated options for establishing alternative connections The LCOS operating system provides a range of security and backup functions to protect your multi site network from disturbances of this t...

Page 10: ...ologies in overview GPRS General Packet Radio Service technology for packet orientated data transfer in GSM networks Achieves in practice data transfer speeds of up to 56 kbps EDGE Enhanced Data Rates for GSM Evolution is technology that increases data rates over GPRS by using an additional method of modulation EDGE acheives theoretical data rates of up to 384 kbps downstream and ca 110 kbps upstr...

Page 11: ...ed VPN connection to be backed up by a direct ISDN dial in connection in addition to the UMTS HSxPA backup Should the provider s network or the Internet connection to the headquarters fail then data transmission can be continued over the ISDN coupling 1 1 3 Backup with VRRP A sophisticated backup system for protection against router hardware failure can be implemented with VRRP Two or more routers...

Page 12: ...er carries out a check to make sure that it is installed at the intended location Only after confirming its location will the router start trans ferring payload data over its WAN interfaces Two methods of location verification are available Via an ISDN telephone call to itself the device can test whether it is con nected to the expected ISDN telephone line Prerequisites for successful ISDN locatio...

Page 13: ...g table shows the properties and functions of your device LANCOM 1751 UMTS Applications Internet Access LAN to LAN coupling via VPN LAN to LAN coupling via ISDN RAS server via VPN RAS server via ISDN IP router NetBIOS proxy for coupling of Microsoft peer to peer networks via ISDN DHCP and DNS server for LAN and WAN Advanced Routing and Forwarding ARF networks 8 N N mapping for coupling networks us...

Page 14: ...g per MLPPP and BACP as well as Stac data compression Hi fn LAN connection Separate FastEthernet LAN ports individually switchable e g as LAN switch or separate DMZ ports auto crossover Alternatively switchable as a WAN interface 4 Security functions IPSec encryption via external software VPN client 5 integrated VPN tunnels for secure network connections IPSec encryption in hardware optional activ...

Page 15: ...wizard for easiest setup of RAS access and site to site LAN cou pling via VPN Remote configuration via ISDN with ISDN PPP connections e g via Win dows Dial Up Networking Serial configuration interface Call back function with PPP authentication mechanisms allowing only prede fined ISDN call numbers FirmSafe for no risk firmware updates Optional software extensions LANCOM VPN Option with 25 active t...

Page 16: ...erating system that supports TCP IP e g Windows Vista Windows XP Millennium Edition Me Windows 2000 Windows 98 Linux BSD Unix Apple Mac OS OS 2 The LANtools also require a Windows operating system A web brow ser under any operating system provides access to WEBconfig LANCOM 1751 UMTS 12 V DC power adapter LAN cable green connectors ADSL connector cable transparent connectors ISDN connector cable l...

Page 17: ...ately 10x longer switched off Inverse flashing means the opposite The LED lights permanently in the respective colour and is only briefly interrupted Flickering means that the LED is switched on and off in irregular inter vals Front side The LANCOM UMTS Routers have status displays on the front panel Top The two top mounted LEDs enable the main function status to be assessed even if the device is ...

Page 18: ...OM are unprotected Normally you would set a configuration password during the basic configuration instruc tions in the following chapter Information about setting a configu ration password at a later time is available in the section The Security Wizard Off Device switched off Green Blinking Self test after power up Green On perma nently Device operational Red green Blinking alterna tely Device ins...

Page 19: ...ttings are defined in LANconfig under Management Costs these settings are only avai lable if the Complete configuration display is activated under Tools Options With WEBconfig resetting the toll protection and all parameters are found under Expert con figuration Setup Charges Power Power Signal that a charge or time limit has been reached Off No active connection Green Flashing Opening the first c...

Page 20: ...ng Opening the first connection Green Inverse flashing Opening an additional connection Green Permanently At least one logical connection is established Green Inverse flickering Data traffic send or receive Off Not connected or no S0 voltage no error message Green Blinking D channel initialization establishing contact to provider Green On perma nently D channel operational Red Flickering D channel...

Page 21: ...ing SIM card error Orange Blinking Flashing UMTS module found login to the UMTS network active Orange On permanently UMTS module ready login to the UMTS network com pleted Green On permanently GPRS connection available Green Blinking 1x per second EDGE connection available Green Blinking 4x per second with breaks UMTS connection available Green Blinking 8x per second with breaks HSxPA connection a...

Page 22: ...if GPS is used for location verification for a short while only As soon as the location is correctly identified the GSM UMTS diversity function is available again and the GPS module is switched off auto matically Connector for the supplied power adapter Switch with 10 100Base Tx connectors SIM card slot Serial configuration port RS 232 V 24 ISDN S0 connection Off No VPN tunnel established Green Bl...

Page 23: ...impossible to reset the configuration to the factory set tings If the password is lost for a device with this setting there is no way to access the configuration In this case the serial communicati ons interface can be used to upload a new firmware version to the device this resets the device to its factory settings which results in the deletion of the former configuration Instructions on firmware...

Page 24: ...s is not to be exceeded 0 25 W or 24 dBm EIRP The system operator is responsible for observing these threshold values LAN First of all you can connect the LANCOM UMTS Router to the LAN Plug in one end of the supplied network cable green connectors to a LAN connector on the device and the other end into an available network connector socket in your local network or on a hub or switch Alternatively ...

Page 25: ...rong power adapter can be of danger to the device or per sons Ready for operation After a brief self test the power LED lights up permanently in green or it blinks alternately in red and green until a con figuration password is set 2 5 Software installation The following section describes the installation of the Windows compatible system software LANtools as supplied You may skip this section if y...

Page 26: ...on via a web browser With LANmonitor you can use a Windows computer to monitor all of your LANCOM routers and LANCOM access points The LANCOM Advanced VPN Client enables VPN connections to be established over the Internet from a remote computer to a VPN router With Documentation you copy the documentation files onto your PC Select the appropriate software options and confirm your choice with Next ...

Page 27: ...ice 3 1 Which information is necessary The basic configuration wizard will take care of the basic TCP IP configuration of the device and protect the device with a configuration password The fol lowing descriptions of the information required by the wizard are grouped in these configuration sections TCP IP settings protection of the configuration security settings 3 1 1 TCP IP settings The TCP IP c...

Page 28: ...nual configuration instead Make your selection after the following consi derations Choose automatic configuration if you are not familiar with networks and IP addresses Select manual TCP IP configuration if you are familiar with networks and IP addresses and one of the following conditions is applicable You have not yet used IP addresses in your network but would like to do so now You would like t...

Page 29: ...g Start up LANconfig by clicking Start Programs LANCOM LANconfig LANconfig automatically detects the new LANCOM devices in the TCP IP network If an unconfigured device is being found during searching the setup wizard starts that will help you make the basic settings of the device or will even do all the work for you provided a suitable network environment exists If you cannot access an unconfigure...

Page 30: ...der is not listed here you must enter the transfer protocol used by your DSL provider manually Confirm your choice with Next Connect charge protection can limit the cost of DSL connections to a pre determined amount if desired Confirm your choice with Next Complete the configuration with Finish Section TCP IP settings to workstation PCs will describe the settings required for the individual workst...

Page 31: ... address of this PC with Start Execute cmd and command ipconfig at the prompt under Windows 2000 or Windows XP with Start Execute cmd and the command winipcfg at the prompt under Windows Me and Windows 9x or with the command ifconfig on the console under Linux In this case the LANCOM is reachable under the IP address x x x 254 x stands for the first three blocks in the IP address of the configurat...

Page 32: ...itable tools and contact the device directly with this IP address Use LANconfig Starting the wizards in WEBconfig Start your web browser e g Internet Explorer Firefox Opera and call the LANCOM there http IP address of the LANCOM or with a name as discribed above If you cannot access an unconfigured device the problem may be due to the netmask of the LAN with less than 254 possible hosts netmask 25...

Page 33: ...s than those shown here If you have chosen automatic TCP IP configuration please continue with Step If you would like to configure the TCP IP settings manually assign an avai lable address from a suitable address range to the LANCOM Also set whether or not it is to operate as a DHCP server Confirm your entry with Apply 110584_LC 1751 UMTS MANUAL EN book Page 33 Tuesday February 26 2008 5 16 PM ...

Page 34: ...our DSL provider from the list that is displayed Confirm your choice with Apply If you select My provider is not listed here you must enter the transfer protocol used by your DSL provider manually in the next window Confirm your choice with Apply Connect charge protection can limit the cost of DSL connections to a pre determined amount if desired Confirm your choice with Apply The basic setup wiza...

Page 35: ...as that of the default gateway and DNS server The PCs must therefore be configu red so that they automatically obtain their own IP address and the IP addresses of the standard gateway and DNS server via DHCP IP address assignment via a separate DHCP server The workstation PCs must be configured so that they automatically obtain their own IP address and the IP addresses of the standard gateway and ...

Page 36: ...odule is deactivated again unless it was switched on manually 3 5 2 ISDN location verification ISDN location verification can prevent the misuse of a router Each time it is switched on the router carries out a check by making an ISDN telephone call to itself to ensure that it is installed at the intended location Only after suc cessful location verification is the router module activated Prerequis...

Page 37: ...raphical coordinates For a location check by GPS an appropriate GPS antenna must be con nected to the AUX connector on the device Additionally a SIM card for mobile telephone operation has to be inserted and the device must be logged on to a mobile phone network For the location check enter Self call or Call forwarding check and enter the destination number as the telephone number to be used for t...

Page 38: ...S checkbox Once the configuration is written back to the device the current longitude and latitude are entered automatically assu ming that location verification is activated and a valid GPS position is available Subsequently this option is automatically deactivated again As an alternative you can determine the geographical coordinates from tools such as Google Maps 110584_LC 1751 UMTS MANUAL EN b...

Page 39: ...n in Google maps WEBconfig Telnet or terminal program Under WEBconfig Telnet or a terminal program you will find the settings for location verification under the following paths Configuration tool Menu Table WEBconfig Expert configuration Setup Config Location verification Terminal Telnet Setup Config Location verification 110584_LC 1751 UMTS MANUAL EN book Page 39 Tuesday February 26 2008 5 16 PM...

Page 40: ...of location verification can be viewed under LANmonitor With WEBconfig Expert configuration Status Config Location verification or Telnet Status Config Location verification you can view the status of the location verification 110584_LC 1751 UMTS MANUAL EN book Page 40 Tuesday February 26 2008 5 16 PM ...

Page 41: ...DN is successful when the number Expect call from agrees with the number Last call from This call is not picked up by the router The status also displays whether a call was accepted at all Location verification via GPS is successful when the GPS position is valid and within the tolerated range deviation from the known position 110584_LC 1751 UMTS MANUAL EN book Page 41 Tuesday February 26 2008 5 1...

Page 42: ...LAN if an employee with access to a key leaves your company The key should also be renewed in case of smallest suspicion of a leak LEPS prevents the global spread of passphrases Activate LEPS to enable the use of individual passphrases 4 2 The security settings wizard Access to the configuration of a device permits not only to read out critical information e g Internet password Rather also the ent...

Page 43: ...works In a next step parameters of the configuration lock like number of failed log in attempts and the duration of the lock can be adjusted Now activate Stateful Inspection ping blocking and Stealth mode in the the firewall configuration The wizard will inform you when entries are complete Complete the con figuration with Finish 4 2 2 Wizard for WEBconfig Under WEBconfig you have the possibility ...

Page 44: ...t off If you need to make use of remote configuration ensure that you do not fail to password protect the configuration see the section above The field for disenabling remote configuration is to be found in LANconfig in the Management configuration area on the Security tab Under Access rights From remote networks select the option denied for all methods of configuration Have your password protecte...

Page 45: ...ecially convenient to set up the filters with the aid of LANconfig Under Firewall QoS the Rules tab contains the functions for defining and editing filter rules Have you excluded certain stations from accessing the device A special filter list can be used to limit access to the device s internal func tions via TCP IP The phrase internal functions refers to configuration sessions via LANconfig WEBc...

Page 46: ... see the reference manual GPS location verification enables a geographical position to be defined within the device After being switched on the device checks if it is located at the correct position The router module is only activated after a posi tive check The scripting function can store the entire configuration in RAM only so that restarting the device will cause the configuration to be delete...

Page 47: ...the DSL interface an external ADSL modem first has to be connected to one of the device s ETH ports When set ting up the Internet access you define which ETH port the ADLS modem has been connected to Does the Setup Wizard know your Internet provider The Wizard is preset with access data for the principal Internet providers in your country and offers you a selection list If you find your Internet p...

Page 48: ...DN B channel can be activated and added to the connection The result is that bandwidth is doubled However under certain circumstances the connection fees may double as well Furthermore your ISDN connection would be engaged so preventing any other incoming or outgoing telephone calls from being made Data compression ISDN only This enables data transfer rates to be increased even further Creating a ...

Page 49: ...N interface to be used for the backup connection and enter the relevant access data for the Internet connection The Wizard then sets up the alternative Internet access and at the same time creates the necessary entries into the backup table and also in the PPP table for checking the Internet connection Please be aware that in the case of backup via UMTS some of the ser vices provided over the main...

Page 50: ... a stateful inspection firewall and firewall filter that provides effective protection from the Internet for your LAN The core concept of the stateful inspection firewall is that the only data transfers that are con sidered to be valid are those implemented by the protected device itself All access attepts that were not requested from within the local network are inva lid The Firewall Wizard assis...

Page 51: ...stination sta tions that the rule applies to and the actions that are to be carried out by the rule on a data packet Finally the new rule is given a name it is activated and you define whe ther further rules are to be considered when the rule acts on a data packet The wizard will inform you as soon as the entries are complete Close the configuration with Finish 5 2 2 Configuration under WEBconfig ...

Page 52: ... coupling of networks is now very simple with the help of the 1 Click VPN wizard It is even possible to simultaneously couple multiple routers to a cen tral network In LANconfig mark the routers at branch offices which are to be coupled to a central router via VPN Use drag drop by mouse to place the devices onto the entry for the cen tral router 110584_LC 1751 UMTS MANUAL EN book Page 52 Tuesday F...

Page 53: ...s ISDN number The final step is to define how the networks are to intercommunicate The INTRANET at headquarters only is to be provided to the branch offices All private networks at the branch offices can also be connected to one another via headquarters All entries for the central device are made just once and are then stored to the device properties The Wizard is not suitable for coupling network...

Page 54: ... randomly gene rated values e g for the preshared key Use LANconfig to start the Set up a RAS Account wizard and select the VPN connection Activate the options LANCOM Advanced VPN Client and Speed up con figuration with 1 Click VPN Enter a name for this access and select the address under which the router is accessible from the Internet In the final step you can select how the access data is to be...

Page 55: ...NS name or IP address VPN IP networks All IP networks defined in the device as type Intranet Preshared key Randomly generated key 16 ASCII characters long Connection medium The LAN is used to establish connections VoIP prioritization VoIP prioritization is activated as standard Exchange mode The exchange mode to be used is Aggressive Mode IKE config mode The IKE config mode is activated the IP add...

Page 56: ...tion window From the com mand line select Extras Setup Wizard In the selection menu select the Setup Wizard Set up Internet connec tion and confirm the selection with Next To set up the Internet access select the UMTS interface your network operator enter the APN Access Point Name and the PIN number for your SIM card The Wizard then carries out all other settings automatically 110584_LC 1751 UMTS ...

Page 57: ...automati cally re establishes after being cut off The Internet connection is always on This function is very useful for convenient access to the Internet or for VPN site coupling Depending on the tariff always on Internet connections can give rise to considerable costs for example with time based charging Please ensure that you are familiar with the details of your mobile provider s UMTS HSxPA tar...

Page 58: ...l strength of the home network with which the card is connected to the Internet The display of signal strength and trans fer mode depend on the type of card being used LANmonitor s signal strength display is highly useful for testing the recep tion quality at locations where the data card is to be put into service With a displayed signal strength of three bars green you can safely assume that the ...

Page 59: ... network coupling via UMTS HSxPA When dialing in some mobile telephone providers assign the UMTS card with an IP address from their own internal range of addresses This repre sents no problem for a normal Internet connection However this can lead to problems when establishing a VPN connection as the IP addresses of the VPN devices may be required for the negotiation of the encryption parameters Wi...

Page 60: ... dynamic VPN option to No dynamic VPN and then activate Aggressive Mode as the IKE exchange mode In LANconfig you then enter unique identities e g unambiguous e mail addresses for the relevant connection in the configuration area VPN tab IKE parameters in the list for IKE key The settings for the aggressive mode must agree for all of the identi ties at both ends of the connection The provider assi...

Page 61: ... directed towards the remote VPN gateway The interval times for the polling calls may have to be adjusted depending on the quality of the con nection Depending on the tariff always on Internet connections can give rise to considerable costs for example with time based charging Please ensure that you are familiar with the details of your mobile provider s UMTS HSxPA tariff 8 3 Other settings 8 3 1 ...

Page 62: ... the commands do Status External Interface Scan Networks or so Setup Interfaces UMTS GPRS parameters Scan Networks 8 3 2 Activate UMTS GPRS profile Operating the LANCOM devices with the UMTS HSxPA function at changing locations or with different UMTS HSxPA GPRS data cards may well require dif ferent sets of settings The relevant information for operating data cards is collected in a UMTS HSxPA GPR...

Page 63: ...n by selecting the automatic operating mode With this setting the data card in the LANCOM will initially attempt to establish a connection via UMTS HSxPA The card will automatically switch to the GPRS network if the UMTS signal proves to be too weak to support data transfer of the necessary quality If required the operating mode can be permanently set to either UMTS HSxPA or GPRS The desired opera...

Page 64: ...limit You can prevent excessive costs from arising from connections over the UMTS HSxPA interface by setting up a time limit for example under LANconfig in the Management configuration area on the Costs tab 110584_LC 1751 UMTS MANUAL EN book Page 64 Tuesday February 26 2008 5 16 PM ...

Page 65: ...merous DSL providers automati cally Only if your DSL provider is not listed you will have to enter manually the protocol being used In any case the protocol that your DSL provider sup plies you with should definitely work You can monitor and correct the protocol settings under 9 2 DSL data transfer is slow The data transfer rate of an broadband Internet DSL connection is dependent upon numerous fa...

Page 66: ...s the TCP IP receive window size of the Windows ope rating system that is set to a value too small for asynchronous connections Instructions on how to increase the Windows size can be found in the Know ledge Base of the support section of the LANCOM web site www lancom eu 9 3 Unwanted connections under Windows XP Windows XP computers attempt to compare their clocks with a timeserver on the Interne...

Page 67: ...nterface COM port Serial configuration interface COM port 8 pin Mini DIN 9 600 115 000 baud Power supply 12V DC via external power supply Permitted power supplies NEST 12V 1A DC S Hohlstkr 2 1 5 5mm RoHS LANCOM item no 110524 Type identification on the power supply Type 15 2230S Housing Dimensions 210 mm x 143 mm x 45 mm B x H x T robust plastic housing stackable prepared for wall mounting Conform...

Page 68: ...s 2000 Windows XP Windows Vista single license item no 61600 LANCOM Advanced VPN Client for Windows 2000 Windows XP Windows Vista single license item no 61601 LANCOM Advanced VPN Client for Windows 2000 Windows XP Windows Vista 25 licenses item no 61602 Options LANCOM VPN 25 Option 25 channels incl activated VPN hardware accelerator item no 60083 LANCOM 1751 UMTS Connector Pin IAE 1 2 3 a 4 b 5 6 ...

Page 69: ...ing to ISO 8877 EN 60603 7 10 2 3 Ethernet interface 10 100Base TX 8 pin RJ45 socket corresponding to ISO 8877 EN 60603 7 Connector Pin Line IAE 1 2 3 T 2a 4 R 1a 5 R 1b 6 T 2b 7 8 Connector Pin IAE 1 T 2 T 3 R 4 5 6 R 7 8 110584_LC 1751 UMTS MANUAL EN book Page 69 Tuesday February 26 2008 5 16 PM ...

Page 70: ...in this documentation are in agreement with the basic requirements and other relevant regulations of the 1995 5 EC directive The CE declarations of conformity for your device are available in the appro priate product area on the LANCOM Systems web site www lancom eu Connector Pin IAE 1 CTS 2 RTS 3 RxD 4 RI 5 TxD 6 DSR 7 DCD 8 DTR U GND 110584_LC 1751 UMTS MANUAL EN book Page 70 Tuesday February 26...

Page 71: ...5 DHCP 35 DHCP server 13 28 30 33 35 Dial in access 54 DNS DNS server 13 35 Documentation 16 Download 4 DSL provider 30 34 transfer protocol 34 DSL connection problems establishing the connection 65 DSL transfer protocol 30 E EDGE 10 F Firewall 14 45 Block stations 45 Firewall filters 50 FirmSafe 15 Firmware 4 Flatrate 48 G GPRS 10 GPS 12 22 24 36 H HSxPA 10 56 I ICMP 45 Information symbols 5 Inst...

Page 72: ...ower adapter 22 R Remote Access Service RAS Server 13 Setup 54 Remote configuration 30 34 Remote configuration via ISDN 15 Reset switch 23 Reset the toll protection 19 Routing table 45 S Security checklist 44 SNMP Configuration protection 44 Software installation 25 SSID 30 34 Stateful inspection firewall 50 Status display Power 17 19 Statusanzeigen 17 Wireless Link 22 Support 4 Switch 22 System r...

Page 73: ...EN work 61 Internet access 56 Mobile conference room 59 Time limit 64 V Virtual Private Network VPN 13 W WEBconfig 30 password 34 System requirements 16 110584_LC 1751 UMTS MANUAL EN book Page 73 Tuesday February 26 2008 5 16 PM ...

Reviews: