background image

 

Part No. 900-345 

Rev. A   April 2004 

SecureBox  

 

SDS2100 

 

User Guide 

Summary of Contents for SecureBox SDS2100

Page 1: ...Part No 900 345 Rev A April 2004 SecureBox SDS2100 User Guide ...

Page 2: ...ows 95 Windows 98 Windows 2000 and Windows NT are trademarks of Microsoft Corp Netscape is a trademark of Netscape Communications Corporation Contacts Lantronix Corporate Headquarters 15353 Barranca Parkway Irvine CA 92618 USA Phone 949 453 3990 Fax 949 453 3995 Technical Support Phone 800 422 7044 or 949 453 7198 Fax 949 450 7226 Online www lantronix com support Email support lantronix com Sales ...

Page 3: ... authority to operate this device The information in this guide may change without notice The manufacturer assumes no responsibility for any errors that may appear in this guide Note Export Control Classification Number 5A002 License exception ENC The following export agreement is required for encryption I agree that I will not export or re export this product or firmware to a national resident of...

Page 4: ...96 Conducted Immunity Test IEC61000 4 8 1993 Magnetic Field Test IEC61000 4 11 1994 Voltage Dips Interrupts Test L V D Directive 73 23 EEC Supplementary Information This Class A digital apparatus complies with Canadian ICES 003 CSA and has been verified as being compliant within the Class A limits of the FCC Radio Frequency Device Rules FCC Title 47 Part 15 Subpart B CLASS A measured to CISPR 22 1...

Page 5: ...l ship the replacement media to the customer In no event will Lantronix be responsible to the user in contract in tort including negligence strict liability or otherwise for any special indirect incidental or consequential damage or loss of equipment plant or power system cost of capital loss of profits or revenues cost of replacement power additional expenses in the use of existing software hardw...

Page 6: ...rmation Label ____________________________________________ 12 Technical Specifications _____________________________________________ 13 2 Getting Started _______________________________________________ 14 Addresses and Port Number __________________________________________ 14 Ethernet MAC Address _________________________________________________ 14 Internet Protocol IP Address ____________________...

Page 7: ...rt ___________________________________________________________ 37 DisConnMode __________________________________________________________ 37 Flush Mode Buffer Flushing ______________________________________________ 38 Pack Control ___________________________________________________________ 38 DisConnTime Inactivity Timeout ___________________________________________ 39 Send Characters _____________...

Page 8: ...__________________________________ 51 Technical Support __________________________________________________ 51 Monitor Mode______________________________________________________ 55 Via the Serial Port ______________________________________________________ 55 Via the Network ________________________________________________________ 55 Monitor Mode Commands ____________________________________________...

Page 9: ...S government and government contractor s networks Security Alarms Access Control Devices Fire Control Panels Time Attendance Clocks and Terminals ATM Machines Data Collection Devices RFID readers Universal Power Supply UPS Management Units Telecommunications Equipment Data Display Devices Protocol Support The SDS uses the Internet Protocol IP for network communications and the Transmission Control...

Page 10: ... The SDS2100 has two male DB9 DTE serial ports that support RS 232 serial standards up to 115 Kbps Figure 1 1 Serial Interface Serial Connector Pinouts The unit s Male DB9 connector provides an RS 232C interface as would be found on most modern computers The default serial port settings are 9600 baud 8 bits no parity 1 stop bit no flow control Figure 1 2 DB9 Male RS232 Serial DTE Connector Male DB...

Page 11: ...outs Figure 1 4 RJ45 Ethernet Connector LEDs The SDS2100 contains the following LEDs Power 10 Mbps Link Activity green 100 Mbps Link Activity green Diagnostics red Status Channel 1 green Status Channel 2 green Simultaneously lit red and green LEDs mean something is wrong If the red LED is lit or blinking count the number of times the green LED blinks between its pauses The following table explains...

Page 12: ...ed and status blinking green 2 blinks RAM error 4 blinks EEPROM checksum error 5 blinks Duplicate IP address on network Diagnostic blinking red and status blinking green 5 blinks No DHCP response Status steady green Serial port not connected to network Status blinking green Serial port connected to network Product Information Label The product information label on the underside of the unit contain...

Page 13: ...face 10 100 RJ45 Ethernet Power Supply External adapter included 120VAC USA 100 240 VAC Universal with regional connectors Power Input 9 30 VDC or 9 24 VAC 2W maximum Dimensions SDS2100 Height 2 3 cm 0 9 in Width 7 3 cm 2 87 in Depth 9 5 cm 3 74 in Weight SDS2100 0 35 Kg 0 8 lbs Temperature Operating range 5 to 50 C 41 to 122 F Storage range 40 to 66 C 40 to 151 F Relative Humidity Operating 10 to...

Page 14: ...dress 00 20 4A 14 01 18 or 00 20 4A 14 01 18 Internet Protocol IP Address Every device connected to an IP network must have a unique IP address This address is used to reference the specific unit Port Number Every TCP connection and every UDP datagram is defined by a destination IP address and a port number For example a Telnet application commonly uses port number 23 A port number is similar to a...

Page 15: ...in order Refer to the numbers in the previous figure 1 Connect a serial device to your unit See the Introduction for more information about what kinds of device attachments the unit supports 2 Connect an Ethernet cable to the 10 100 port 3 Supply power to your unit using the power supply that was included in the packaging Note The required input voltage is 9 30 VDC or 9 24 VAC 2 W maximum 4 Supply...

Page 16: ...In most installations a fixed IP address is desirable The systems administrator generally provides the IP address Obtain the following information before starting to set up your unit IP Address ___ ___ ___ ___ Subnet Mask ___ ___ ___ ___ Gateway ___ ___ ___ ___ DHCP The unit ships with a default IP address of 0 0 0 0 which automatically enables DHCP Provided a DHCP server exists on the network it ...

Page 17: ...oots itself After reboot the unit sends out another ARP request to see if the selected address is in use and so on AutoIP is not intended to replace DHCP The unit will continue to look for a DHCP server on the network If a DHCP server is found the unit will switch to the DHCP server provided address and reboot Note If a DHCP server is found but it denies the request for an IP address the unit does...

Page 18: ...etwork Class 1 Click the Start button on the Task Bar and select Programs Æ Lantronix Æ Device Installer Æ Device Installer The DeviceInstaller window displays Figure 2 3 DeviceInstaller Window 2 Click the Assign IP icon The Assign IP Address window displays 18 ...

Page 19: ... device The following Assign IP Address window appears Figure 2 5 Assign IP Address Window Assignment Method 4 Select Assign a specific IP address to assign a static IP address to the device or select Obtain an IP address automatically to enable BOOTP DHCP or Auto IP on the device 5 Click Next The following Assign IP Address window appears 19 ...

Page 20: ...Enter the IP address subnet mask and gateway being assigned to the device Enter this information in XXX XXX XXX XXX format 7 Click Next The following Assign IP Address window appears Figure 2 7 Assign IP Address Window Assignment 8 Click the Assign button to finalize the IP assignment 20 ...

Page 21: ... Device Management Window 1 Do one of the following Note To assign Expert settings and Security settings you must use the Setup Mode window in a Telnet session To configure the unit via a Web browser click the Web icon The Lantronix WEB Manager window displays in your browser To configure the unit via a Telnet session click the Telnet icon The Setup Mode window displays 2 Continue with the appropr...

Page 22: ...IP address on your network to build a new entry in the ARP table the IP address must be a host other than the machine on which you are working Once there is at least one additional entry in the ARP table use the following command to ARP an IP address to the unit Figure 2 10 ARP on Windows arp s 191 12 3 77 00 20 4a xx xx xx 3 Open a Telnet connection to port 1 The connection will fail quickly but ...

Page 23: ... Setup Mode cycle the unit s power power off and back on After power up the self test begins and the red Diagnostic LED starts blinking You have one second to enter three lowercase x characters Note The easiest way to enter Setup Mode is to hold down the x key at the terminal or emulation while powering up the unit 3 Select 0 Server Configuration and follow the prompts until you get to IP address ...

Page 24: ...asiest and preferred method Use a Telnet connection to configure the unit over the network Use a terminal or terminal emulation program to access the serial port locally The unit s configuration is stored in nonvolatile memory NVRam and is retained without power You can change the configuration at any time The unit performs a reset after the configuration has been changed and stored Configuring vi...

Page 25: ...figure the SDS2100 as shown in Figure 3 3 Serial cabling lets you view pinouts for the SDS serial port View SDS Configuration Tutorials provide step by step instructions for configuring encryption serial tunneling and the Com Port Redirector Technical Support lets you download the latest firmware for your SDS and view documentation 25 ...

Page 26: ...nfiguration parameters later in this chapter Note The sequence of parameters explained and examples shown later in this chapter correspond to the Setup Mode window rather than to the WEB Manager sub pages 2 When you are finished click the Update Settings button to save your settings For example to enter server properties 1 Click the Server Properties button The Server Properties section of the Web...

Page 27: ...sword is required to access the Setup Mode window via a serial connection 4 Click the Update Settings button Configuring via the Setup Mode Window Using a Telnet Connection To configure the unit over the network establish a Telnet connection to port 9999 Note You can also use the Telnet to Device icon on the DeviceInstaller Device Management window to establish the connection 1 From the Windows St...

Page 28: ...de window displays To remain in Setup Mode you must press Enter within 5 seconds Figure 3 6 Setup Mode Window 3 Select an option on the menu by entering the number of the option in the Your choice field and pressing Enter 4 To enter a value for a parameter type the value and press Enter or to confirm a current value just press Enter 28 ...

Page 29: ...ons save the new configurations option 9 The unit will reboot Using the Serial Ports For local configuration a terminal or a PC running a terminal emulation program can be connected to the unit s serial port channel 1 The terminal or emulation should be configured for 9600 baud 8 bit no parity 1 stop bit and no flow control 1 Cycle the unit s power power off and back on After power up the self tes...

Page 30: ...alue in your network See Methods of Assigning the IP Address for more information on IP addressing Set Gateway IP Address The gateway address or router allows communication to other LAN segments The gateway address should be the IP address of the router connected to the same LAN segment as the unit The gateway address must be within the local network Netmask A netmask defines the number of bits ta...

Page 31: ...ecurity Settings for Telnet access only Note No password is required to access the Setup Mode window via a serial connection DHCP Naming A DHCP name is a unique identifier used for managing multiple DHCP hosts on a network Your unit ships with a default DHCP name of Cxxxxxx where xxxxxx are the last six digits of the Mac address You can change the DHCP name up to eight characters when configuring ...

Page 32: ...0 9600 default 19200 38400 57600 and 115200 bits per second I F Interface Mode The Interface I F Mode is a bit coded byte that you enter in hexadecimal notation Note If you do not want to convert the binary numbers to hexadecimals yourself look up the values in Table 6 6 Interface Mode Options in the Binary to Hexadecimal chapter Table 3 3 Interface Mode Options I F Mode Option Bit 7 6 5 4 3 2 1 0...

Page 33: ...on 7 Echo 80 Web server Warning We recommend that you not use the reserved port numbers for this setting as incorrect operation may result The port number functions as the TCP UDP source port number for outgoing packets Packets sent to the unit with this port number are received to this channel The port number selected is the Incoming TCP UDP port and Outgoing TCP UDP source port Use Port 0 when y...

Page 34: ...n When you use manual connection you are not required to enter the entire IP address if the IP is already configured as the remote IP address in the unit For example if the remote IP address already configured in the unit is 129 1 2 3 then an example command string would be C3 7 This would connect to 129 1 2 3 and port 7 You may also use a different ending for the connection string For example C50...

Page 35: ... hostlist option Figure 3 11 Hostlist Option To use this ability follow these steps 1 To enable the hostlist enter a Connect Mode of 0x20 2X The menu shows you a list of current entries already defined in the product 2 To delete modify or add an entry select Yes If you enter an IP address of 0 0 0 0 that entry and all others after it are deleted 3 After completing the hostlist repeat the previous ...

Page 36: ...red in command mode it does not mean to echo data that is transferred Quiet Mode no echo refers to the modem not sending an answer to the commands received or displaying what was typed To disconnect a connection using Modem Mode commands There must be a 1 second guardtime no data traffic before sending There must not be a break longer than 1 second between s There must be another 1 second guardtim...

Page 37: ...V1 compound commands such as ATE0V1 are not recognized All other AT commands with Modem Mode set to full verbose acknowledge with an OK but no action is taken Remote IP Address This is the destination IP address used with an outgoing connection Remote Port The remote TCP port number must be set for the unit to make outgoing connections This parameter defines the port number on the target host to w...

Page 38: ...network buffers with connection startup and disconnect You can also select between two different packing algorithms Note If you do not want to convert the binary numbers to hexadecimals yourself look up the values in Table 6 5 Flush Mode Options in the Binary to Hexadecimal chapter Table 3 10 Flush Mode Options Function Bit 7 6 5 4 3 2 1 0 Input Buffer Serial to Network Clear with active connectio...

Page 39: ...RC Checksum or other trailing characters follow the end of sequence character this option helps to adapt frame transmission to the frame boundary Send Characters If 2 Byte Send Character Sequence is enabled the unit interprets the sendchars as a 2 byte sequence if not set they are interpreted independently If Send Immediately After Send Characters is not set any characters already in the serial bu...

Page 40: ...e option is enabled in Disconnect Mode see DisConnMode above If this option is enabled you can use the terminal name for the Telnet terminal type Enter only one name If the terminal type option is enabled the unit also reacts to the EOR end of record and binary options which can be used for applications like terminal emulation to IBM hosts Channel Port Password This parameter appears only if the c...

Page 41: ...Settings Note You can change these settings via Telnet or serial connections only not on the WEB Manager We recommend that you set security over the dedicated network or over the serial setup If you set parameters over the network Telnet 9999 someone else could capture these settings Figure 3 13 Security Settings Disable SNMP This setting allows you to disable the SNMP protocol on the unit prevent...

Page 42: ...Port 80 will be closed Disable ECHO Ports This setting disables the use of the echo server that is built into the unit The option disables support for UDP and TCP connections to port 7 Enable Enhanced Password This setting defaults to the N option which allows you to set a 4 character password that protects the Configuration Menu via Telnet and Web pages The Y Yes option allows you to set an exten...

Page 43: ...length enter 48 hexadecimal characters For a 256 bit key length enter 64 hexadecimal characters 8 Continue pressing Enter until you return to the Change Setup menu 9 At the Change Setup menu select option 9 to save and exit Encryption only applies to the port selected for data tunneling default 10001 regardless of whether you are using TCP or UDP Generally one of two situations applies Encrypted S...

Page 44: ...ial port to the factory default settings The server configurations IP address information remain unchanged Exit Configuration Mode Select 8 to exit the configuration mode without saving any changes or rebooting OR select 9 to reboot and save all changes All values are stored in nonvolatile memory 44 ...

Page 45: ...serial port You can also update the unit s internal Web interface CBXW COB via TFTP or DeviceInstaller Via DeviceInstaller After downloading the firmware to your computer you can use DeviceInstaller to install it If you haven t already installed DeviceInstaller from the product CD see Install the DeviceInstaller 1 Download the updated firmware files from www lantronix com or ftp ftp lantronix com ...

Page 46: ...located by DeviceInstaller highlight the device in the device list and click the Upgrade button which displays after you select the device Select a custom installation by specifying the individual files and clicking Next Figure 4 3 Device Upgrade Wizard Window 1 5 Click the Browse button to select the location of the firmware file being loaded then click Next 46 ...

Page 47: ... firmware files are located To download new firmware using a TFTP client 1 Use a TFTP client to send a binary file SDS ROM to the unit to upgrade the unit s internal operational code and cbx cob to upgrade its internal Web interface Note TFTP requires the ROM binary version of the unit s internal operational code 2 Make sure the Put and Binary options at the top of the window are selected 3 Enter ...

Page 48: ...network 1 Enter the host unit s Monitor Mode see Monitor Mode in the Troubleshooting chapter 2 Send the firmware to the receiving unit using the SF command where x x x x is the receiving unit s IP address Figure 4 6 Sending Firmware to Another Unit SF x x x x The receiving unit performs a power reset after the firmware has been loaded and stored Note You can only update your unit s internal Web in...

Page 49: ...de in the Troubleshooting chapter 2 Download the firmware to the unit using the DL command 3 Select Send Text File and select the SD21 HEX file to be downloaded The downloaded file must be the HEX ASCII version Note For SDS1100 select the SD11 HEX file to be downloaded 4 After the final record is received the unit checks the integrity of the firmware image before programming the new firmware in th...

Page 50: ...SDS2100 User Guide 4 Updating Firmware 50 ...

Page 51: ...e Technical Support If you are experiencing an error that is not described in this chapter or if you are unable If you are experiencing an error that is not described in this chapter or if you are unable to fix the error you may Check our online knowledge base at www lantronix com support com E mail us at support lantronix com Call us at 800 422 7044 Domestic 949 453 7198 International 949 450 722...

Page 52: ...he ARP method the Press Enter to go into Setup Mode error described below displayed Now when you Telnet to the SDS the connection fails When you Telnet into port 1 on the SDS you are only assigning a temporary IP address When you Telnet into port 9999 and do not press Enter quickly the SDS will reboot causing it to lose the IP address Telnet back into Port 1 Wait for it to fail then Telnet to port...

Page 53: ...ged or the unit is not plugged into power properly Try plugging the SDS into another outlet If this does not fix the problem contact your dealer or Lantronix Technical Support for a replacement The SDS2100 will not power up properly and the LEDs are flashing Various Consult the LEDs section in the Introduction chapter or the Quick Start for the LED flashing sequence patterns Call Lantronix Technic...

Page 54: ... using the correct serial cable and the SDS should be set up correctly but you are not communicating with your device attached to the SDS across the network If you are sure that the serial cable is correct then you may not be connecting to the correct socket of the SDS Another possibility is that the SDS is not set up correctly to make a good socket connection to the network You can check to see w...

Page 55: ...red Monitor Mode Via the Network To enter Monitor Mode using a Telnet connection 1 First establish a Telnet session The following message displays Figure 5 1 Entering Monitor Mode Via the Network Lantronix Secure Device Server MAC address 00204A0250AF Software Version 05 6b3 040311 SDS2100 AES library version 1 8 2 1 Press Enter to go into Setup Mode _ 2 Type M upper case A 0 prompt indicates that...

Page 56: ...and outgoing TCP connections NC Network Connection Shows the unit s IP configuration RS Reset Resets the unit s power SI x x x x n n n n Send Set IP Address Remotely assigns an IP address to a unit where x x x x is the new IP address and n n n n is the remote unit s serial number written twice QU Quit Exits diagnostics mode G0 G1 GE GF Get configuration from memory page Gets a memory page of confi...

Page 57: ...on options in hexadecimal notation The following tables are included Binary to Hexadecimal Conversions Connect Mode Options Disconnect Mode Options Flush Mode Buffer Flushing Options Interface Mode Options Pack Control Options Converting Binary to Hexadecimal Hexadecimal digits have values ranging from 0 to F which are represented as 0 9 A for 10 B for 11 etc To convert a binary value for example ...

Page 58: ...tlist Hex Never None quiet No active startup N A Never None quiet Any character 1 Never None quiet Active DSR 2 Never None quiet CR 0x0D 3 Never None quiet Manual connection 4 Never None quiet Autostart 5 Never None quiet UDP C Never Character No active startup 10 Never Character Any character 11 Never Character Active DSR 12 Never Character CR 0x0D 13 Never Character Manual connection 14 Never Ch...

Page 59: ...rt D5 Unconditionally Character UDP DC Never None quiet No active startup Hostlist N A Never None quiet Any character Hostlist 21 Never None quiet Active DSR Hostlist 22 Never None quiet CR 0x0D Hostlist 23 Never None quiet Manual connection Hostlist N A Never None quiet Autostart Hostlist 25 Never None quiet UDP Hostlist N A Never Character No active startup Hostlist N A Never Character Any chara...

Page 60: ...SR Hostlist E2 Unconditionally None quiet CR 0x0D Hostlist E3 Unconditionally None quiet Manual connection Hostlist N A Unconditionally None quiet Autostart Hostlist E5 Unconditionally None quiet UDP Hostlist N A Unconditionally Character No active startup Hostlist N A Unconditionally Character Any character Hostlist F1 Unconditionally Character Active DSR Hostlist F2 Unconditionally Character CR ...

Page 61: ...connect State LED Off with Connection Disconnect with EOT D Hex Enable 0 Enable Enable 10 Enable Enable 20 Enable Enable Enable 30 Enable Enable 40 Enable Enable Enable 50 Enable Enable Enable 60 Enable Enable Enable Enable 70 Enable Enable 80 Enable Enable Enable 90 Enable Enable Enable A0 Enable Enable Enable Enable B0 Enable Enable Enable C0 Enable Enable Enable Enable D0 Enable Enable Enable E...

Page 62: ...e 88 Enable Enable Disable 98 Enable Disable Enable A8 Enable Enable Disable Enable B8 Enable Enable Disable C8 Enable Enable Enable Disable D8 Enable Enable Disable Enable E8 Enable Enable Enable Disable Enable F8 Disable Enable 9 Enable Disable Enable 19 Disable Enable Enable 29 Enable Disable Enable Enable 39 Enable Disable Enable 49 Enable Enable Disable Enable 59 Enable Disable Enable Enable ...

Page 63: ...Active connection Disconnect Enable D0 Passive connection Disconnect Enable E0 Active connection Passive connection Disconnect Enable F0 Active connection 1 Active connection Active connection 11 Passive connection Active connection 21 Active connection Passive connection Active connection 31 Disconnect Active connection 41 Active connection Disconnect Active connection 51 Passive connection Disco...

Page 64: ...tive connection Passive connection Passive connection Enable B2 Disconnect Passive connection Enable C2 Active connection Disconnect Passive connection Enable D2 Passive connection Disconnect Passive connection Enable E2 Active connection Passive connection Disconnect Passive connection Enable F2 Active connection Passive connection 3 Active connection Active connection Passive connection 13 Passi...

Page 65: ...ct Disconnect 54 Passive connection Disconnect Disconnect 64 Active connection Passive connection Disconnect Disconnect 74 Disconnect Enable 84 Active connection Disconnect Enable 94 Passive connection Disconnect Enable A4 Active connection Passive connection Disconnect Enable B4 Disconnect Disconnect Enable C4 Active connection Disconnect Disconnect Enable D4 Passive connection Disconnect Disconn...

Page 66: ...onnection Disconnect 26 Active connection Passive connection Passive connection Disconnect 36 Disconnect Passive connection Disconnect 46 Active connection Disconnect Passive connection Disconnect 56 Passive connection Disconnect Passive connection Disconnect 66 Active connection Passive connection Disconnect Passive connection Disconnect 76 Passive connection Disconnect Enable 86 Active connectio...

Page 67: ...connection Passive connection Disconnect Active connection Passive connection Disconnect 77 Active connection Passive connection Disconnect Enable 87 Active connection Active connection Passive connection Disconnect Enable 97 Passive connection Active connection Passive connection Disconnect Enable A7 Active connection Passive connection Active connection Passive connection Disconnect Enable B7 Di...

Page 68: ...ace Mode Options Interface Bits Parity Stop Bits Hex RS 232C 7 No 1 48 RS 232C 7 No 2 C8 RS 232C 7 Even 1 78 RS 232C 7 Even 2 F8 RS 232C 7 Odd 1 58 RS 232C 7 Odd 2 D8 RS 232C 8 No 1 4C RS 232C 8 No 2 CC RS 232C 8 Even 1 7C RS 232C 8 Even 2 FC RS 232C 8 Odd 1 5C RS 232C 8 Odd 2 DC 68 ...

Page 69: ...2 Byte Sequence 1 12ms 14 2 Byte Sequence 1 52ms 15 2 Byte Sequence 1 250ms 16 2 Byte Sequence 1 5sec 17 2 Byte Sequence 2 12ms 18 2 Byte Sequence 2 52ms 19 2 Byte Sequence 2 250ms 1A 2 Byte Sequence 2 5sec 1B 1 Byte Sequence No 12ms Yes 20 1 Byte Sequence No 52ms Yes 21 1 Byte Sequence No 250ms Yes 22 1 Byte Sequence No 5sec Yes 23 1 Byte Sequence 1 12ms Yes 24 1 Byte Sequence 1 52ms Yes 25 1 Byt...

Page 70: ...mal Sendcharacter Defined by a Trailing Characters Idle Time Force Transmit Send Immediately after Sendcharacter Hex 2 Byte Sequence 2 12ms Yes 38 2 Byte Sequence 2 52ms Yes 39 2 Byte Sequence 2 250ms Yes 3A 2 Byte Sequence 2 5sec Yes 3B 70 ...

Reviews: