background image

NB3700 User Manual 3.8

5.3

INTERFACES

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

24

5.3.1

WAN

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

24

5.3.2

Ethernet

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

30

5.3.3

Mobile

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

36

5.3.4

WLAN

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

41

5.3.5

USB

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

47

5.3.6

Serial Port

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

50

5.3.7

Digital I/O

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

53

5.3.8

GNSS

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

54

5.4

ROUTING

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

57

5.4.1

Static Routes

. . . . . . . . . . . . . . . . . . . . . . . . . . . . .

57

5.4.2

Extended Routing

. . . . . . . . . . . . . . . . . . . . . . . . . .

59

5.4.3

Multipath Routes

. . . . . . . . . . . . . . . . . . . . . . . . . . .

61

5.4.4

Mobile IP

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

62

5.4.5

Quality Of Service

. . . . . . . . . . . . . . . . . . . . . . . . . .

65

5.4.6

Multicast

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

67

5.5

FIREWALL

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

68

5.5.1

Administration

. . . . . . . . . . . . . . . . . . . . . . . . . . . .

68

5.5.2

Adress/Port Groups

. . . . . . . . . . . . . . . . . . . . . . . . .

68

5.5.3

Rules

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

69

5.5.4

NAPT

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

71

5.6

VPN

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

74

5.6.1

OpenVPN

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

74

5.6.2

IPsec

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

80

5.6.3

PPTP

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

86

5.6.4

GRE

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

89

5.6.5

Dial-In

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

90

5.7

SERVICES

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

92

5.7.1

SDK

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

92

5.7.2

DHCP Server

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 103

5.7.3

DNS Server

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 105

5.7.4

NTP Server

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 107

5.7.5

DynDNS

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 108

5.7.6

E-Mail

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 110

5.7.7

Events

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 111

5.7.8

SMS

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 112

5.7.9

SSH/Telnet Server

. . . . . . . . . . . . . . . . . . . . . . . . . . 115

5.7.10 SNMP Agent

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 117

5.7.11 Web Server

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 122

5.7.12 Redundancy

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 123

5.7.13 Voice Gateway

. . . . . . . . . . . . . . . . . . . . . . . . . . . . 125

5.8

SYSTEM

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 132

3

Summary of Contents for NB3700

Page 1: ...NetModule Router NB3700 User Manual for Software Version 3 8 Manual Version 1 5 NetModule AG Switzerland October 28 2016...

Page 2: ...3 2 USB 2 0 Host Port 11 3 3 3 M12 Ethernet Connectors 11 3 3 4 Power Supply 12 3 3 5 Digital Inputs and Outputs 13 3 3 6 RS 232 Port 14 4 Installation 16 4 1 Environmental Conditions 16 4 2 Installa...

Page 3: ...ce 65 5 4 6 Multicast 67 5 5 FIREWALL 68 5 5 1 Administration 68 5 5 2 Adress Port Groups 68 5 5 3 Rules 69 5 5 4 NAPT 71 5 6 VPN 74 5 6 1 OpenVPN 74 5 6 2 IPsec 80 5 6 3 PPTP 86 5 6 4 GRE 89 5 6 5 Di...

Page 4: ...ters 157 6 4 Setting Config Parameters 157 6 5 Getting Status Information 158 6 6 Scanning Networks 159 6 7 Sending E Mail or SMS 159 6 8 Updating System Facilities 159 6 9 Manage keys and certificate...

Page 5: ...P Configuration 45 5 15 USB Administration 47 5 16 USB Device Management 48 5 17 Serial Port Administration 50 5 18 Serial Port Settings 51 5 19 Digital I O Ports 53 5 20 Static Routing 57 5 21 Extend...

Page 6: ...Voice Gateway Administration 125 5 50 Voice Gateway Endpoint Configuration 127 5 51 Voice Gateway Routing Configuration 130 5 52 System 132 5 53 Regional settings 135 5 54 User Accounts 136 5 55 Remot...

Page 7: ...ification 13 3 11 Isolated Digital Inputs Specification 13 3 12 Pin Assignments of Digital Inputs and Outputs 14 3 13 RS 232 Port Specification 14 3 14 Pin Assignments of RS 232 Port 15 4 1 Operating...

Page 8: ...the router and its features The following chapters describe any aspects of commissioning the device installation procedure and provide helpful information towards configuration and maintenance Plese f...

Page 9: ...below 1500 Volts according to IEC 60950 1 TNV 1 circuit levels using safety approved components NB3700 routers shall only be used with a certified CSA or equivalent power supply which must have a lim...

Page 10: ...e routers comply with the relevant standards following the provisions of the Council Directive 1999 5 EC The signed version of the Declara tions of Conformity can be found on the NetModule web page 2...

Page 11: ...source codes covered by these licenses please contact our technical support at router support netmodule com Acknowledgements This product includes PHP freely available from http www php net Software...

Page 12: ...models include support for UMTS EDGE GPRS The UMTS LTE models can be equipped with a supplementary VOICE V or GNSS G option We also offer models for CDMA 450MHz Ca All models have following basic func...

Page 13: ...apply Mob1 lll on Mobile connection 1 is up l blinking Mobile connection 1 is being established m off Mobile connection 1 is down Mob2 lll on Mobile connection 2 is up l blinking Mobile connection 2...

Page 14: ...ed m off Normally open output port 1 is open DO2 l on Normally closed output port 2 is closed m off Normally closed output port 2 is open DI1 l on Input port 1 is set m off Input port 1 is not set DI2...

Page 15: ...cable with at least 6mm2 copper area Avoid corrosion and protect the screws against loosening Earthing is mandatory for the variant Pb 50 VDC to 136 VDC power supply Power Front Power supply galvanica...

Page 16: ...cification 3 3 3 M12 Ethernet Connectors Specification The five Ethernet ports have the following specification Feature Specification Isolation 1500 Vrms Speed 10 100 Mbps Mode Half Full Duplex Crosso...

Page 17: ...here are no batteries included Connector type M12 4 poles A coded male Table 3 7 Power Input Specifications Variant Pa Variant Pb 50 VDC to 136 VDC The power input has the following specifications Fea...

Page 18: ...fication Feature Specification Number of output ports 2 Limiting continuous current 1 A Maximum switching voltage 60 VDC 42 VAC Vrms Maximum switching capacity 60 W Table 3 10 Isolated Digital Outputs...

Page 19: ...mally closed Table 3 12 Pin Assignments of Digital Inputs and Outputs 3 3 6 RS 232 Port The RS 232 port if present has the following specification Feature Specification Protocol 3 wire RS 232 GND TXD...

Page 20: ...NB3700 User Manual 3 8 Pin Signal Pinning 2 RxD 3 not connected 4 TxD Table 3 14 Pin Assignments of RS 232 Port 20...

Page 21: ...to 136 VDC 10 Operating Temperature Range 25 C to 70 C Humidity 0 to 95 non condensing Altitude Variant Pa up to 4000m Altitude Variant Pb up to 2000m Over Voltage Category I Pollution Degree 2 Ingre...

Page 22: ...r information about SIM configuration can be found in chapter 5 3 3 4 4 Installation of the WLAN Antennas Any WLAN antennas must be mounted to the connectors WLAN1 and WLAN2 The number of attached ant...

Page 23: ...and Line Interface CLI and set configuration parameters directly The IP address of Ethernet1 is 192 168 1 1 and the Dynamic Host Configuration Pro tocol DHCP is activated on the interface by default T...

Page 24: ...e admin password will be also applied for the root user which can be used to access the device via the serial console telnet SSH or to enter the bootloader You may also configure additional users whic...

Page 25: ...serial port of your local computer You will also see the kernel messages at bootup there 3 Recovery Image In severe cases we can provide a recovery image on demand which can be loaded into RAM via TF...

Page 26: ...outer s interfaces WAN This page offers details about any enabled Wide Area Network WAN links such as the IP addresses network information signal strength etc The information about the amount of downl...

Page 27: ...on LAN This page shows information about the LAN interfaces plus the neighborhood informa tion DHCP This page offers details about any activated DHCP service including a list of issued DHCP leases Ope...

Page 28: ...about Dynamic DNS System Status The system status page displays various details of your NB3700 router including system details information about mounted modules and software release information SDK Th...

Page 29: ...n your hardware model WAN links can be made up of either Wireless Wide Area Network WWAN Wireless LAN WLAN Ethernet or PPP over Ethernet PPPoE connections Please note that each WAN link has to be conf...

Page 30: ...permanently in order to minimize link downtime Parameter WAN Link Priorities 1st priority The primary link which will be used whenever possible 2nd priority The first fallback link it can be enabled p...

Page 31: ...e of firewall issues Once established the Web Manager can be reached over port 8080 using the WAN address but still over the LAN1 interface using port 80 Parameter WAN Link Operation Modes disabled Li...

Page 32: ...any negative side effects the number of bytes in the data segment and the headers must not add up to more than the number of bytes in the Maximum Transmission Unit MTU The MTU can be configured per e...

Page 33: ...sion Settings Link The WAN link to be monitored can be ANY Mode Specifies whether the link shall only be monitored if being up e g for using a VPN tunnel or if connectivity shall be also validated at...

Page 34: ...transmitted in case a first ping failed Max number of failed trials The maximum number of failed ping trials until the link will be declared as down Emergency action The emergency action which should...

Page 35: ...ill be available as soon as a pre configured USB Ethernet device has been plugged in Ethernet Port Assignment Figure 5 6 Ethernet Ports This menu can be used to individually assign each Ethernet port...

Page 36: ...Ethernet port individually Most devices support auto negotiation which will configure the link speed automatically to comply with other devices in the network In case of negotiation problems you may...

Page 37: ...he associated virtual interface Any untagged packets as well as packets with an unassigned ID will be distributed to the native interface Figure 5 8 VLAN Management In order to form a distinctive subn...

Page 38: ...00 User Manual 3 8 Parameter VLAN Priority Levels 2 Excellent Effort 3 Critical Applications 4 Video 100 ms latency and jitter 5 Voice 10 ms latency and jitter 6 Internetwork Control 7 Network Control...

Page 39: ...he DNS servers can be set globally in the DNS server config uration menu But as soon as a link comes up it will use the interface specific name servers e g the ones being retrieved over DHCP and updat...

Page 40: ...e all IP related settings address subnet gateway DNS server will be retrieved from a DHCP server in the network You may also define static values but caution has to be taken to assign an unique IP add...

Page 41: ...egistering to a network usually takes some time and depends on signal strength and possible radio interferences You may hit the Update button at any time in order to restart PIN unlocking and trigger...

Page 42: ...e Please check the account details associated with your purchased SIM and figure out whether it is protected with a PIN PIN code The PIN code for unlocking the SIM card SMS gateway The service center...

Page 43: ...NB3700 User Manual 3 8 mentary Service Data USSD requests e g for querying the available balance of a prepaid account 43...

Page 44: ...ss and goes on as soon as the connection is up Refer to section 5 8 7 or consult the system log files for troubleshooting the problem in case the connection did not come up Figure 5 11 WWAN Interfaces...

Page 45: ...rtheron you may configure the following advanced settings Parameter WAN Advanced Parameters Required signal strength Sets a minimum required signal strength before the connec tion is dialed Home netwo...

Page 46: ...IP interface which can be used for routing and to provide services such as DHCP DNS NTP in the same way like an Ethernet LAN interface does Figure 5 12 WLAN Management If the administrative status is...

Page 47: ...ard Frequencies Bandwidth Net Data Rate Range Indoor Outdoor 802 11a 5 GHz 20 MHz 54 Mbit s 35m 120m 802 11b 2 4 GHz 20 MHz 11 Mbit s 35m 140m 802 11g 2 4 GHz 20 MHz 54 Mbit s 38m 140m 802 11n 2 4 5 G...

Page 48: ...s it comes back You can perform a WLAN network scan and pick the settings from the discovered information directly The authentication credentials have to be obtained by the operator of the remote acce...

Page 49: ...WPA2 should be preferred over WPA1 running WPA WPA2 mixed mode offers both WPA cipher The WPA cipher to be used the default is to run both TKIP and CCMP Passphrase The passphrase used for authenticati...

Page 50: ...nts and Ethernet hosts operate in the same subnet However for multiple SSIDs we strongly recommend to set up separated interfaces in routing mode in order to avoid unwanted access and traffic between...

Page 51: ...NB3700 User Manual 3 8 Parameter WLAN IP Settings IP address netmask In routing mode the IP address and netmask for this WLAN network 51...

Page 52: ...rt in order to get a list of supported devices Figure 5 15 USB Administration USB Administration Parameter USB Administration Administrative status Specifies whether devices shall be recognized Enable...

Page 53: ...ehave latency sensitive which may raise problems when operating over a slow IP connection Some devices may generally not work with the USB IP driver Please contact our support in case of compatibility...

Page 54: ...of the admin password The file can hold multiple hashes which will be processed line by line dur ing authentication which can be used for setting up more systems with different admin passwords For new...

Page 55: ...hich can be ac cessed with a serial terminal client from the other side It will provide helpful bootup and kernel messages and spawns a login shell so that users can login to the system device server...

Page 56: ...baud rate run on the serial port Data bits Specifies the number of data bits contained in each frame Parity Specifies the parity used for every frame that is transmitted or received Stop bits Specifie...

Page 57: ...P port on which the server will be available Timeout The time in seconds before the port will be disconnected if there is no activity on it A zero value disables this function Allow remote control All...

Page 58: ...s You can apply the following settings Parameter Digital I O Settings DO1 after reboot Initial status of DO1 after system has booted DO2 after reboot Initial status of DO2 after system has booted Besi...

Page 59: ...either standalone or assisted for A GPS Antenna type The type of the connected GPS antenna either passive or actively 3 volt powered Accuracy The desired accuracy in meters Fix frame interval The amo...

Page 60: ...f precision The dilution of precision as stated in GPGSA frames Furtheron each satellite also comes with the following details Parameter GNSS Satellite Information PRN The PRN code of the satelitte al...

Page 61: ...gency action The corresponding emergency action You can either let just restart the server which also re initializes GPS on the module or also reset the module in severe cases Please note that this mi...

Page 62: ...choose the route interface automatically depending on the best matching network configured for an interface Figure 5 20 Static Routing In general host routes precede network routes and network routes...

Page 63: ...ace default 0 higher met rics have the effect of making a route less favorable Flags A ctive P ersistent H ost Route N etwork Route D efault Route The flags obtain the following meanings Flag Descript...

Page 64: ...of a destination address netmask but also a source address netmask incoming interface and the type of service TOS of packets Parameter Extended Route Configuration Source address The source address of...

Page 65: ...er Manual 3 8 Parameter Extended Route Configuration Type of service The TOS value within the header of the packet Route to Specifies the target interface or gateway to where the packet should get rou...

Page 66: ...rfaces have to be defined to establish multipath routing Additional interfaces can be added by pressing the plus sign Parameter Add Multipath Routes Target network net mask Defines the target network...

Page 67: ...ss called the care of address in MIP terms of the mobile node has changed The home agent will then encapsulate packets destined to a mobile node s home address into a tunnel packet containing the curr...

Page 68: ...This is a 32 bit hexadecimal value Authentication type The used authentication algorithm This can be prefix suffix md5 default for MIP or hmac md5 Shared secret The shared secret used for authenticati...

Page 69: ...identifying the secu rity context for the tunnel between the mobile node and the home agent This is used to distinguish mobile nodes from each other Therefore each mobile node needs to be assigned a...

Page 70: ...s on which QoS should be active Parameter QoS Interface Parameters Interface The WAN interface on which QoS should be active Bandwidth congestion The bandwidth congestion method In case of auto the sy...

Page 71: ...h for this queue You can now configure and assign any services to each queue The following parameters apply Parameter QoS Service Parameters Interface The QoS interface of the queue Queue The QoS queu...

Page 72: ...owards the down stream interfaces on which hosts have joined the groups Parameter Multicast Routing Settings Administrative status Specifies whether multicast routing is active Incoming interface The...

Page 73: ...page can be used to enable and disable firewalling When turning it on a shortcut can be used to generate a predefined set of rules which allow administration over HTTP HTTPS SSH or TELNET by default b...

Page 74: ...a matching rule is found Packets which are not matching any of the rules configured will be ALLOWED Figure 5 25 Firewall Rules Parameter Firewall Rule Configuration Description A meaningful descriptio...

Page 75: ...interface The interface on which matching packets are received Protocol The used IP protocol of matching packets UDP TCP or ICMP Destination port s The destination port of matching packets which can...

Page 76: ...which outgoing NAT also called Masquerading will be performed NAT will hereby use the address of the selected interface and choose a random source port for outgoing connections and thus enables commu...

Page 77: ...NB3700 User Manual 3 8 Figure 5 27 Inbound NAPT 77...

Page 78: ...shall be redirected Redirect port The port to which matching packets will be redirected NAPT Outbound Rules Outbound rules will modify the source section of IP packets and can be used to establish 1 1...

Page 79: ...parameters either in standard configuration or upload an expert mode file which has been created in advance Refer to chapter 5 6 1 to learn more about how to manage clients and generate the files Par...

Page 80: ...NB3700 User Manual 3 8 Figure 5 29 OpenVPN Configuration 80...

Page 81: ...unnel protocol to be used for the transport connection Network mode Defines how the packets should be forwarded which can be either routed or bridged from to a particular LAN interface If required you...

Page 82: ...nt The expert configuration mode offers a straightforward way to configure a tunnel by simply uploading a zip package containing the required configuration and optionally key certificate files A clien...

Page 83: ...ior to creating certificates and establishing a tunnel connection Please ensure that all NTP servers are reachable Using host names also requires a working DNS server Client Management Once you have s...

Page 84: ...useful for routing purposes e g in case you want to redirect traffic for particular networks towards the server Routing between the clients is generally not allowed but you can enable it if desired F...

Page 85: ...e a secure channel and a bundle of algorithms that provide the parameters necessary to operate the AH and or ESP operations The Internet Security Association Key Management Protocol ISAKMP provides a...

Page 86: ...NB3700 User Manual 3 8 Figure 5 31 IPsec Administration 86...

Page 87: ...f packets It encapsulates packets in UDP and therefore requires a slight overhead which has to be taken into account when running over small sized MTU interfaces Please note that running NAT Traversal...

Page 88: ...re shared keys PSK or certifi cates within a public key infrastructure Extended Authentication XAUTH leverages RADIUS like authentication and can be used to apply user level access control over IPSec...

Page 89: ...ecommend AES256 Authentication algo rithm The desired IKE authentication method we prefer SHA1 over MD5 IKE Diffie Hellman Group The IKE Diffie Hellman Group SA life time The lifetime of Security Asso...

Page 90: ...esent Therefore you may need to specify the networks right and left of the endpoints by applying the following settings Parameter IPsec Network Settings Local network address The address of your local...

Page 91: ...wadays considered insecure but it still provides a straightforward way for establishing tunnels Figure 5 33 PPTP Administration When setting up a PPTP tunnel you would need to choose between server or...

Page 92: ...NB3700 User Manual 3 8 Figure 5 34 PPTP Tunnel Configuration 92...

Page 93: ...er address within the tunnel Client address range Specifies a range of IP addresses assigned to each client PPTP Client Management PPTP clients for a server tunnel need to be configured here They are...

Page 94: ...ing parameters are required for setting up a tunnel Parameter GRE Configuration Peer address The IP address of the remote peer Local tunnel address The local IP address of the tunnel Local tunnel netm...

Page 95: ...l In connection is not possible Figure 5 36 Dial in Server Settings The following settings can be set Parameter Dial in Server Configuration Administrative status Specifies whether incoming calls shal...

Page 96: ...ser Manual 3 8 which shall be allowed to dial in Please note that Dial In connections are generally discouraged As they are implemented as GSM voice calls they suffer from unreliability and poor bandw...

Page 97: ...le specific Application Programming Interface API which ships with a comprehensive set of functions for accessing hardware interfaces e g digital IO ports GPS external storage media serial ports but a...

Page 98: ...obtained from the NetModule support web page gives a detailed introduction of the language including a description of all available functions SDK API Functions The current range of API functions can b...

Page 99: ...e of variables for a specific section a list of available sections can be obtained by running cli status h By using the dump function you can figure out the content of the returned structure dump curr...

Page 100: ...Manual 3 8 wanlink 0 mode wanlink 0 name wanlink 0 prio wanlink 0 weight Running the CLI in interactive mode you will be also able to step through possible configuration parameters by the help of the...

Page 101: ...telling the router when the script is to be executed This can be either time based e g each Monday or triggered by one of the pre defined system events e g wan up as described in Events chapter 5 7 7...

Page 102: ...NB3700 User Manual 3 8 Figure 5 37 SDK Administration 102...

Page 103: ...orms you about the current status of the SDK It provides an overview about any finished jobs you can also stop a running job there and view the script output in the troubleshooting section where you w...

Page 104: ...NB3700 User Manual 3 8 Figure 5 38 SDK Jobs 104...

Page 105: ...the job Trigger Specifies the trigger that should launch the job Script Specifies the script to be executed Arguments Defines arguments which can be passed to the script sup ports quoting they will pr...

Page 106: ...der The source code is listed in the appendix Once enabled you can send a message to the phone number associated with a SIM modem It generally requires a password to be given on the first line and a c...

Page 107: ...digital output port output 2 on Turns on the second digital output port output 2 off Turns off the second digital output port Table 5 69 SMS Control Commands A response to the status command typicall...

Page 108: ...ive status Specifies whether the DHCP server is enabled or not First lease address The first address out of the range of IP addresses given to hosts Last lease address The last address out of this ran...

Page 109: ...NB3700 User Manual 3 8 Figure 5 39 DHCP Server 109...

Page 110: ...so used for serving fixed addresses for particular host names Figure 5 40 DNS Server The following settings can be applied Parameter DNS Server Settings Administrative status Enables or disables the D...

Page 111: ...NB3700 User Manual 3 8 names Please remember to point local hosts to the router s address for resolving them 111...

Page 112: ...h interface can be applied then Parameter NTP Server Settings Administrative status Specifies whether the NTP server is enabled or not Poll interval Defines the polling interval 64 2048 seconds for sy...

Page 113: ...ich can be useful in NAT scenarios The DynDNS client will be triggered whenever a WAN or VPN link comes up Figure 5 42 Dynamic DNS Settings We provide support for a bunch of common DynDNS operators bu...

Page 114: ...provided by your DynDNS service e g my box dyndns org Port The HTTP port of the service typically 80 Username The user name used for authenticating at the service Password The password used for authe...

Page 115: ...s Parameter E Mail Client Settings E mail client status Administrative status of the E Mail client From e mail address E Mail address of the sender Server address SMTP server address Server port SMTP...

Page 116: ...the event manager you can notify one or more recipients by SMS or E Mail upon certain system events The messages will contain a description provided by you and a short system info A list of all system...

Page 117: ...ce works and may fail You may use the sms report received event to figure out whether a message has been successfully sent Please do not forget that modems might register roaming to foreign networks w...

Page 118: ...NB3700 User Manual 3 8 Figure 5 44 SMS Configuration 118...

Page 119: ...created rules are processed by order and in case of matches will either drop or forward the incoming message before entering the system All non matching messages will be allowed Status The status page...

Page 120: ...ther user whereas normal users will only be able to view status values the admin user will obtain privileges to modify the system Figure 5 45 SSH and Telnet Server Please note that these services will...

Page 121: ...eter SSH Server Settings Administrative status Whether the SSH service is enabled or disabled Server port The TCP port of the service usually 22 Disable password based login By turning on this option...

Page 122: ...1 5 4795 LLDP EXT MED MIB 1 3 6 1 4 1 31496 VENDOR MIB The VENDOR MIB tables offer some additional information over the system and its WWAN GNSS and WLAN interfaces They can be accessed over the follo...

Page 123: ...iguration Administrative status Enable or disable the SNMP agent Operation mode Specifies if agent should run in compatibilty mode or for SNMPv3 only Contact System maintainer or other contact informa...

Page 124: ...set any values However it is possible to define its communities and authoritive host which will be granted administrative access Parameter SNMPv1 v2c Authentication Read community Defines the communi...

Page 125: ...01admin01 192 168 1 1 1 3 6 1 4 1 31496 10 40 10 0 i 1 Running a configuration update snmpset v 3 u admin n l authNoPriv a MD5 x DES A admin01admin01 192 168 1 1 1 3 6 1 4 1 31496 10 40 11 0 s http se...

Page 126: ...n n l authNoPriv a MD5 x DES A admin01admin01 192 168 1 1 1 3 6 1 4 1 31496 10 53 10 0 i 1 Setting digital OUT2 snmpset v 3 u admin n l authNoPriv a MD5 x DES A admin01admin01 192 168 1 1 1 3 6 1 4 1...

Page 127: ...unication will be encrypted and thus avoids any misuse of the system In order to enable HTTPS you would need to generate or upload a server certificate in the section 5 8 8 Figure 5 47 Web Server Para...

Page 128: ...ckets accordingly A takeover will happen within approximately 3 seconds as soon as the partner is not reachable anymore checked via multicast packets This may happen when one device is rebooting or th...

Page 129: ...p VID The Virtual Router ID you can theoretically run multiple instances Interface Interface on which VRRP should be performed Virtual gateway address The virtual gateway address formed by the partici...

Page 130: ...used to set it up Parameter Voice Gateway Administration Settings Administrative status Specifies whether the gateway shall be enabled or disabled Call routing Defines who will be responsible for call...

Page 131: ...rt Specifies the agent s listening port SIP user name Specifies the username used in from headers SIP register expires Specifies the registration interval in seconds In case you are running multiple W...

Page 132: ...pported Parameter Voice Gateway Endpoint Types Voice Over Mobile Endpoint for GSM UMTS LTE calls can be used for calls to mobile or landline phones SIP registrar SIP endpoint which can be a client reg...

Page 133: ...s tics and noise pickup Although the echo delay is typically short 16 ms with all headsets the echo return loss char acteristics can vary significantly and are not well known a priori to the handset d...

Page 134: ...ubscriber The subscriber name of the SIP agent Host The IP address of the SIP agent Port The port of the SIP agent Username The username to authenticate at the SIP agent Password The password used for...

Page 135: ...tus information e g number duration of calls per endpoint registration status and so on Using the SDK you can also initiate or accept a call adjust its volume level or do a hangup Anyway for simple sc...

Page 136: ...t must be configured to use the router as its registrar proxy Parameter X Lite Configuration User ID SIP username used in from headers i e subscriber name Domain SIP Domain used in from headers option...

Page 137: ...he following system parameters can be set Parameter System Settings Local hostname The hostname of the system Application area The desired application area which influences the system behaviour such a...

Page 138: ...can be queried over SNMP or CLI GUI Banks to be displayed You can configure the behavior of the status LEDs on the front panel of your device They are usually divided into two banks top bottom and ar...

Page 139: ...r 2 Optionally the address of a second NTP server Sync time from GPS Derive time from first GPS device if enabled Reboot This page can be used to set up a periodic automatic reboot but also to trigger...

Page 140: ...NB3700 User Manual 3 8 Figure 5 53 Regional settings 140...

Page 141: ...n login via HTTP telnet if authentication succeeds Secure authentication required Users can only login via HTTPS ssh Secure authentication preferred Users will be redirected to HTTPS but can sill logi...

Page 142: ...modify or delete existing users here as well Remote Authentication A RADIUS server can be used for authenticating remote users This applies for the Web Manager the WLAN network and other services supp...

Page 143: ...NB3700 User Manual 3 8 Figure 5 55 Remote Authentication 143...

Page 144: ...ures Therefore it s always a good idea to keep a copy of the working configuration Attention In case you perform a major downgrade with a previous release line e g 3 7 0 to 3 6 0 please ensure to alwa...

Page 145: ...to perform a firmware update of a specific module Parameter Module Firmware Update Update operation The update operation method being used You can upload a firmware package download the files from a...

Page 146: ...age zip containing the configuration file and a packed version of other essential files such as certificates in the root directory Manual File Configuration Figure 5 56 Manual File Configuration This...

Page 147: ...NB3700 User Manual 3 8 Figure 5 57 Automatic File Configuration 147...

Page 148: ...RL The URL where the configuration file should be retrieved from supported protocols are HTTP HTTPS TFTP FTP Factory Configuration Figure 5 58 Factory Configuration This menu can be used to reset the...

Page 149: ...the currently running configuration as factory defaults which will reside active even when a factory reset has been initiated e g by your service staff Please ensure that this corresponds to a working...

Page 150: ...em log can be redirected to a syslog server see section 5 8 1 Figure 5 59 Log Viewer Tech Support You can generate and download a tech support file here We strongly recommend pro viding this file when...

Page 151: ...etween hosts This can be achieved by logging onto the box and start a network packet capture by using the tool tcdump We recommend to use the n switch to bypass name resolution e g tcpdump n i lan0 Yo...

Page 152: ...nd WLAN clients Figure 5 61 Keys and certificates The entry pages shows an overview about installed keys and certificates The following sections may appear Type Description Root CA The root Certificat...

Page 153: ...ns Operation Description generate locally Generate key and certificate locally on the box see 5 8 8 for more options upload files Key and certificate will be uploaded We support files in PKCS12 PKCS7...

Page 154: ...ning requests are generated locally the following settings will be take into account Parameter Certificate Configuration Organisation O The certificate owner s organization Department OU The name of t...

Page 155: ...DER or PKCS7 format All files CA certificate certificate and private key can also be uploaded in one stroke by using the container format PKCS12 RSA DSS keys can be converted from OpenSSH or Dropbear...

Page 156: ...ected you are required to erase the certificate first and then start the enrollment process all over again Authorities For SSL client connections as used by SDK functions or when downloading configura...

Page 157: ...license to be present in the system some of them also depend on the mounted modules Please contact us for getting a valid license for available components and we will provide a license file based on...

Page 158: ...or implied To obtain the corresponding open source codes covered by these licenses please contact our technical support at router support netmodule com Acknowledgements This product includes PHP free...

Page 159: ...NB3700 User Manual 3 8 5 9 LOGOUT Please use this menu to log out from the Web Manager 159...

Page 160: ...shell Please note that each CLI session will perform an automatic logout as soon as a certain time of inactivity 10 minutes by default has been reached It can be turned off by the command no autologou...

Page 161: ...the line CTRL t Drag the character before point forward moving point for ward as well if point is at the end of the line then this transposes the two characters before the point ALT t Drag the word b...

Page 162: ...to factory defaults reboot Reboot system shell Run shell command help Print help for command no autologout Turn off auto logout history Show command history exit Exit 6 3 Getting Config Parameters The...

Page 163: ...iguration system System information configuration Configuration information license License information wwan WWAN module status wlan WLAN module status gnss GNSS GPS module status eth Ethernet interfa...

Page 164: ...output 6 7 Sending E Mail or SMS The send command can be used to send a message via E Mail SMS to the specified address or phone number send h Usage send h type dest msg Options type type of message...

Page 165: ...may also run update software latest to install the latest version from our server 6 9 Manage keys and certificates The cert command can be used to manage keys and certificates cert h Usage cert h p p...

Page 166: ...etwork Networking openvpn OpenVPN connections pptp PPTP connections qos QoS daemon smsd SMS daemon snmpd SNMP daemon surveyor Supervision daemon syslog Syslog daemon telnet Telnet server usbipd USB IP...

Page 167: ...g System The reset command can be used to reset the router back to factory defaults reset h Usage reset h 6 13 Rebooting System The reboot command can be used to reboot the router reboot h Usage reboo...

Page 168: ...cliphp status configuration parameter cliphp status 0 Service is disabled cliphp status 1 Service is enabled This section describes the CLI PHP interface for Version 2 It accepts POST and GET requests...

Page 169: ...the format return msg with return values of OK if succeeded and ERROR if failed Any output from the commands will be appended Examples OK status command successful ERROR authentication failed status D...

Page 170: ...usage command set arg0 config key arg1 config value arg2 config key arg3 config value Notes In contrast to the other commands this command requires a set of tuples because of the reserved char i e ar...

Page 171: ...tml usr admin pwd admin01 command reboot reset Run factory reset Key usage command reset Examples http 192 168 1 1 cli php version 2 output html usr admin pwd admin01 command reset update Update syste...

Page 172: ...nternational format such as 123456789 including a leading plus sign which can be encoded with 2B The SMS daemon must be properly configured prior to using that function Examples http 192 168 1 1 cli p...

Page 173: ...192 168 1 1 cli php version 2 output mime usr admin pwd admin01 command send arg0 techsupport arg1 stdout http 192 168 1 1 cli php version 2 output html usr admin pwd admin01 command send arg0 techsup...

Page 174: ...nd thus prevent you from getting too much gray hair In case of support requests please use the form at our support page and submit a detailed description of your problem together with a tech support f...

Page 175: ...ct use of this information This document may contain information about third party products or processes Such third party information is generally out of influence of NetModule and therefore Net Modul...

Page 176: ...application notes firmware upgrades troubleshooting tips press releases or any other concerns NetModule AG Tel 41 31 985 25 10 Meriedweg 11 Fax 41 31 985 25 11 CH 3172 Niederwangen info netmodule com...

Page 177: ...tunnel interface based on TUN TAPx Specifies an OpenVPN tunnel interface based on TAP PPTPx Specifies a PPTP tunnel interface MOBILEIPx Refers to a Mobile IP tunnel interface SIMx Specifies the SIM sl...

Page 178: ...used to program ap plications CLI Command Line Interface a generic interface to query the router or perform system tasks SIM Subscriber Identity Module SMS Short Message Service SSID Service Set Ident...

Page 179: ...er case and may have a different naming Their index starts from zero whereas interfaces seen by the user will be written in capital letters starting from one A 2 System Events ID Event Description 101...

Page 180: ...12 gre up GRE connection came up 413 gre down GRE connection went down 501 system login failed User login failed 502 system login succeeded User login succeeded 503 system logout User logged out 504 s...

Page 181: ...usb storage removed USB storage device has been removed 903 usb eth added USB Ethernet device has been added 904 usb eth removed USB Ethernet device has been removed 905 usb serial added USB serial de...

Page 182: ...ation The factory configuration including default values for any configuration parameter can be derived from the file etc config factory config cfg on the router You may also call cli get f parameter...

Page 183: ...241000 Z ORGANIZATION NetModule AG CONTACT INFO NetModule AG Switzerland DESCRIPTION MIB module which defines the NB router specific entities REVISION 201411241000 Z DESCRIPTION MIB for software relea...

Page 184: ...urrent DESCRIPTION Update the system configuration from the specified URL The URL must be preceded by one of the prefixes tftp ftp http and either point to the update package or to a server directory...

Page 185: ...wanTemperature DisplayString wwanModemIndex OBJECT TYPE SYNTAX Integer32 0 254 MAX ACCESS not accessible STATUS current DESCRIPTION WWAN modem index nbWwanEntry 1 wwanModemName OBJECT TYPE SYNTAX Disp...

Page 186: ...e OBJECT TYPE SYNTAX DisplayString MAX ACCESS read only STATUS current DESCRIPTION The current temperature of the WWAN modem nbWwanEntry 11 NBGnssTable nbGnssTable OBJECT TYPE SYNTAX SEQUENCE OF NBGns...

Page 187: ...CCESS read only STATUS current DESCRIPTION The current number of available satellites for the GNSS device nbGnssEntry 7 NBWlanTable nbWlanTable OBJECT TYPE SYNTAX SEQUENCE OF NBWlanEntry MAX ACCESS no...

Page 188: ...ort IN1 dio 1 dioStatusIn2 OBJECT TYPE SYNTAX INTEGER off 0 on 1 MAX ACCESS read only STATUS current DESCRIPTION The current value of digital I O port IN2 dio 2 dioStatusOut1 OBJECT TYPE SYNTAX INTEGE...

Page 189: ...events 204 dio out1 on NOTIFICATION TYPE STATUS current DESCRIPTION DIO OUT1 turned on events 205 dio out1 off NOTIFICATION TYPE STATUS current DESCRIPTION DIO OUT1 turned off events 206 dio out2 on N...

Page 190: ...YPE STATUS current DESCRIPTION GRE connection came up events 412 gre down NOTIFICATION TYPE STATUS current DESCRIPTION GRE connection went down events 413 system login failed NOTIFICATION TYPE STATUS...

Page 191: ...ON TYPE STATUS current DESCRIPTION Dynamic DNS update failed events 802 usb storage added NOTIFICATION TYPE STATUS current DESCRIPTION USB storage device has been added events 901 usb storage removed...

Page 192: ...IM on Mobile1 email to sms are This script implements a lightweight SMTP server which is able to receive mail and forward them as SMS to a phone number etherwake are This script can be used to wake up...

Page 193: ...ssages from the serial port serial readwrite are This script will write to and read from the serial port serial tcp broadcast are This script reads messages coming from the serial port and forwards th...

Page 194: ...rs a techsupport to a remote FTP server transfer file are This scripts archives a remote file transfer are This scripts stores the latest GNSS positions in a remote FTP file udp msg server are This sc...

Reviews: