background image

15: Security Settings

PremierWave® XC HSPA+ Intelligent Gateway User Guide

103

Table 15-3  SSH Server Authorized Users

SSH Client Users

The SSH Client Users are used by all applications that play the role of an SSH Client. Specifically 
Tunneling in Connect Mode. To configure the PremierWave XC HSPA+ intelligent gateway as an 
SSH client, an SSH client user must be both configured and also exist on the remote SSH server.

At the very least, a Password or Key Pair must be configured for a user. The keys for public key 
authentication can be created elsewhere and uploaded to the device or automatically generated 
on the device.

If uploading existing Keys, take care to ensure the Private Key will not be compromised in transit. 
This implies the data is uploaded over some kind of secure private network.

The default Remote Command is '<Default login shell>' which tells the SSH Server to execute a 
remote shell upon connection. This can be changed to anything the SSH Server on the remote 
host can execute.

Note:

If you are providing a key by uploading a file, make sure that the key is not 

password protected.

Table 15-4  SSH Client Users

SSH Settings

Description

Username

Enter a new username or edit an existing one.

Password

Enter a new password or edit an existing one.

Public RSA Key

Click 

Choose File 

to browse to and select the existing public RSA key you want to 

use with this user.  In Web Manager, you can also browse to the public RSA key to be 
uploaded. If authentication is successful with the key, no password is required.

Public DSA Key

Click

 Choose File 

to browse to and select the existing public DSA key you want to 

use with this user.  In Web Manager, you can also browse to the public DSA key to be 
uploaded.If authentication is successful with the key, no password is required.

Add/Edit (key)

Click the 

Add/Edit

 button after setting the information for 

SSH Client: Authorized 

Users

.

SSH Settings

Description

Username

Enter the name that the device uses to connect to an SSH server.

Password

Enter the password associated with the username.

Remote Command

Enter the command that can be executed remotely.  Default is shell, which tells the 
SSH server to execute a remote shell upon connection.  This command can be 
changed to anything the remote host can perform.

Private Key

Click 

Choose File 

to browse to and select the existing private key you want to 

upload.  In Web Manager, you can also browse to the private key to be uploaded.  Be 
sure the private key will not be compromised in transit. This implies the data is 
uploaded over some kind of secure private network.

Public Key

Click 

Choose File 

to browse to and select the existing public key you want to upload.  

In Web Manager, you can also browse to the public key to be uploaded.

Key Type

Select a bit length for the key:

RSA

DSA

Summary of Contents for PREMIERWAVE XC HSPA+

Page 1: ...Part Number 900 678 Revision D February 2017 PremierWave XC HSPA Intelligent Gateway User Guide ...

Page 2: ... web site at www lantronix com support warranty Contacts Lantronix Inc 7535 Irvine Center Drive Suite 100 Irvine CA 92618 USA Toll Free 800 526 8766 Phone 949 453 3990 Fax 949 453 3995 Technical Support Online www lantronix com support Sales Offices For a current list of our domestic and international sales offices go to the Lantronix web site at www lantronix com about contact Disclaimer All info...

Page 3: ...ed Flash and SNMP information Removed Query Port content May 2013 A Initial document for firmware release 7 7 0 0R27 April 2014 B Updated document to firmware release 7 8 0 0 August 2014 C Updated document to firmware release 7 9 0 0 February 2017 D Updated document to firmware release 8 0 0 0 Changes include adding IPv6 TCP Keep Alive IKEv2 log verbosity cellular modem IO and cellular network tra...

Page 4: ... Troubleshooting Capabilities _________________________________________________19 Configuration Methods _____________________________________________________19 Addresses and Port Numbers ________________________________________________19 Hardware Address _____________________________________________________19 IP Address ___________________________________________________________20 Port Numbers ___...

Page 5: ...gure Network 2 Link Settings ______________________________________45 Network 2 Cellular wwan0 QoS ____________________________________________46 To Configure Network 2 QoS Settings ______________________________________47 Gateway ________________________________________________________________47 Status _______________________________________________________________47 WAN _________________________...

Page 6: ...onfigure Application Settings _________________________________________66 10 Line and Tunnel Settings 67 Line Statistics ____________________________________________________________67 Line Settings _____________________________________________________________67 To Configure Line Settings _______________________________________________67 To Configure Line Command Mode ______________________________...

Page 7: ...____________________________88 To Configure HTTP Authentication _________________________________________89 RSS Settings _____________________________________________________________89 To Configure RSS Settings ______________________________________________90 SNMP Settings ___________________________________________________________90 To Configure SNMP Settings _____________________________________...

Page 8: ...__106 Certificate and Key Generation __________________________________________106 To Configure an Existing SSL Credential ___________________________________107 Trusted Authorities ____________________________________________________108 16 Maintenance and Diagnostics Settings 109 Filesystem Settings _______________________________________________________109 Statistics ____________________________...

Page 9: ...ettings _________________________________________________________119 To Reboot or Restore Factory Defaults ____________________________________119 17 Management Interface Settings 120 Command Line Interface Settings ____________________________________________120 Basic CLI Settings ____________________________________________________120 To View and Configure Basic CLI Settings ____________________...

Page 10: ...__129 LED Indicators ___________________________________________________________129 Routing Gateway _________________________________________________________129 Protocol Support _________________________________________________________130 Event Triggers and Actions _________________________________________________130 Security ________________________________________________________________130 Mana...

Page 11: ...figuration for Half Duplex RS 422 485 2 wire ___25 Figure 3 11 PremierWave XC HSPA Bottom Back Panel View ____________________________26 Figure 3 13 SIM Card Insertion______________________________________________________27 Figure 3 14 PremierWave XC HSPA Unit Dimensions in Inches in ________________________28 Figure 5 1 Device Status Page ______________________________________________________33 F...

Page 12: ..._____46 Table 6 10 WAN Configuration _____________________________________________________47 Table 6 11 Adding a New MAC Address Filters _________________________________________48 Table 6 12 Port Forwarding Rules List ________________________________________________49 Table 6 13 Adding a New Port Forwarding Rule ________________________________________49 Table 6 14 Static Route Setting Routes ___...

Page 13: ..._________________________________91 Table 12 9 SMTP Settings _________________________________________________________92 Table 12 10 Email Configuration ____________________________________________________92 Table 13 1 Inbound SMS Settings ___________________________________________________94 Table 13 2 Adding a New SMS Settings ______________________________________________94 Table 13 3 Outbound ...

Page 14: ..._________________________________119 Table 17 1 CLI Configuration Settings _______________________________________________120 Table 17 2 Telnet Settings _______________________________________________________121 Table 17 3 SSH Settings _________________________________________________________121 Table 17 4 XML Exporting Configuration _____________________________________________122 Table 17 5 Expo...

Page 15: ...ut Output Ports Instructions for configuring relay output and digital input settings 9 Action Settings Instructions for configuring alarm settings 10 Line and Tunnel Settings Instructions for configuring line and tunnel settings 11 Terminal and Host Settings Instructions for configuring terminal and host settings 12 Network Services Instructions for configuring DNS FTP HTTP and Syslog settings 13 ...

Page 16: ... information about the commands Also provides details for XML configuration and status PremierWave XC HSPA Intelligent Gateway Quick Start Instructions for getting the PremierWave XC HSPA device up and running DeviceInstaller Utility Online Help Instructions for using the Windows operating system based utility to locate the intelligent gateway and to view its current settings Com Port Redirector Q...

Page 17: ... Failback Support Support mission critical applications with a secondary path to the internet via cellular WAN Device Server Application Suite Control and monitor serial port based devices over the IP network Supporting multiple virtual serial connections Multiple connection modes and configuration options to enable transparent tunneling of hundreds of serial protocols Event Triggers and Actions M...

Page 18: ...c v3 UDP IP TCP IP SSH SSL TLS RSS UPnP ICMP BOOTP DHCP Auto IP Telnet SNTP FTP FTPS DNS TFTP XML and Syslog for network communications and management FTP and HTTP HTTPS web server for firmware upgrades and uploading downloading files TCP IP UDP IP Telnet SSH SSL TCP AES and UDP AES for command response based data acquisition application or alarm triggered connection HTTP HTTPS web based monitorin...

Page 19: ...he IP address and related settings and view current settings on the PremierWave XC HSPA intelligent gateway using a Graphical User Interface GUI on a PC attached to a network You will need the latest version of the Lantronix DeviceInstaller utility See Accessing the PremierWave XC HSPA Device Using DeviceInstaller on page 30 Command Mode There are a few methods for accessing Command Mode CLI makin...

Page 20: ...8 LDP Lantronix Discovery Protocol port TCP UDP Port 10001 Tunnel 1 see note below UDP Port 1900 and TCP Port 30179 UPnP Note Additional TCP UDP ports and tunnels will be available depending on the product type The default numbering of each additional TCP UDP port and corresponding tunnel will increase sequentially i e TCP UDP Port 1000X Tunnel X Product Information Label The product information l...

Page 21: ...tes and rubber feet PremierWave XC HSPA Quick Start Guide User Supplied Items To complete your installation you need the following items RS 232 422 485 serial devices that require network connectivity Devices and sensors that require network connectivity A serial cable as listed below for each serial device One end of the cable must have a female DB9 connector for the serial port A null modem cabl...

Page 22: ...s solid when there is a connection to the packet domain on the cellular network e g a data or GPRS UMTS HSPA connection AMBER displays solid when there is a connection to the cellular network e g a GSM connection OFF indicates WWAN cellular interface is inactive or disabled Serial 1 GREEN flashes when Serial port 2 is transmitting data AMBER flashes when Serial port 2 is receiving data OFF when no...

Page 23: ...rt 2 seconds off pattern repeats No IP obtained from Ethernet network when eth0 interface is enabled Long long short short short 2 seconds off pattern repeats No link no SIM detected Long pattern repeats No cellular link when wwan0 Cellular Network is enabled Long long long long short 2 seconds off pattern repeats No IP obtained from cellular networkwhen wwan0 Cellular Network is enabled and bridg...

Page 24: ...DB9 serial ports that support RS 232 422 485 Figure 3 5 shows the front view of the device The default serial port settings are 9600 baud 8 bits no parity 1 stop bit no flow control Figure 3 5 PremierWave XC HSPA Male DB9 DTE Serial Ports Figure 3 6 PremierWave XC HSPA Pinout Configuration for RS 232 Serial Serial Reset USB 1 2 Button Port ...

Page 25: ...rnet LED The Ethernet port can connect to an Ethernet 10 Mbps or Fast Ethernet 100 Mbps network Reset Button You can reset the PremierWave XC HSPA intelligent gateway to factory defaults including clearing the network settings The IP address gateway and netmask are set to 00s To reset the unit to factory defaults perform the following steps 1 Place the end of a paper clip or similar object into th...

Page 26: ...es with brackets for mounting it for example on a wall If using AC power do not use outlets controlled by a wall switch Observe the following guidelines when connecting the devices The PremierWave unit serial ports support RS 232 422 485 Use a null modem cable to connect the serial port to another DTE device Use a straight though modem cable to connect the serial port to a DCE device Connect your ...

Page 27: ...ower unplugged insert your SIM card 2 Connect an RJ 45 Ethernet cable between the unit and your Ethernet network 3 Connect the antennas to the SMA connectors on the back Do note that the safe distance due to RF exposure from antenna is 2 cm Note Antennas must be installed prior to powering on the unit Do not remove or connect the antennas while the unit power is on 4 Plug the PremierWave XC device...

Page 28: ...3 Installation of the PremierWave XC HSPA Device PremierWave XC HSPA Intelligent Gateway User Guide 28 Figure 3 14 PremierWave XC HSPA Unit Dimensions in Inches in ...

Page 29: ... below it becomes a plug and play mechanism to reach the device s Web UI Web Manager and complete the rest of the configuration Note There is no new software to install as UPnP support is built into Windows operating systems however it must be enabled on the Windows PC Please see notes on enabling UPnP Network Discovery on Windows XP and Windows 7 operating systems To search devices on Windows XP ...

Page 30: ...utable to start the installation process and respond to the installation wizard prompts If prompted to select an installation type select Typical 2 Click Start All Programs Lantronix DeviceInstaller 4 4 DeviceInstaller 3 When DeviceInstaller starts it will perform a network device search To perform another search click Search 4 Expand the PremierWave folder by clicking the symbol next to the folde...

Page 31: ...s Obtained Appears Dynamically if the PremierWave device automatically received an IP address e g from DHCP Appears Statically if the IP address was configured manually If the IP address was assigned dynamically the following fields appear Obtain via DHCP with values of True or False Obtain via BOOTP with values of True or False Subnet Mask Shows the subnet mask specifying the network segment on w...

Page 32: ...ess the Web Manager by selecting the Web Configuration tab on the DeviceInstaller application window To access Web Manager perform the following steps 1 Open a standard web browser Lantronix supports the latest versions of Internet Explorer Mozilla Firefox Safari or Chrome web browsers 2 Enter the IP address or hostname of the PremierWave XC HSPA unit in the address bar The IP address may have bee...

Page 33: ...ave XC HSPA Intelligent Gateway User Guide 33 Device Status Page The Device Status page is the first to appear after you log into Web Manager The Device Status page also appears when you click Status in Web Manager Figure 5 1 Device Status Page ...

Page 34: ...e Web Manager Page Web Manager pages have these sections The menu bar always appears at the left side of the page regardless of the page shown The menu bar lists the names of the pages available in the Web Manager To bring up a page click it in the menu bar Menu Bar Links to subpages Items to configure Header Information and Help Area Configuration and or Status Area Footer Logout button ...

Page 35: ...ick interface A menu bar on the left side of each page provides links you can click to navigate from one page to another Some pages are read only while others let you change configuration settings Note There may be times when you must reboot the PremierWave XC HSPA device for the new configuration settings to take effect The chapters that follow indicate when a change requires a reboot Anytime you...

Page 36: ...s you configure the network interface 38 Protocol Stack Lets you perform lower level network stack specific activities 111 Query Port Lets you change configuration settings for the query port 114 Relay Allows you to view and configure relay output shows current relay output statuses and allows you to modify display of both relays 80 RSS Lets you change current Really Simple Syndication RSS setting...

Page 37: ...Using Web Manager PremierWave XC HSPA Intelligent Gateway User Guide 37 XML Lets you export XML configuration and status records and import XML configuration records 122 Web Manager Page continued Description See Page ...

Page 38: ...nd strings of this chapter are to be replaced with a user specified name Network 1 Status In the Network 1 status pages you can view both the current interface operational settings as well as the settings that would take effect upon a device reboot as well as Link QoS and Failover status information To view Ethernet eth0 Interface status click Network on the menu and select Network 1 Interface Sta...

Page 39: ...55 0 0 Default Gateway Enter the IPv4 address of the router for this network Note This setting will be used if Static IP is active both DHCP and BOOTP are Disabled Hostname Enter the hostname for the interface It must begin with a letter or number continue with a sequence of letters numbers or hyphens and end with a letter or number This setting will take effect immediately but will not register t...

Page 40: ...tic IPv6 is active DHCPv6 is Disabled Changing this value requires a reboot When DHCPv6 is enabled the XPort Pro Lx6 tries to obtain an IPv6 address from a DHCPv6 server If it cannot then XPort Pro Lx6 generates and uses a Link local IPv6 address IPv6 Default Gateway Enter the default IPv6 Default Gateway IPv6 Domain Enter the IPv6 domain name suffix for the interface Note This setting will be use...

Page 41: ...vice can be enabled and configured for both Network 1 eth0 and Network 2 wwan0 If enabled the router will control the flow of outbound traffic according to the user defined filters In other words QoS improves performance by allowing the user to prioritize applications Filters can be defined to prioritize traffic based on the source or destination network source or destination port or the source MA...

Page 42: ...r disable state Import filters Click to enable or disable import filters to import configurations from other interfaces Uplink Speed Enter the maximum uplink speed Set 0 to set speed to default Delete Click the checkbox to the left of any existing QoS filter to be deleted and click the Submit button Filter type Select the filter type from the drop down window Network Port Network Enter the Network...

Page 43: ...ng Web Manager To modify Failover settings click Network on the menu and select Network 1 Failover Configuration Using the CLI To enter the eth0 link command level enable config if 1 failover Using XML Include in your file configgroup name network failover instance eth0 Network 1 Failover Settings Description State Click to enable or disable state Failover Interface Always select wwan0 in the Prem...

Page 44: ...sable the interface Priority It ranges from 0 10 Note Lower priority number means higher preference Connection Mode The Always On connection mode keeps the device always connected to the cellular network The On Demand connection mode leaves the link quiescent until an application attempts to make use of the cellular network connection Be aware that in this mode the first attempt to initiate a conn...

Page 45: ...Link Settings To Configure Network 2 Link Settings Using Web Manager To modify network 2 wwan0 interface information click Network on the menu and select Network 2 Link Configuration Using the CLI To enter the link command level enable if 2 link Using XML Include in your file configgroup name wwan0 link instance wlan0 Network 2 Link Settings Description APN Enter the configurable network identifie...

Page 46: ...Excellent Effort Bandwidth allocation is minimum 10 Best Effort Bandwidth allocation is minimum 10 Background Bandwidth allocation is minimum 5 and has the lowest priority Table 6 8 shows the network QoS settings that can be configured including adding new filters Table 6 8 Network 2 wwan0 QoS Settings Table 6 9 Adding or Deleting Network 2 wwan0 QoS Settings Network 2 QoS Settings Description Sta...

Page 47: ...0 WAN Configuration Gateway Settings Description Operating Mode Select the type of operating mode Disabled prevents the device to be used as a gateway use the device normally Gateway allows the device to be used as a router with NAT Router allows the device to be used as a router without NAT Firewall Select to enable or disable firewall Enabled enables the device firewall Disabled disable the devi...

Page 48: ...ble from outside of the cellular providers network The port forwarding rules will not work if the device does not receive any traffic Hosts within the cellular providers network cannot reach the device The port is blocked by the cellular provider If traffic to certain ports is blocked before it reaches the PremierWave device the port forwarding rules will still not work even with a public and acce...

Page 49: ...e device routing table Table 6 14 Static Route Setting Routes Port Forwarding Rule Description Enabled Enables the port forwarding rule Delete Deletes the port forwarding rule Name User friendly name for the rule Click on the Edit icon to make changes Ingress IP Address Port Range Port or Port range for the rule Protocol Protocols for the rule TCP UDP or Both IP Address Target Port Target for the ...

Page 50: ...r the Network or Host for the route Gateway Enter the Gateway for the route Interface Select the Interface for the route Metric Enter the priority for the route Lower metric means higher priority Add Click Add after adding new route information DHCP Settings Description Lease time Enter the duration for which lease is initially assigned Clients must renew after this duration State Enable or Disabl...

Page 51: ...tion that enables the selection of routes between any two nodes on a computer network Routing algorithms determine the specific choice of route Each router has a prior knowledge of networks directly attached to it A routing protocol shares this information among immediate neighbors first then through the network This way routers gain knowledge of the topology of the network The PremierWave device ...

Page 52: ...Interval Indicate the number of seconds for the Update Interval Send unsolicited Response message every Update Interval seconds containing the complete routing table to all neighboring RIP routers Timeout Interval Indicate the number of seconds for the Timeout Interval Upon expiration of the Timeout Interval the routes are no longer valid however they are retained in the routing table for a short ...

Page 53: ...dress is to be mapped LAN IP Address An existing LAN IP address to which the virtual IP address is to be mapped Virtual IP Settings Description Name Enter a name of the virtual IP address IP Address Enter the virtual IP address to which the LAN IP address is to be mapped LAN IP Address Enter the LAN IP address to which the virtual IP address is to be mapped Add Click Add after adding new virtual I...

Page 54: ...le or disable the VPN connection Connection Type Select connection type Host to Subnet VPN tunnel for local and remote subnets are fixed Host to Host VPN tunnel for remote subnet area is dynamic and local subnet is fixed IKEv2 Select the IKE version 2 setting to be used from the drop down menu Permit no IKEv2 should be transmitted but will be accepted if the other end initates to us with IKEv2 Thi...

Page 55: ...rd Secrecy PFS Select to enable or disable whether Perfect Forward Secrecy of keys is desired on the connection s keying channel Enabling this feature will require IKE to generate a new set of keys in Phase 2 rather than using the same key generated in Phase 1 Pre shared key PSK Enter the pre shared key to be used in the IPSec setting between the Local and VPN Gateway ISAKMP PHASE 1 IKE Aggressive...

Page 56: ...on the remote network Ping Interval Indicate the ping interval in minutes to use failover host and ping interval to monitor connectivity with a host on the remote network Max Tries Enter the tries for the VPN tunnel is restarted if Max Tries pings to the host fail GRE Settings Description Name Enter the user defined name of the GRE tunnel State Select to enable and disable GRE tunnel IP Address As...

Page 57: ...igent Gateway User Guide 57 To Configure Tunnel Serial Settings Using Web Manager To configure the GRE for a specific tunnel click GRE Using the CLI To enter GRE command level enable gre Using XML Include in your file configgroup name gre ...

Page 58: ...mes the SIM card will be permanently locked and no longer operable Allowed Bands Select the allowed bands determining the frequency band usage of the device Select Unselect individual bands to restrict the allowed bands to a specific band or band combination Antenna Diversity Select to enable or disable Antenna Diversity controls the RX receiver antenna diversity support to achieve verification of...

Page 59: ... errcodes The following is a list of common errors that may appear in the Cellular module PH SIM PIN required PH FSIM PIN required PH FSIM PUK required SIM not inserted SIM PIN required SIM PUK required SIM failure SIM busy SIM wrong incorrect password SIM PIN2 required SIM PUK2 required ...

Page 60: ...ommand level enable config relays relay number Using XML Include in your file configgroup name relay instance number Relay Output Settings Description State This field is found in the Relay Status page Indicates state of the relay Select On or Off to change the state of the relay Title Enter the relay title as it will appear in web manager XML and CLI Leave this field blank to utilize the default ...

Page 61: ...nd level enable config digital inputs digital input number Using XML Include in your file configgroup name action instance digital input 1 state change Include in your file configgroup name action instance digital input 2 state change Include in your file configgroup name digital input instance number Digital Input Settings Description State This field is found in the Digital Input Status page Ind...

Page 62: ...n scheduled reboot alarm Email Alarm Reminder Interval Normal Email Normal Message Normal Reminder Interval SNMP Reminder Interval SNMP Normal Message and Delay Actions Table 9 1 contains the configuration options for all the alarms and reports listed above Table 9 1 Action Settings Action Settings Description Delay Use Delay to defer alarm processing Alarm actions will not be executed if the caus...

Page 63: ...t number is the port which HTTP server is listening on Use Protocol to connect to HTTP server HTTPS is a SSL encrypted communication channel and SSL Trusted Authorities must be setup withHTTP server SSL certificate Username used to logon to HTTP server if authentication is required Password used to logon to HTTP server if authentication is required If the alarm stays on or off longer than the Remi...

Page 64: ...e device temperature change Include in your file configgroup name cellular temperature change Include in your file configgroup name action instance on scheduled reboot Python Python is a dynamic object oriented programming language that can be used for developing a wide range of software applications The Lantronix PremierWave HSPA includes the installation of Python interpreter making it easy to l...

Page 65: ...ython shared libraries Script Settings Description Enabled checkbox Check the Enabled checkbox within a particular script to enable it Uncheck the checkbox to disable the script Run on startup checkbox Check the Run on startup checkbox within a particular script to have it run upon the start up of the PremierWave unit Uncheck the checkbox to disable automatically running the unit upon startup Run ...

Page 66: ...pplication scripts click Applications on the menu Using the CLI To enter the application script change command level enable config applications Using XML Include in your file configgroup name applications Filename Enter the package file name pathway in the file system and click the Install button to install it Script Settings Description ...

Page 67: ...ine Statistics This page displays the current status and various statistics for the serial line Note The following section describes the steps to view Line 1 statistics these steps apply to other line instances of the device Using Web Manager To view statistics for Line 1 click Line in the menu and select Line 1 Statistics Using the CLI To view Line statistics enable line 1 show statistics Using X...

Page 68: ...and 921600 may be selected 300 600 1200 2400 4800 9600 19200 38400 57600 115200 230400 460800 921600 When selecting a Custom baud rate you may manually enter any value between 300 and 5000000 Note The maximum baud rate in RS232 mode is 1000000 bps Custom baud rates are not supported when a line is configured for Command Mode Parity Set the Parity of the Line The default is None Data Bits Set the n...

Page 69: ...baud rates are not supported in Command Mode Wait Time Enter the amount of time to wait during boot time for the Serial String This timer starts right after the Signon Message has been sent on the Serial Line and applies only if mode is Use Serial String Note This field becomes available when Use Serial String is selected for Mode Serial String Enter the Text or Binary string of bytes that must be...

Page 70: ...evices that establish the network connection between them Tunneling parameters are configured using the Tunnel menu and submenus The Tunnel settings allow you to configure how the Serial Network tunneling operates Tunneling is available on all serial lines The connections on one serial line are separate from those on another serial port Note The following section describes the steps to view and co...

Page 71: ... the DTR is asserted whenever either a connect or an accept mode tunnel connection is active with the Telnet Protocol RFC2217 saying that the remote DSR is asserted Asserted while connected the DTR is asserted whenever either a connect or an accept mode tunnel connection is active Continuously asserted Tunnel Packing Mode Settings Description Mode Configure the Tunnel Packing Mode Choices are Disa...

Page 72: ... matching value For instance the default local port is 10001 for serial line 1 and the default local port for serial line 2 is 10002 and so on for the number of serial lines supported Serial data can still be received while waiting for a network connection keeping in mind serial data buffer limitations Send Character Enter Control Characters in any of the following forms control J 0xA hexadecimal ...

Page 73: ...ogresses sequentially in equal value so that Tunnel X 1000X For example Tunnel 1 10001 Tunnel 2 10002 Protocol Select the protocol type for use with Accept Mode SSH SSL TCP default protocol TCP AES Telnet Credentials Specifies the name of the set of RSA and or DSA certificates and keys to be used for an SSL connection AES Encrypt Key Specify the text or hexadecimal advanced encryption standard AES...

Page 74: ...igured Disabled this is the default setting incoming characters from the Serial Line are sent on into the network Any buffered characters are sent first Block Network Set whether Block Network is enabled for debugging purposes Choices are Enabled if Enabled incoming characters from the network will not be processed Instead they will be buffered and will eventually flow off the network side Disable...

Page 75: ...or Connect Mode using UDP the PremierWave module accepts packets from any device on the network It will send packets to the last device that sent it packets Note The port in Connect Mode is not the same port configured in Accept Mode The TCP keepalive time is the time in which probes are periodically sent to the other end of the connection This ensures the other side is still connected Table 10 6 ...

Page 76: ...P segments will be retransmitted before the connection is closed Initial Send enter the Initial Send string for data sent out of the network upon connection establishment before any data from the Line The string may contain one or more Directives of the form char and can be entered in Text or Binary form Notes If the keep alive idle time the initial keep alive probe expires the user timeout is exp...

Page 77: ... Default is 15000 Flush Serial Data Set whether the serial Line data buffer is flushed upon a new network connection Choices are Enabled serial data buffer is flushed on network connection Disabled serial data buffer is not flushed on network connection default Block Serial Set whether Block Serial is enabled for debugging purposes Choices are Enabled If Enabled incoming characters from the Serial...

Page 78: ... is taken as a disconnect Table 10 7 Tunnel Disconnect Mode Settings To Configure Tunnel Disconnect Mode Settings Using Web Manager To configure the Disconnect Mode for a specific tunnel click Tunnel in the menu and select Tunnel 1 Disconnect Mode Using the CLI To enter the Tunnel 1 Disconnect command level enable tunnel 1 disconnect Tunnel Disconnect Mode Settings Description Stop Character Enter...

Page 79: ...ommand Mode Choices are Enabled Disabled default Verbose Response Set whether Modem Response Codes are sent out on the Serial Line Choices are Enabled Disabled default Response Type Select a representation for the Modem Response Codes sent out on the Serial Line Choices are Text ATV1 default Numeric ATV0 Error Unknown Commands Set whether the Error Unknown Commands is enabled ATU0 and ERROR is ret...

Page 80: ...dem Emulation Settings Using Web Manager To configure the Modem Emulation for a specific tunnel click Tunnel in the menu and select Tunnel 1 Modem Emulation Using the CLI To enter the Tunnel 1 Modem command level enable tunnel 1 modem Using XML Include in your file configgroup name tunnel modem instance 1 ...

Page 81: ... send break or start echoing IAC is only supported in Telnet Login Connect Menu Select the interface to display when the user logs in Choices are Enabled shows the Login Connect Menu Disabled shows the CLI default Exit Connect Menu Select whether to display a choice for the user to exit the Login Connect Menu and reach the CLI Choices are Enabled a choice allows the user to exit to the CLI Disable...

Page 82: ...e Terminal 1 settings these steps apply to other terminal instances of the device Using Web Manager To configure a particular Terminal Line click Terminal on the menu and select Line 1 Configuration Using the CLI To enter the Terminal Line command level enable config terminal 1 Using XML Include in your file configgroup name terminal instance 1 Host Configuration Table 11 2 Host Configuration Host...

Page 83: ...nd level enable config host 1 Using XML Include in your file configgroup name host instance 1 SSH Username Appears if you selected SSH as the protocol Enter a username to select a pre configured Username Password Key configured on the SSH Client Users page or leave it blank to be prompted for a username and password at connect time Note This configuration option is only available when SSH is selec...

Page 84: ...To View or Configure DNS Settings Using Web Manager To view DNS current status click DNS in the menu To lookup DNS name or IP address click DNS in the menu to access the Lookup field Note To configure DNS for cases where it is not supplied by a protocol click Network in the menu and select Interface Configuration Using the CLI To enter the DNS command level enable dns Using XML Include in your fil...

Page 85: ...f the syslog Here you can configure the syslog host and the severity of the events to log Note The system log is always saved to local storage but it is not retained through reboots unless diagnostics logging to the file system is enabled Saving the system log to a server that supports remote logging services see RFC 3164 allows the administrator to save the complete system log history The default...

Page 86: ...down menu This setting applies to all syslog facilities The drop down list in the Web Manager is in descending order of severity e g Emergency is more severe than Alert HTTP Settings Description State Select to enable or disable the HTTP server Enabled default Disabled Port Enter the port for the HTTP server to use The default is 80 Secure Port Enter the port for the HTTPS server to use The defaul...

Page 87: ...hen file including firmware upgrade is uploaded from webpage Logging State Select to enable or disable HTTP server logging Enabled default Disabled Max Log Entries Set the maximum number of HTTP server log entries Only the last Max Log Entries are cached and viewable Log Format Set the log format string for the HTTP server Follow these Log Format rules a remote IP address could be a proxy b bytes ...

Page 88: ...n with to refer to the filesystem Auth Type Select the authentication type None no authentication is necessary Basic encodes passwords using Base64 Digest encodes passwords using MD5 SSL can only be accessed over SSL no password is required SSL Basic is accessible only over SSL and encodes passwords using Base64 SSL Digest is accessible only over SSL and encodes passwords using MD5 Note When chang...

Page 89: ...e read community used by the agent defaults to public community Write Community Specify the write community used by the agent defaults to private community System Contact Specify the system contact System Name Update the system name as necessary The default system name is System Description Update the system description as necessary The default system information includes the manufacturer name mod...

Page 90: ...e under Windows Components Networking Services Details before setting up the PremierWave device to utilize Discovery Using Web Manager To access the area with options to configure discovery and view current discovery statistics click Discovery in the menu Using the CLI To enter the command level enable config discovery Using XML Include in your file configgroup name discovery Discovery Description...

Page 91: ...er the SMTP server port number The default is 25 Username Enter a Username to direct outbound email messages through a mail server Password Enter a Password to direct outbound email messages through a mail server Overriding Domain Enter the domain name to override the current domain name in EHLO Extended Hello Email Configuration Settings Description From Click the Configure SMTP link to configure...

Page 92: ...gure basic Email settings click Email in the menu and select Email 1 Configuration To send an email click Email in the menu and select Email 1 Send Email Using the CLI To enter Email command level enable email 1 Using XML Include in your file configgroup name email instance 1 Message File Enter the path of the file to send with the email alert This file appears within the message body of the email...

Page 93: ...scription Delete Click beside an existing SMS Sender Configuration to delete it Number View the sender number of an existing SMS sender Shoulder Tap Check to allow incoming SMS with content containing shoulder tap from this sender to start the cellular interface Relay Control Check to allow incoming SMS with content containing relay N On Off from this sender to open and close the device relays Inb...

Page 94: ...Using Web Manager To view and configure outbound SMS click SMS in the menu and select Outbound Using the CLI To enter the command level enable configure sms outbound Using the XML Include in your file configgroup name sms outbound Number Enter the Recipient Number Encoding Select the SMS encoding mode ASCII 7 bit ASCII 8 bit UCS 2 Message Enter the SMS message content Note Entering more than 70 ch...

Page 95: ...are and release notes for the unit from the Lantronix Web site www lantronix com support downloads or by using anonymous FTP ftp ftp lantronix com Loading New Firmware through Web Manager Upload the firmware using the device web manager System page To upload new firmware 1 Select System in the menu bar The System page appears ...

Page 96: ...rmware on the PremierWave XC HSPA unit 5 Click OK in the confirmation popup which appears The firmware will be installed and the device will automatically reboot afterwards 6 Close and reopen the web manager internet browser to view the device s updated web pages Note You may need to increase HTTP Max Bytes in some cases where the browser is sending data aggressively within TCP Windows size limit ...

Page 97: ...rmat The device will reboot upon successful completion of the firmware upgrade Example FTP session ftp 192 168 10 127 Connected to 192 168 10 127 220 vsFTPd 2 0 7 Name 192 168 10 127 user admin 331 Please specify the password Password 230 Login successful Remote system type is UNIX Using binary mode to transfer files ftp put premierwave_xc_hspa_8_0_0_0R15 200 PORT command successful Consider using...

Page 98: ...n as opposed to symmetric encryption in which a single secret key is used by both parties TLS SSL Transport Layer Security TLS and its predecessor Secure Sockets Layer SSL use asymmetric encryption for authentication In some scenarios only a server needs to be authenticated in others both client and server authenticate each other Once authentication is established clients and servers use asymmetri...

Page 99: ...ate request for a CA typically for a fee The CA will sign the certificate request producing a certificate key combo the certificate contains the identity of the owner and the public key and the private key is available separately for use by the owner As an alternative to acquiring a signed certificate from a CA you can act as your own CA and create self signed certificates This is often done for t...

Page 100: ... CLI Command Mode and for tunneling in Accept Mode The SSH client is for tunneling in Connect Mode To configure the PremierWave XC HSPA intelligent gateway as an SSH server there are two requirements Defined Host Keys both private and public keys are required These keys are used for the Diffie Hellman key exchange used for the underlying encryption protocol Defined Users these users are permitted ...

Page 101: ...curity keys ensure the keys are not compromised in transit Public Key Click Choose File to browse to and select the existing public key you want to upload In Web Manager you can also browse to the public key to be uploaded Key Type Select a key type to use for the new key RSA DSA Bit Size Select a bit length for the new key 512 768 1024 Submit key Click the Submit button after setting the informat...

Page 102: ...se File to browse to and select the existing public RSA key you want to use with this user In Web Manager you can also browse to the public RSA key to be uploaded If authentication is successful with the key no password is required Public DSA Key Click Choose File to browse to and select the existing public DSA key you want to use with this user In Web Manager you can also browse to the public DSA...

Page 103: ... Username Enter the name that the device uses to connect to an SSH server Key Type Select a bit length for the key RSA DSA Bit Size Select the bit length of the new key 512 768 1024 Using a larger Bit Size takes more time to generate the key Approximate times are 1 second for a 512 bit RSA key 1 second for a 768 bit RSA key 1 second for a 1024 bit RSA key 2 seconds for a 512 bit DSA key 2 seconds ...

Page 104: ...self Note The blue text in the XML command strings of this chapter are to be replaced with a user specified name Create a New Credential After creating a new credential you can either establish your credential through Certificate and Key Generation or Upload Certificate Table 15 6 Create a New Credentials To Create a New Credential Using Web Manager To create a new credential click SSL in the menu...

Page 105: ... must start with BEGIN CERTIFICATE and end with END CERTIFICATE Some Certificate Authorities add comments before and or after these lines Those need to be deleted before upload New Certificate Type Choose the new certificate type to be uploaded PEM PKCS7 PKCS12 New Private Key Click Choose File to browse to and select the certificate type being uploaded The key needs to belong to the certificate e...

Page 106: ...ated with the new self signed certificate preferably matching the host name or the ip address of the device whichever will be the intended access approach This is a required field Expires Enter the expiration date in mm dd yyyy format for the new self signed certificate Example An expiration date of May 9 2018 is entered as 05 09 2018 Type Select the type of key RSA Public Key Cryptography algorit...

Page 107: ...ed Authorities Settings Description Authority Click Choose File to browse to and select the SSL authority certificate RSA or DSA certificates are allowed The format of the authority certificate can be PEM or PKCS7 PEM files must start with BEGIN CERTIFICATE and end with END CERTIFICATE Some Certificate Authorities add comments before and or after these lines Those need to be deleted before upload ...

Page 108: ...e USB mount option is disabled USB drive will not be mounted Table 16 1 File Statistics To View Statistics Using Web Manager To view statistics format the filesystem or configure USB auto mount features click Filesystem in the menu and select Statistics File Display View the list of existing files and their contents in the ASCII or hexadecimal formats Table 16 2 File Display Settings Filesystem Co...

Page 109: ...Files can also be uploaded via HTTP Table 16 4 File Transfer Settings File Modification Commands Description rm Removes the specified file from the file system touch Creates the specified file as an empty file cp Creates a copy of a file mkdir Creates a directory on the file system rmdir Removes a directory from the file system format Format the file system and remove all data File Transfer Settin...

Page 110: ...Select the action that is to be performed via TFTP Get a get command will be executed to store a file locally Put a put command will be executed to send a file to a remote location Local File Enter the name of the local file on which the specified get or put action is to be performed Remote File Enter the name of the file at the remote location that is to be stored locally get or externally put Ho...

Page 111: ...ommand level enable config icmp Using XML Include in your file configgroup name icmp To View ICMP Protocol Stack Settings Using Web Manager To view ICMPv6 protocol settings click Protocol Stack in the menu and select ICMPv6 Multicast Time to Live This value fills the Time To Live in any multicast IP header Normally this value will be one so the packet will be blocked at the first router It is the ...

Page 112: ...d level enable config arp Using XML Include in your file configgroup name arp Protocol Stack ARP Settings Description IP Address Enter the IP address to add to the ARP cache After entering the MAC address click the Add button MAC Address Enter the MAC address to add to the ARP cache After also entering the IP address click the Add button Add button Click the Add button after entering the ARP Cache...

Page 113: ...ow hardware information Using XML Include in your file statusgroup name hardware IP Sockets You can view the list of listening and connected IP sockets To View the List of IP Sockets Using Web Manager To view IP Sockets click Diagnostics in the menu and select IP Sockets Using the CLI To enter the command level enable show ip sockets Using XML Include in your file statusgroup name ip sockets Ping ...

Page 114: ...ceroute Settings To Perform a Traceroute Using Web Manager To perform a Traceroute click Diagnostics in the menu and select Traceroute Using the CLI To enter the command level enable trace route host Using XML Not applicable Timeout Enter the time in seconds for the PremierWave XC intelligent gateway to wait for a response from the host before timing out The default is 5 seconds Submit Button Clic...

Page 115: ...enable device show memory Diagnostics Log Description Log Output Select a diagnostic log output type Disable Turn off the logging feature Filesystem Directs logging to log txt Line 1 or 2 Directs logging to the selected serial line Log Max Length Set the maximum length of the log txt file in Kbytes Note This setting becomes available when Filesystem is selected Log Verbosity Level Select the Verbo...

Page 116: ...To View Process Information Using Web Manager To view process information click Diagnostics in the menu and select Processes Using the CLI To enter the command level enable show processes Using XML Include in your file statusgroup name processes Threads The PremierWave unit threads information shows details of threads in the ltrx_evo task which can be useful for technical experts in debugging To V...

Page 117: ...L Include in your file configgroup name clock Clock Description Method Select a clock change method from the drop down menu Manual this option allows you to directly set the date and time SNTP this option keeps the time synchronized with the NTP Server Cellular Network this option allows the time to be synchronized with the cellular network Date Use the drop down menu to select the Year Month and ...

Page 118: ...nd time Displays the current date and time Schedule Select the Daily or Interval schedule from the drop down menu Time 24 hour Enter the Hour and Min minute in 24 hour time for the reboot time if Daily schedule is selected Interval Enter the interval number and select the interval type Hours Days or Weeks from the drop down menu Reboot Device Click the Reboot button to reboot the device Restore Fa...

Page 119: ...CLI in the menu and select Configuration Using the CLI To enter CLI command level enable config cli Using XML Include in your file configgroup name cli Command Line Interface Configuration Settings Description Login Password Enter the password for the admin account PASS is the default password Enable Level Password Enter the password for access to the Command Mode Enable level There is no password...

Page 120: ...e SSH settings control CLI access to the PremierWave device over the SSH protocol Table 17 3 SSH Settings Telnet Settings Description Telnet State Select to enable or disable CLI access via Telnet Telnet Port Enter an alternative Telnet Port to override the default used by the CLI server Blank the field to restore the default Telnet Max Sessions Specify the maximum number of concurrent Telnet sess...

Page 121: ...or another The XML data can be dumped to the screen or exported to a file on the file system By default all groups are exported You may also select a subset of groups to export Table 17 4 XML Exporting Configuration XML Export Configuration Settings Description Export to browser Select this option to export the XCR data in the selected fields to the browser Use the xcr dump command to export the d...

Page 122: ...t Networking Export button Click Export after selecting the XML Export Configuration settings XML Export Status Settings Description Export to browser Select this option to export the XCR data in the selected fields to the browser Use the xcr dump command to export the data to the browser Export to local file Select this option to export the XCR data to a file on the device If you select this opti...

Page 123: ...m single line Settings on the Filesystem This import option copies line settings from an the input file containing only one Line instance to all of the selected Lines Table 17 6 Import Configuration from Filesystem Settings Import Configuration from Filesystem Settings Description Filename Enter the name of the file on the PremierWave unit local to its filesystem that contains XCR data Lines to Im...

Page 124: ...PA Intelligent Gateway User Guide 125 To Import Configuration in XML Format Using Web Manager To import configuration click XML in the menu and select Import Configuration Using the CLI To enter the XML command level enable xml Using XML Not applicable ...

Page 125: ...ctly into the firmware image but may be overridden by placing the appropriate file in the appropriate directory on the PremierWave XC HSPA unit file system Web Manager files can be retrieved and overridden with the following procedure 1 FTP to the PremierWave XC HSPA device 2 Make a directory mkdir and name it http config 3 Change to the directory cd that you created in step 2 http config 4 Save t...

Page 126: ...119 for additional configuration options available on the Systems page Table 18 1 Short and Long Name Settings To Customize Short or Long Names Using Web Manager To access the area with options to customize the short name and the long name of the product or to view the current configuration click System in the menu Using the CLI To enter the command level enable Using XML Include in your file conf...

Page 127: ... x Omni Directional Penta band Antennas Ethernet 10BaseT and 100Base TX Link auto sensing MDIX full and half duplex support RJ 45 Connector with LEDs operation and link 1 5 KV Isolation Serial Interface Software selectable RS 232 422 485 Software selectable RS 485 termination Serial data rates from 300 to 921 Kbps Characters 7 or 8 data bits Parity Odd Even None Stop Bits 1 or 2 Modem Control DTR ...

Page 128: ...ay Output ON and OFF Automatic Event Trigger ON or OFF possible events includeloss of cellular link loss of Ethernet link digital input event Relay Output Response User configurable Support 1A 24V I O Connectors 2 x Digital Input 1 x Relay Output Terminal Block LED Indicators Cellular Mode Signal Strength Serial RX TX USB Connection System Status Power Ethernet Speed Ethernet Activity Routing Gate...

Page 129: ...iscovery Protocols UPnP Industrial Protocols Modbus TCP Modbus RTU Modbus ASCII Event Triggers and Actions Events Cellular Link State Change Ethernet Link State Change Digital Input State Change Actions SMS Email HTTP Post FTP Put Relay Output SNMP Trap Security SSL v3 SSH v2 Client Server Supports up to 2048 bit certificates Encryption AES 3DES RC4 Authentication SHA 1 MDS Base 64 User Access Lis...

Page 130: ...s typical Power Supply 100 240 VAC 50 60 Hz 12 VDC 1 8A with locking barrel connector and regional adapters 40 to 75 C Environmental Operating Temperature 40 to 70 C Storage Temperature 40 to 85 C Relative Humidity 5 to 95 non condensing IP Rating 30 Dimensions Size L x W x H 109 mm x 109 mm x 30 mm 4 3 in x 4 3 in x 1 2 in Weight 0 24 kg 0 55 lb ...

Page 131: ...with the maximum permissible gain and required antenna impedance for each antenna type indicated Antenna types not included in this list having a gain greater than the maximum gain indicated for that type are strictly prohibited for use with this device Approved Antenna Taoglas TG 09 113 Hinged Monopole 2 8dBi peak gain Cet appareil conforme aux normes exempts de licence CNR d Industrie Canada Son...

Page 132: ...3 1st Edition 2006 07 EN 62311 2008 Emissions and Immunity US FCC 22H 2013 FCC 24E 2013 FCC 15 109 2013 Class B FCC 15 107 2013 Class B Canada RSS 132 2013 RSS 133 2013 RSS 210 2010 Europe R TTE Directive 1999 5 EC EN 301 908 1 V5 2 1 2011 EN 301 908 2 V5 2 1 2011 EN 301 511 V9 0 2 2003 EN 301 489 1 V1 9 2 2011 EN 301 489 7 V1 3 1 2005 EN 301 489 24 V1 5 1 2010 EN 55022 2010 Class B EN 55024 Trans...

Page 133: ...er s Contact Lantronix Inc 7535 Irvine Center Drive Suite 100 Irvine CA 92618 USA Tel 949 453 3990 Fax 949 453 3995 RoHS REACH and WEEE Compliance Statement Please visit http www lantronix com legal rohs for Lantronix s statement about RoHS REACH and WEEE compliance ...

Page 134: ...rmation extended support services and product documentation To contact technical support or sales look up your local office at http www lantronix com aboujchent contact html When you report a problem please provide the following information Your name company name address and phone number Lantronix product and model number Lantronix MAC address or serial number Firmware version and current configur...

Page 135: ...ing from 0 to F which are represented as 0 9 A for 10 B for 11 etc To convert a binary value for example 0100 1100 to a hexadecimal representation treat the upper and lower four bits separately to produce a two digit hexadecimal number in this case 4C Use the following table to convert values from binary to hexadecimal Scientific Calculator Another simple way to convert binary to hexadecimal is to...

Page 136: ... Hexadecimal Conversions PremierWave XC HSPA Intelligent Gateway User Guide 137 Figure D 2 Windows Scientific Calculator 4 Click Hex The hexadecimal value appears Figure D 3 Hexadecimal Values in the Scientific Calculator ...

Reviews: