background image

IPSEC 

 

Connect Status and Control 

Show IPSEC connection and status of current router on IPSEC page. 

 

Name:

 the name of IPSEC connection 

Type: 

The type and function of current IPSEC connection 

Common name:

 local subnet, local address, opposite end address and opposite end subnet of 

current connection 

Status: 

connection status: closed, negotiating, establish 

Closed: 

this connection does not launch a connection request to opposite end 

Negotiating: 

this connection launches a request to opposite end, is under negotiating, the 

connection has not been established yet 

Establish: 

the connection has been established, enabled to use this tunnel 

Action: 

the action of this connection, current is to delete, edit, reconnect and enable 

Delete: 

to delete the connection, also will delete IPSEC if IPSEC has set up 

Edit:

 to edit the configure information of this connection, reload this connection to make the 

configuration effect after edit 

Reconnect: 

this action will remove current tunnel, and re-launch tunnel establish request 

Enable: 

when the connection is enable, it will launch tunnel establish request when the system 

reboot or reconnect, otherwise the connection will not do it 

Add: 

to add a new IPSEC connection 

 

Add IPSEC connection or edit IPSEC connection 

Type: 

to choose IPSEC mode: 

  

 

Net-to-Net VPN

: create a site-to-site tunnel 

  

 

Host-to-Host VPN

: create a client-to-site tunnel 

 

Connection: 

this part contains basic address information of the tunnel 

Summary of Contents for Datamax 4G

Page 1: ......

Page 2: ...nagement 17 Status 18 Router Information 18 WAN 24 Wi Fi 26 Bandwidth 28 LAN WAN Setup 29 LAN 29 WAN 32 Services 39 Wi Fi 43 Wi Fi Security 45 Advanced Feature 48 DDNS 48 PPTP VPN 50 L2TP VPN 52 Open...

Page 3: ...76 URL Filtering 78 Packet Filtering 79 Serial Applications 80 maXconnect 81 GPS 82 Administration 83 Management 83 Schedule Reboot Shutdown 85 SMS Function 86 Web logs 87 Shell Commands 87 Firmware...

Page 4: ...simile 61 2 96300844 Email support maxon com au Public holidays excluded Sales Hours of Operation Monday to Thursday 8 30am to 5 00pm Friday from 8 30am to 4 30pm Telephone 1300000734 Facsimile 61 2 9...

Page 5: ...n accordance with instructions can cause harmful radiation to radio communication Unauthorized antennas modifications or attachments could impair call quality damage the device or result in violation...

Page 6: ...s could cause an explosion or fire resulting in bodily injury or death Areas with a potentially explosive atmosphere are often but not always clearly marked They include Fueling areas such as gas or p...

Page 7: ...t Router with RS232 wifi Model MA100 1010 4G Document Type PDF Current Version Number 1 0 Status of the Document Public Release Revision Date June 2017 Total Number of Pages 90 Revision History Level...

Page 8: ...nt transportation smart grid industrial automation and telemetry Features and Benefits Designed for Industrial Application Industrial cellular module MC7430 High powered industrial 32bit CPU Industria...

Page 9: ...epeater and Bridge modes WIFI security options include WEP WPA WPA2 encryption Supports RADIUS authentication and MAC address filter Support DHCP server and client firewall NAT DMZ host URL block QoS...

Page 10: ...em Content GPS Module Industrial GPS module Receiver Type 50 channle GPS L1 1575 42MHz C A code SBAS WAAS EGNOS MSAS GAGAN Support GALILEO Max update rate 4 Hz Accuracy Position 2 5m CPE SBAS 2 0m CPE...

Page 11: ...ts RJ45 auto MDI MDIX 1 5KV magnetic isolation protection Serial 1x RS232 port 15KV ESD protection Data bits 5 6 7 8 Stop bits 1 1 5 optional 2 Parity none even odd space optional mark optional Baud r...

Page 12: ...cation 355 592mA 12VDC Schedule Shutdown 2 57 4 2mA 12 VDC Physical Characteristics Item Content Housing Iron providing IP30 protection Dimensions 207x135x28 mm Weight 790g Environmental Limits Item C...

Page 13: ...1 WIFI antenna Female SMA 1 GPS antenna Male SMA 1 Ethernet cable 1 Console cable 1 optional Power lead 1 Installation and Cable Connection SIM card Installation Power off the router and press the ej...

Page 14: ...J45 connector and is labelled as Console on the router If required plug the RJ45 end of the serial cable into the RS232 port on the router and plug the DB9F end of the serial cable into the serial int...

Page 15: ...Power The input supply voltage range is 5 36VDC We recommend using the standard DC 12VDC 1 5A power adaptor available from RFI 7 RTS input 8 CTS output...

Page 16: ...g interface of switch is connected Communicating WAN OFF The WAN interface is unplugged ON BLINK The WAN interface is plugged in data is traversing the WAN interface WIFI OFF WIFI is not active ON WIF...

Page 17: ...need a computer with a spare Ethernet LAN port The LAN card configuration should have the Internet Protocol TCP IP set to obtain an IP Address and DNS server address automatically To check these sett...

Page 18: ...field The Default IP Address of the Ethernet port is 192 168 0 1 The router will prompt to change the login credentials the default username and password are both admin 4 After providing the correct...

Page 19: ...f board not module firmware MAC Address This is MAC address of Router Host Name This is host name of router WAN Domain Name This is WAN domain name of router Current Time This is current AEST time Upt...

Page 20: ...memory minus allocated memory Cached the memory used by high speed cache memory Active Active use of buffer or cache memory page file size Inactive Not often used in a buffer or cache memory page fil...

Page 21: ...LAN port Ethernet IP Address IP Address of the LAN port Subnet Mask Subnet Mask of the LAN port Gateway Gateway of the LAN port Local DNS DNS of the LAN port Host Name host name of LAN client IP Addr...

Page 22: ...te DHCP client Connected L2TP server This tab will only be displayed if L2TP Server is configured under Advanced feature L2TP VPN This will provide connected L2TP Server Interface The interface assign...

Page 23: ...PTP Server Interface The interface assigned by dial up system Local IP Tunnel IP address of the local PPTP server Datamax Remote IP Tunnel IP address of remote PPTP client Delete Click to disconnect P...

Page 24: ...e are several connection types on Main WAN connection type The configured connection type will show under Connection type Connection Uptime length of time this connection has been established If not c...

Page 25: ...bar graph of the selected month data traffic Previous Month change graph to previous ie earlier month Next Month change graph to next ie later month Backup save traffic information to a file on your P...

Page 26: ...ess mode Access Point Client etc Network Wireless network mode SSID Wireless network name Channel Wireless network channel TX Power Reflection power of wireless network Rate Reflection rate of wireles...

Page 27: ...Network Display other networks nearby SSID The name of wireless network nearby Mode Operating mode of wireless network nearby MAC Address MAC address of the wireless nearby Channel The channel of the...

Page 28: ...his page display the bandwidth information on LAN and WAN Bandwidth Monitoring LAN Graph horizontal axis Time vertical axis Speed rate Bandwidth Monitoring WAN Graph horizontal axis Time vertical axis...

Page 29: ...setup For WAN Setup users can configure modem to connect to 4G or 3G network Default is 4G connection Router can be configured for Automatic DHCP configuration if any device connects to WAN port Dual...

Page 30: ...Local DNS If you want to use nameservers attached to one of the Datamax LAN ports enter the IP address of the server here To use the nameservers supplied by the WAN interface leave at 0 0 0 0...

Page 31: ...exclude the Datamax IP address Maximum DHCP Users The maximum number of concurrent DHCP lease Client Lease Time Leased time for IP address in minutes After this amount of time the client will need to...

Page 32: ...urrently unreachable you can set the routers real time clock here Click the get button to refresh the browser page with the current router time and Set to set the current router time WAN This WAN sett...

Page 33: ...e when it is again available Main WAN Connection Type There are seven configuration options for the WAN interface Disabled Static IP Automatic DHCP Configuration dhcp 4G PPOE 3G Link 1 3G Link 2 dhcp...

Page 34: ...tically via DHCP This is useful when modem is connected to another router via its WAN Port DHCP 4G This connection allows modem to connect to 4G network Users are recommended to configure with correct...

Page 35: ...Tagging If your ISP supports VDSL you can enable it here MPPE Encryption if your connection requires Microsoft point to point encryption shared key is entered here Single Line Multi Link enable single...

Page 36: ...you can enter the PIN here Connection type Connection type Auto Force 4G Force 3G Force 2G Prefer 3G Prefer 2G options In most cases Auto is preferred however in some circumstances and locations you...

Page 37: ...fic can be send received Note The main and backup WAN detection servers have the route to their IP address bound to the specified link main or backup Therefore main and backup link detection servers a...

Page 38: ...Time the time between forced reconnects STP STP Spanning Tree Protocol allows for multiple redundant links while preventing routing loops packets do not ping pong from router to router...

Page 39: ...may need to reduce this please contact your network administrator and or ISP Services DHCP Server DHCP assigns IP addresses to user s local devices While the main configuration is on the setup page us...

Page 40: ...in users can define here their local LAN domain which is used as local domain for DNSmasq and DHCP service if chose above Static Leases if users want to assign certain hosts a specific address then th...

Page 41: ...d it can prevent an external attacker to access the router s internal Web interface It is a security measure Additional DNSMasq Options some extra options users can set by entering them in Additional...

Page 42: ...to capture system messages By default they will be collected in the local file var log messages To send them to another system enter the IP address of a remote syslog server Syslog Out Mode three log...

Page 43: ...e router login information is send without encryption in the telnet protocol WAN Traffic Counter Ttraff Daemon enable or disable wan traffic counter function Wi Fi Wireless Network Enable or Disable t...

Page 44: ...ailable this decreases throughput Wireless Network Name SSID The SSID is the network name shared among all devices in a wireless network The SSID must be identical for all devices in the wireless netw...

Page 45: ...P Isolation This setting isolate wireless clients so that client to client access between different SSIDs is prohibited Note Save the changes after changing the Wireless Mode Wireless Network Mode wir...

Page 46: ...ere are two levels of WEP encryption 64 bit 40 bit and 128 bit To utilize WEP select the desired encryption bit and enter a passphrase or up to four WEP key in hexadecimal format If you are using 64 b...

Page 47: ...etween 8 and 63 ASCII character or hexadecimal digits Key Renewal Interval in seconds 1 99999 WPA Enterprise WPA2 Enterprise WPA2 Enterprise Mixed WPA Enterprise uses an external RADIUS server to perf...

Page 48: ...ice The Maxon MA100 1010 4G router currently supports DynDNS freedns Zone edit NO IP 3322 easyDNS TZO DynSIP and Custom based on the user User Name DDNS server username Password DDNS server password H...

Page 49: ...DDNS Status shows DDNS specific log information...

Page 50: ...cast support Enable or disable broadcast support of PPTP server Force MPPE Encryption Enable of disable force MPPE encryption of PPTP data DNS1 DNS2 WINS1 WINS2 set DNS1 DNS2 WINS1 WINS2 Server IP Inp...

Page 51: ...NS Name PPTP server s IP Address or DNS Name Remote Subnet the network of the remote PPTP server Remote Subnet Mask subnet mask of remote PPTP server MPPE Encryption enable or disable Microsoft Point...

Page 52: ...e router as PPTP server differ from LAN address Client IP s IP address assigns to the client the format is xxx xxx xxx xxx xxx xxx xxx xxx CHAP Secrets User name and password of the client using L2TP...

Page 53: ...osoft Point to Point Encryption MTU Maximum transmission unit MRU Maximum receive unit NAT Network address translation User Name User name to login L2TP Server Password Password to login L2TP Server R...

Page 54: ...server Bridge TAP DHCP Proxy mode enable or disable DHCP Proxy mode Pool start IP pool start IP of the client allowed by OPENVPN server Pool end IP pool end IP of the client allowed by OPENVPN server...

Page 55: ...w Client to Client enable or disable allow client to client Allow duplicate cn enable or disable allow duplicate cn TUN MTU Setting set the value of TUN MTU TCP MSS MSS of TCP data TLS Cipher TLS Tran...

Page 56: ...nal Config additional configurations of the server CCD Dir DEFAULT file other file approaches TLS Auth Key authority key of Transport Layer Security Certificate Revoke List configure some revoke certi...

Page 57: ...512 CBC Hash Algorithm Hash algorithm provides a method of quick access to data including SHA1 SHA256 SHA512 MD5 nsCertType verification support ns certificate type Use LZO Compression enable or disa...

Page 58: ...and AES 256 SHA TLS AUTH Key authority key of Transport Layer Security Additional Config additional configurations of OPENVPN server Policy based Routing input some defined routing policy CA Cert CA...

Page 59: ...use this tunnel Action the action of this connection current is to delete edit reconnect and enable Delete to delete the connection also will delete IPSEC if IPSEC has set up Edit to edit the configur...

Page 60: ...and subnet mask i e 192 168 7 0 24 Local ID tunnel local end identification IP and domain name are available Remote ID tunnel opposite end identification IP and domain name are available Detection thi...

Page 61: ...ryption ESP encryption type ESP Integrity ESP integrity solution ESP Key life Set ESP key life current unit is hour the default is 0 IKE aggressive mode allowed Negotiation mode adopt aggressive mode...

Page 62: ...unnel app Status Switch on off someone GRE tunnel app Name GRE tunnel name Through The GRE packet transmit interface Peer Wan IP Addr The remote WAN address Peer Subnet The remote gateway local subnet...

Page 63: ...ple 192 168 1 0 24 Port from Enter the number of the external port the port number seen by users on the Internet IP Address Enter the IP Address of the PC running the application Port to Enter the num...

Page 64: ...ilitarized Zone hosting feature allows one local user to be exposed to the Internet for use of a special purpose service such as Internet gaming or videoconferencing DMZ hosting forwards all the ports...

Page 65: ...ession LZS Stac Compression Enable or disable LZS Stac Compression MPPC Compression Enable or disable MPPC Compression MPPE PPPoE Encryption Enable or disable MPPE PPPoE Encryption Session Limit per M...

Page 66: ...emote Authentication Dial in User Authentication Port Radius Accounting Port Set the Remote Authentication Dial in User Accounting Port Radius Shared Key Transactions between the client and RADIUS acc...

Page 67: ...nable the Dynamic Routing feature for the WAN side select WAN To enable this feature for the LAN and wireless side select LAN WLAN To enable the feature for both the WAN and LAN select Both To disable...

Page 68: ...Mask the subnet mask for the new route Gateway IP address of the gateway device that forwards packets to the destination host or network Interface The interface that has the gateway attached LAN WLAN...

Page 69: ...address Vlan VLAN s allow users to specify which ports are bridged that is where broadcast traffic will be shared This allows users to create separate subnets on each LAN port or group of LAN ports N...

Page 70: ...priority and bulk traffic file transfer P2P gets low priority The main goal is to allow both types to live side by side without unimportant traffic disturbing more critical things All of this is autom...

Page 71: ...replacement for the CBQ qdisc in Linux HTB helps in controlling the use of the outbound bandwidth on a given link HTB allows you to use one physical link to simulate several slower links and to send...

Page 72: ...iority Users may specify priority for all traffic from a given IP address or IP Range Check all values and click Save Settings to save settings Click the Cancel changes button to cancel unsaved change...

Page 73: ...disabled Only enable the SPI firewall users can use other firewall functions filtering proxy block WAN requests etc Additional Filters Filter Proxy Wan proxy server may reduce the security of the gate...

Page 74: ...Complete the changes click the Save Settings button to save your changes Click the Cancel Changes button to cancel unsaved changes Impede WAN DoS Bruteforce Limit ssh Access This feature limits the ac...

Page 75: ...nable the corresponding connection will be recorded in the journal the disabled are not recorded Incoming Log To see a temporary log of the Router s most recent incoming traffic click the Incoming Log...

Page 76: ...choose to filter it will block specific computers to access the specific sites at a specific time You can set up 10 Internet access policies filtering specific PCs access Internet services at a partic...

Page 77: ...ter the appropriate IP addresses into the IP fields If you have a range of IP addresses to filter complete the appropriate IP Range fields Enter the appropriate MAC addresses into the MAC fields 6 Cli...

Page 78: ...icy rules is filtered If the user chooses the default policy rules for refuse and editing strategies to save or directly to save the settings If the strategy edited is the first it will be automatical...

Page 79: ...ilter Packet filter function is realized based on IP address or port of packets Enable Packet Filter Enable or disable packet filter function Policy The filter rule s policy you can choose the followi...

Page 80: ...at least one of these four parameters Serial Applications There is a console port on the Maxon MA100 1010 Normally this port is used to debug the router This port can also be used as a serial port The...

Page 81: ...time interval to send heart beat packet This item is valid only when you choose UDP DTU or TCP DTU protocol type TCP Server Listen Port This item is valid when Protocol Type is TCP Server Custom Hear...

Page 82: ...rface This item selects the GPS output interface including network and serial port Protocol TCP mode or UDP mode GPS Centre Address The GPS centre s IP Address or domain name GPS Centre Listening Port...

Page 83: ...r code The new password must not exceed 32 characters in length and must not include any spaces Enter the new password a second time to confirm it Note Default username and password is admin It is str...

Page 84: ...the router You must also change the router s default password to one of your own if you haven t already To remotely manage the router enter http xxx xxx xxx xxx 8080 the x s represent the router s In...

Page 85: ...d time Users can schedule regular shutdown and boot for the router At a specific date time match the weekday or match the mon day shutdown At a specific date time match the weekday and the mon day boo...

Page 86: ...ure WAN username and password via SMS This function is enabled by default Phone number added to the below list can only send SMS to the modem If no phone number is configured modem accepts message fro...

Page 87: ...our command and click Run Commands to submit Startup Users save some command lines to be executed at start up s router Fill the text area with commands only one command by row and click Save Start up...

Page 88: ...users to upgrade or downgrade firmware It may take few minutes to upgrade the firmware therefore please be patient and keep monitoring the upgrade bar modem will come back online after performing upgr...

Page 89: ...g the same firmware and same model of router Factory Default Factory default settings allow user to revert setting to factory settings The modem erase current configuration and load the factory settin...

Page 90: ...Reboot This menu allows modem to perform soft reboot of the modem When user change any settings modem should reboot...

Reviews: