manualshive.com logo in svg
background image

Pepwave Surf SOHO

User Manual

Pepwave Product:

Surf SOHO

Pepwave Firmware 8.1.3
August 2021

C

OPYRIGHT

& T

RADEMARKS

Specifications are subject to change without notice.  Copyright © 2020 Pepwave Ltd. All Rights Reserved.  Pepwave and the Pepwave
logo are trademarks of Pepwave Ltd. Other brands or products mentioned may be trademarks or registered trademarks of their
respective owners.

Содержание Pepwave Surf SOHO

Страница 1: ...2021 COPYRIGHT TRADEMARKS Specifications are subject to change without notice Copyright 2020 Pepwave Ltd All Rights Reserved Pepwave and the Pepwave logo are trademarks of Pepwave Ltd Other brands or products mentioned may be trademarks or registered trademarks of their respective owners ...

Страница 2: ...odem 13 Built In Remote User VPN Support 13 DPI Engine 13 Wi Fi Air Monitoring 14 SP Default Configuration 14 Installation 15 Preparation 15 Constructing the Network 15 Connecting to the Web Admin Interface 15 SpeedFusion Cloud 19 Activate SpeedFusion Cloud Service 19 Enable SpeedFusion Cloud 21 Connect Clients to Cloud 29 Link Wi Fi to Cloud 30 Optimize Cloud Application 32 Configuring the LAN In...

Страница 3: ... ALL traffic 56 Outbound Policy Management 57 Port Forwarding 60 UPnP NAT PMP Settings 62 NAT Mappings 63 QoS 65 Bandwidth Control 65 Application Prioritization 65 Firewall 67 Outbound and Inbound Firewall Rules 68 Intrusion Detection and DoS Prevention 72 Content Blocking 73 Routing Protocols 74 OSPF RIPv2 74 BGP 77 Remote User Access 80 L2TP with IPsec 80 OpenVPN 80 PPTP 81 Authentication Method...

Страница 4: ...ule 113 Email Notification 114 Event Log 117 SNMP 117 InControl 120 Configuration 120 Feature Add ons 121 Reboot 121 Tools 121 Ping 122 Traceroute Test 123 Wake on LAN 123 WAN Analysis 124 Status 126 Device 127 Active Sessions 129 Client List 131 OSPF RIPv2 132 BGP 132 PepVPN Status 132 Event Log 135 WAN Quality 136 Usage Reports 137 Appendix A Restoration of Factory Defaults 141 https www peplink...

Страница 5: ...Appendix B Declaration 141 https www peplink com 5 Copyright 2021 Peplink ...

Страница 6: ...HO up to Ethernet and Cellular connections and it will automatically fail over from one to the other as needed That way you can stay connected even when a connection breaks This manual covers setting up a Surf SOHO router and provides an introduction to their features and usage Tips Want to know more about Pepwave routers Visit our YouTube Channel for a video introduction https www peplink com 6 C...

Страница 7: ...yper Text Transfer Protocol ICMP Internet Control Message Protocol IP Internet Protocol LAN Local Area Network MAC Address Media Access Control Address MTU Maximum Transmission Unit MSS Maximum Segment Size NAT Network Address Translation PPPoE Point to Point Protocol over Ethernet QoS Quality of Service SNMP Simple Network Management Protocol TCP Transmission Control Protocol UDP User Datagram Pr...

Страница 8: ...WAN Ethernet WAN connection in full half duplex Static IP support for PPPoE USB mobile connection s Wi Fi WAN connection Network address translation NAT port address translation PAT Inbound and outbound NAT mapping IPsec NAT T and PPTP packet pass through Intelligent Failover MAC address clone and passthrough Customizable MTU and MSS values WAN connection health check Dynamic DNS Ping DNS lookup a...

Страница 9: ...dth usage control and monitoring on group and user level Application prioritization for custom protocols and DSL cable optimization Other Supported Features User friendly web based administration interface HTTP and HTTPS support for web admin interface Configurable web administration port and administrator password Firmware upgrades configuration backups ping and traceroute via web admin interface...

Страница 10: ...Pepwave Surf SOHO Router Overview Panel Appearance https www peplink com 10 Copyright 2021 Peplink ...

Страница 11: ...1 25 Router Throughput 120Mbps Number of PPTP VPN Users 3 Number of PPTP VPN Users 2 Power Input DC Jack 10V 24VDC AC Adapter AC Input 100V 240V DC Output 12V 1 5A Power Consumption 26W max with USB WAN 22W max without USB WAN Dimensions 9 17 x 5 6 x 1 18 inch 233 x 142 x 30 mm Weight 0 86 pounds 388 grams Operating Temperature 14 to 113 F 10 to 45 C Humidity 15 95 non condensing Certifications FC...

Страница 12: ...etwork Status OFF System initializing Red Booting up or busy Green Ready state LAN and Ethernet WAN Ports Green LED ON 1000 Mbps OFF 10 Mbps 100 Mbps or port is not connected Orange LED ON Port is being connected Blinking Data is being transferred OFF No data is being transferred or port is not connected Port type Auto MDI MDI X ports Wi Fi Signal Off No connection Signal strength Wi Fi signal str...

Страница 13: ...ithout making any changes to your network For any reason your Peplink router looses power the LAN Bypass will safely and automatically bypass the Peplink router to resume your original network connection QoS Clearer VoIP VoIP and videoconferencing are highly sensitive to latency With QoS Peplink routers can detect VoIP traffic and assign it the highest priority giving you crystal clear calls https...

Страница 14: ...egacy devices can also connect using PPTP Click here for the full instructions on setting up L2TP with IPsec Click here for the full instructions on setting up OpenVPN connections DPI Engine The DPI report written in the updated KB article will show further information on InControl2 through breaking down application categories into subcategories sscs https forum peplink com t updated ic2 deep pack...

Страница 15: ...his feature go to https Device s IP cgi bin MANGA support cgi SP Default Configuration The SP Default Configuration feature written in the updated KB article allows for the provisioning of custom made settings a k a InControl2 configuration via the Ethernet LAN port and is ideal for those wanting to do a bulk deployment of many Peplink devices Note If you would like to use this feature please cont...

Страница 16: ...cable connect a computer to one of the LAN ports on the Pepwave router Repeat with different cables for up to 4 computers to be connected 2 With another Ethernet cable or a USB modem Wi Fi antenna connect to one of the WAN ports on the Pepwave router Repeat the same procedure for other WAN ports Connect the power adapter to the power connector on the rear panel of the Pepwave router and then plug ...

Страница 17: ...e first successful logon Password requirements are A minimum of 10 lower AND upper case characters including at least 1 number When HTTP is selected the URL will be redirected to HTTPS by default https www peplink com 17 Copyright 2021 Peplink ...

Страница 18: ...login the Dashboard of the web admin interface will be displayed The Dashboard shows current WAN LAN and Wi Fi AP statuses Here you can change WAN connection priority and https www peplink com 18 Copyright 2021 Peplink ...

Страница 19: ...ware version CPU Load throughput and uptime Important Note Configuration changes e g WAN LAN admin settings etc will take effect only after clicking the Save button at the bottom of each page The Apply Changes button causes the changes to be saved and applied https www peplink com 19 Copyright 2021 Peplink ...

Страница 20: ...ud is supported in firmware version 8 1 0 and above SpeedFusion Cloud is a subscription basis SpeedFusion Cloud license can be purchased at https store peplink com Cloud Solutions SpeedFusion Cloud Service Activate SpeedFusion Cloud Service You are entitled to a 30 days free period with 100GB of SpeedFusion usage upon activation of the SpeedFusion Cloud service This offer is limited to once per de...

Страница 21: ...sion Cloud service Via Free 30 days Trial or Via Care Plans that you would like to activate Next register or login to your account Select the devices that you wish to activate SpeedFusion Cloud on and Click ACTIVATE https www peplink com 21 Copyright 2021 Peplink ...

Страница 22: ... the license key into the window and click on Activate once you have received the license key Enable SpeedFusion Cloud Enable SpeedFusion Cloud from SpeedFusion Cloud Choose Cloud Location https www peplink com 22 Copyright 2021 Peplink ...

Страница 23: ...Choose Automatic Click on the green tick button to confirm the change Click on Apply Changes to save the change https www peplink com 23 Copyright 2021 Peplink ...

Страница 24: ...https www peplink com 24 Copyright 2021 Peplink ...

Страница 25: ...By default the router will build a SpeedFusion tunnel to the SpeedFusion Cloud https www peplink com 25 Copyright 2021 Peplink ...

Страница 26: ... or VOIP a WAN Smoothing sub tunnel can be created Navigate to Speedfusion Cloud Choose a cloud location SFC A Speedfusion tunnel configuration window will pop out Click on the sign to create the WAN Smoothing sub tunnel https www peplink com 26 Copyright 2021 Peplink ...

Страница 27: ...https www peplink com 27 Copyright 2021 Peplink ...

Страница 28: ...Click on Save and Apply Changes to save the configuration Now the router has 2 Speedfusion tunnels to the Speedfusion Cloud https www peplink com 28 Copyright 2021 Peplink ...

Страница 29: ...https www peplink com 29 Copyright 2021 Peplink ...

Страница 30: ... outbound policy to steer the internet traffic to go into Speedfusion Cloud Please go to Advanced Outbound Policy click on Add Rule to create a new outbound policy https www peplink com 30 Copyright 2021 Peplink ...

Страница 31: ...sion Cloud provides a convenient way to route the LAN client to the cloud From SpeedFusion Cloud Connect Clients to Cloud Choose a client from the drop down list Click Save Apply Changes https www peplink com 31 Copyright 2021 Peplink ...

Страница 32: ...Cloud provides a convenient way to route the Wi Fi client to the cloud from SpeedFusion Cloud Link Wi Fi to Cloud This option is available for Balance 20X Balance 30 Pro and Balance One https www peplink com 32 Copyright 2021 Peplink ...

Страница 33: ...d The new SSID will inherit all settings from one of the existing SSIDs including the Security Policy Then click Save follow by Apply Changes SpeedFusion Cloud SSID will be shown on Dashboard https www peplink com 33 Copyright 2021 Peplink ...

Страница 34: ...sed on the application Go to SpeedFusion Cloud Optimize Cloud Application Select a Cloud application to route through SpeedFusion Cloud from the drop down list Click Save Apply Changes Click the to remove a selected Cloud application to route through SpeedFusion Cloud https www peplink com 34 Copyright 2021 Peplink ...

Страница 35: ...t the VLAN is used in other settings and cannot be deleted You can find which settings are using the VLAN by hovering over the grey X Alternatively a red X means that there are no settings using the VLAN You can delete that VLAN by clicking the red X Clicking any of the existing LAN interfaces or creating a new one will show the following IP Settings IP Address The IP address and subnet mask of th...

Страница 36: ...nnectivity between them and this local LAN Spanning Tree Protocol Click the box will enable STP for this layer 2 profile bridge Override IP Address when bridge connected Select Do not override if the LAN IP address and local DHCP server should remain unchanged after the Layer 2 PepVPN is up If you choose to override IP address when the VPN is connected the device will not act as a router and most ...

Страница 37: ...t Extended DHCP Option In addition to standard DHCP options e g DNS server address gateway address subnet mask you can specify the value of additional extended DHCP options as defined in RFC 2132 With these extended options enabled you can pass additional configuration information to LAN hosts To define an extended DHCP option click the Add button choose the option to define and enter its value Fo...

Страница 38: ...o circuit ID and Remote ID in option 82 DHCP Relay Logging Check this box to log DHCP relay activity Drop In Mode Drop in mode or transparent bridging mode eases the installation of the Surf SOHO on a live network between the firewall and router such that changes to the settings of existing equipment are not required The following diagram illustrates drop in mode setup Check the box Enable to enab...

Страница 39: ... such that no configuration changes are required on existing equipment Check the box to enable the drop in mode feature WAN for Drop In Mode Select the WAN port to be used for drop in mode If WAN is selected the high availability feature will be disabled automatically Shared Drop In IPA When this option is enabled the passthrough IP address will be used to connect to WAN hosts email notification r...

Страница 40: ...subnet mask and gateway address The address and subnet mask values are in w x y z format The local LAN subnet and subnets behind the LAN will be advertised to the VPN Remote routes sent over the VPN will also be accepted Any VPN member will be able to route to the local subnets Press to create a new route Press to remove a route Entries in this list will allow traffic to route to a different subne...

Страница 41: ...n the option is enabled queried DNS replies will be cached until the records TTL has been reached This feature can improve DNS response time by storing all received DNS results for faster DNS lookup However it cannot return the most updated result for frequently updated DNS records By default DNS Caching is disabled Include Google Public DNS Servers When this option is enabled the DNS proxy server...

Страница 42: ...rs If all of the selected connections are down queries will be forwarded to all resolvers on healthy WAN connections A Advanced feature please click the button on the top right hand corner to activate Port Settings To configure port settings navigate to Network LAN Port Settings On this screen you can enable specific ports name the LAN ports as well as determine the speed of the LAN ports LAN Phys...

Страница 43: ...ding the left mouse button move it the Disabled row and drop it by releasing the mouse button You can also set priorities on the Dashboard Click the Details button in the corresponding row to modify the connection setting WAN Quality Monitoring This setting advice how WAN Quality information is being gathered By default WAN Quality information will always be collected automatically for all WAN con...

Страница 44: ...down menu to apply a time schedule to this interface only visible if Schedules have been created in System Schedule Connection Method There are five possible connection methods for Ethernet WAN DHCP Static IP PPPoE L2TP GRE The connection method and details are determined by and can be obtained from the ISP Routing Mode This field shows that NAT network address translation will be applied to the t...

Страница 45: ...n is Yes Upload Bandwidth This field refers to the maximum upload speed This value is referenced when default weight is chosen for outbound traffic and traffic prioritization A correct value can result in effective traffic prioritization and efficient use of upstream bandwidth Download Bandwidth This field refers to the maximum download speed Default weight control for outbound traffic will be adj...

Страница 46: ...able VLAN you will be able to enter a name for your network WAN Health Check Settings To ensure traffic is routed to healthy WAN connections only the Pepwave router can periodically check the health of each WAN connection The health check settings for each WAN connection can be independently configured Health Check Methods PING The router will send an ICMP PING packet to the specified IP address o...

Страница 47: ...f your network usage To enable this function connect to the Web Admin Interface and go to Network WAN Check the box Enable next to Bandwidth Allowance Monitor and you can see the following Action If the feature Email Notification is enabled you will be notified through email when usage hits 75 and 95 of the monthly allowance If the box Disconnect when usage hits 100 of monthly allowance is checked...

Страница 48: ...Through registration with dynamic DNS service provider s the default public Internet IP address of each WAN connection can be associated with a hostname With dynamic DNS service enabled for a WAN connection you can connect to your WAN s IP address externally even if its IP address is dynamic You must register for an account from the listed dynamic DNS service providers before enabling this option ...

Страница 49: ...et WAN configuration but has a few unique options that are shown in this section The options that are the same as the ethernet WAN connection configuration are shown in the Ethernet WAN section Wi Fi WAN Settings Channel Width choose between the available options 20 Mhz 20 40Mhz 20 40 80 Mhz Channel Selection Determine whether the channel will be automatically selected If you select custom the fol...

Страница 50: ... Click the icon for additional options Roaming Algorithm select Normal default pr Advanced enables Intensive Scan options Roaming Signal Level Threshold Configure the Roaming Signal Level Threshold in dBm Roaming Signal Level Gain Configure the Roaming Signal Level Gain in dBm Roaming Check Interval Configure the Roaming Check Interval in Seconds Connect to Any Open Mode AP This option is to speci...

Страница 51: ...Click Network WAN Details Create Profile to get started This will open a window similar to the one shown below Wi Fi Connection Profile Settings Network Name SSID Enter a name to represent this Wi Fi connection Security This option allows you to select which security policy is used for this wireless network Available options Open https www peplink com 51 Copyright 2021 Peplink ...

Страница 52: ... with dynamic WEP key Preferred BSSID Configure the BSSID the BSSID is the MAC address of the wireless access point WAP Connection Method Choose DHCP or Static IP DNS servers Configure the DNS servers that this WAN connection should use https www peplink com 52 Copyright 2021 Peplink ...

Страница 53: ...lecting the question mark Indication of WiFi strength values Signal Strength Quality indication 30 dBm Maximum signal strength 50 dBm Excellent signal strength 60 dBm Good reliable signal strength 67 dBm Minimum signal strength for applications that require very reliable timely delivery of data packets 70 dBm Not strong goof for soet internet browsing and email 80 dBm Unreliable 90 dBm Unusable ht...

Страница 54: ...a PeVPN Connection To start navigate to Network VPN SpeedFusion and enter a Local ID and click save This device will be identified by other SpeedFusion Peers by this local ID When a PepVPN connection is established between sites the local LAN subnet and subnets behind the LAN defined under Static Route on the LAN settings page will be advertised to the VPN All VPN members branch offices and headqu...

Страница 55: ...To configure PepVPN navigate to Advanced PepVPN and select New Profile The example below had allPepVPN advanced features enabled https www peplink com 55 Copyright 2021 Peplink ...

Страница 56: ...https www peplink com 56 Copyright 2021 Peplink ...

Страница 57: ...remote peer s WAN IP address or hostname s here If the remote uses more than one address enter only one of them here Multiple hostnames are allowed and can be separated by a space character or carriage return Dynamic DNS host names are also accepted This field is optional With this field filled the Pepwave Surf SOHO will initiate connection to each of the remote IP addresses until it succeeds in m...

Страница 58: ...ed PepVPN connection Click the button to select your connection and the following menu will appear You can optionally specify a DNS server to resolve incoming DNS requests Click the checkbox next to Backup Site to designate a backup SpeedFusion profile that will take over should the main PepVPN connection fail Handshake Port and Link Failure Detection Time Handshake Port Click the icon to customiz...

Страница 59: ... and load balance outbound traffic among WAN connections Important Note Outbound policies are applied only when more than one WAN connection is active The settings for managing and load balancing outbound traffic are located at Advanced PepVPN The screenshot below shows the Outbound Policy window with Expert mode enabled The bottom most rule HTPS_Peristence is Default This rule manages the device ...

Страница 60: ...ination of alphanumeric characters 0 9 A Z a z underscores _ dashes and or non leading trailing spaces Enable When this box is checked this outbound policy will be enabled Otherwise it will be disabled Source This setting specifies the source IP address IP network MAC address or Client s Associated SSID for traffic that matches the rule Destination This setting specifies the destination IP address...

Страница 61: ...uting traffic regardless of the connection s health status When No Connections are Available This field allows you to configure the default action when all the selected Connections are not available Drop the Traffic Traffic will be discarded Use Any Available Connections Traffic will be routed to any available Connection even it is not selected in the list Fall through to Next Rule Traffic will co...

Страница 62: ... the other parameters of the rule Service Name This setting identifies the service to the system administrator Valid values for this setting consist of only alphanumeric and underscore _ characters Protocol The Protocol setting along with the Port setting specifies the protocol of the service as TCP UDP ICMP or IP Traffic that is received by the Pepwave router via the specified protocol at the spe...

Страница 63: ...traffic that is received by the Pepwave router via the specified protocol at the specified port range is forwarded via the same respective ports to the LAN hosts specified by the Servers setting For example with IP Protocol set to TCP and Port set to Port Range and Service Ports 80 88 TCP traffic received on ports 80 through 88 is forwarded to the configured servers via the respective ports Port M...

Страница 64: ...eck the corresponding box es to enable UPnP and or NAT PMP Enable these features only if you trust the computers connected to a LAN port or WiFi AP When the options are enabled a table listing all the forwarded ports under these two protocols can be found at Status UPnP NAT PMP In the example above the UPnP device is running When the UPnP device is disconnected the router will suspend the service ...

Страница 65: ...o a number of public IP addresses specified below in order to facilitate inbound and outbound traffic This option is only available when IP Address is selected Range The IP range is a contiguous group of private IP addresses used by the LAN host The system maps these addresses to a number of public IP addresses specified below to facilitate outbound traffic This option is only available when IP Ra...

Страница 66: ...etting specifies the WAN IP addresses that should be used when an IP connection is made from a LAN host to the Internet Each LAN host in an IP range or IP network will be evenly mapped to one of each selected WAN s IP addresses for better IP address utilization in a persistent manner for better application compatibility Note that if you do not want to use a specific WAN for outgoing accesses you s...

Страница 67: ...s Application Prioritization Three application priority levels can be set High Normal and Low Pepwave routers can detect various application traffic types by inspecting the packet content Select an application by choosing a supported application or by defining a custom application manually The priority preference of supported applications is placed at the top of the table Custom applications are a...

Страница 68: ...nd DSCP value DSL Cable Optimization DSL cable based WAN connections have lower upload bandwidth and higher download bandwidth When a DSL cable circuit s uplink is congested the download bandwidth will be affected Users will not be able to download data at full speed until the uplink becomes less congested DSL Cable Optimization can relieve such an issue When it is enabled the download speed will ...

Страница 69: ...ks access to offensive websites and or other inappropriate uses The firewall functionality of Pepwave routers supports the selective filtering of data traffic in both directions Outbound LAN to WAN Inbound WAN to LAN Internal Network VLAN to VLAN The firewall also supports the following functionality Intrusion detection and DoS prevention Web blocking https www peplink com 69 Copyright 2021 Peplin...

Страница 70: ...ound firewall settings are located at Advanced Firewall Access Rules Click Add Rule to display the following screen Inbound firewall settings are located at Advanced Firewall Access Rules Inbound Firewall Rules https www peplink com 70 Copyright 2021 Peplink ...

Страница 71: ...Click Add Rule to display the following screen Internal Network Firewall settings are located at Advanced Firewall Access Rules https www peplink com 71 Copyright 2021 Peplink ...

Страница 72: ...ave router will disregard the other parameters of the rule Click the dropdown menu next to the checkbox to place this firewall rule on a time schedule WAN Connection Inbound Select the WAN connection that this firewall rule should apply to Protocol This setting specifies the protocol to be matched Via a drop down menu the following protocols can be specified Any TCP UDP ICMP DSCP IP Alternatively ...

Страница 73: ... as follows Aug 13 23 47 44 Denied CONN Ethernet WAN SRC 20 3 2 1 DST 192 168 1 20 LEN 48 PROTO TCP SPT 2260 DPT 80 CONN The connection where the log entry refers to SRC Source IP address DST Destination IP address LEN Packet length PROTO Protocol SPT Source port DPT Destination port Click Save to store your changes To create an additional firewall rule click the Add Rule and repeat the above step...

Страница 74: ...Prevention Pepwave routers can detect and prevent intrusions and denial of service DoS attacks from the Internet To turn on this feature click check the Enable check box and press the Save button When this feature is enabled the Pepwave router will detect and prevent the following kinds of intrusions and denial of service attacks Port scan NMAP FIN URG PSH Xmas tree Another Xmas tree Null scan SYN...

Страница 75: ...g in foobar com will be blocked e g www foobar com foobar com etc However myfoobar com will not be blocked You may enter the wild card at the end of a domain name to block any web site with a host name having the domain name in the middle If you enter foobar then www foobar com www foobar co jp or foobar co uk will be blocked Placing the wild card in any other position is not supported The device ...

Страница 76: ... click the Routing Protocols OSPF RIPv2 item on the sidebar to reach the following menu OSPF Router ID This field determines the ID of the router By default this is specified as the LAN IP address If you want to specify your own ID enter it in the Custom field Area This is an overview of the OSPFv2 areas you have defined Click on the area name to configure it To set a new area click Add To delete ...

Страница 77: ...next to the drop down menu Interfaces Determine which interfaces this area will use to listen to and deliver OSPF packets Interface Cost Enable the advanced option question mark to be able to configure a custom cost for each interface To access RIPv2 settings click RIPv2 Settings Authentication Choose an authentication method if one is used from this drop down menu Available options are MD5 and Te...

Страница 78: ...u should configure Firewall rules instead Network Advertising Selected networks will be advertised over OSPF RIPv2 If no network is selected all LAN VLAN networks will be advertised by default All the networks belonging to interfaces that have OSPF or RIPv2 enabled will be advertised even if they are not selected in this table Static Route Advertising Enable this option to advertise LAN static rou...

Страница 79: ...bar to configure BGP Click x to delete a BGP profile Click Add to add a new BGP profile BGP Profile Name This field is for specifying a name to represent this profile Enable When this box is checked this BGP profile will be enabled If it is left unchecked it will be disabled Interface The interface in which the BGP neighbor is located Autonomous System The Autonomous System Number ASN assigned to ...

Страница 80: ...on to advertise your own source address as the next hop when propagating routes iBGP Local Preference This is the metric advertised to iBGP Neighbors to indicate the preference for external routes The value must be between 0 to 4294967295 inclusively Default 100 BFD Enable this option to add Bidirectional Forwarding Detection for path failure All directly connected Neighbors that use the same phys...

Страница 81: ...accepted routes not in the list will be rejected Reject Routes in Restricted Networks will be rejected routes not in the list will be accepted Restricted Blocked Networks This field specifies the network s in the route import entry Exact Match When this box is checked only routes with the same Network and Subnet Mask will be filtered Otherwise routes within the Networks and Subnets will be filtere...

Страница 82: ...ows an individual user to connect to a private business network from a remote location using a laptop or desktop computer connected to the Internet Networks routed by a Peplink router can be remotely accessed via OpenVPN L2TP with IPsec or PPTP To configure this feature navigate to Network Remote User Access and choose the required VPN type L2TP with IPsec L2TP with IPsec Remote User Access Settin...

Страница 83: ...fic designated to the untagged LAN and VLAN segment through the OpenVPN tunnel PPTP No additional configuration required The Point to Point Tunneling Protocol PPTP is an obsolete method for implementing virtual private networks PPTP has many well known security issues Continue to configure authentication methods Authentication Methods Authentication Method Connect to Network Select the VLAN networ...

Страница 84: ... at sign and period only The password must be between 8 and 12 characters long LDAP Server Enter the matching LDAP server details to allow for LDAP server authentication Radius Server Enter the matching Radius server details to allow for Radius server authentication Active Directory Enter the matching Active Directory details to allow for Active Directory server authentication https www peplink co...

Страница 85: ...st Specifies the IP address or hostname of the RADIUS server host Authentication Port This setting specifies the UDP destination port for authentication requests By default the port number is 1812 Secret This field is for entering the secret key for communicating to the RADIUS server Accounting Port This setting specifies the UDP destination port for accounting requests By default the port number ...

Страница 86: ...rt This setting specifies the UDP destination port for authentication requests By default the port number is 1812 Secret This field is for entering the secret key for communicating to the RADIUS server Accounting Port This setting specifies the UDP destination port for accounting requests By default the port number is 1813 https www peplink com 86 Copyright 2021 Peplink ...

Страница 87: ...a security Read the following knowledgebase article for full instructions on how to create and import a self signed certificate https forum peplink com t how to create a self signed certificate and import it to a peplink product Service Forwarding Service forwarding settings are located at Advanced Misc Settings Service Forwarding https www peplink com 87 Copyright 2021 Peplink ...

Страница 88: ...k Enable Forwarding for the WAN connection s that needs forwarding Under SMTP Server enter the ISP s email server hostname or IP address Under SMTP Port enter the TCP port number for each WAN The Pepwave router will intercept SMTP connections Choose a WAN port according to the outbound policy and then forward the connection to the SMTP server if the chosen WAN has enabled forwarding If the forward...

Страница 89: ...nnections for the WAN will be simply forwarded to the connection s original destination DNS Forwarding When DNS forwarding is enabled all clients outgoing DNS requests will also be intercepted and forwarded to the built in DNS proxy server Custom Service Forwarding After clicking the enable checkbox enter your TCP port for traffic heading to the router and then specify the IP Address and Port of t...

Страница 90: ...rk and pass through the Pepwave router FTP FTP sessions consist of two TCP connections one for control and one for data In a multi WAN situation they must be routed to the same WAN connection Otherwise problems will arise in transferring files By default the Pepwave router monitors TCP control connections on port 21 for any FTP connections and binds TCP connections of the same FTP session to the s...

Страница 91: ...ill in the appropriate fields In this example we ll create a group accounting Click save when you have finished adding the required networks The grouped network accounting can now be used to configure a group policy or firewall rule SIM Toolkit The SIM Toolkit accessible via Advanced Settings SIM Toolkit supports two functionalities USSD and SMS https www peplink com 91 Copyright 2021 Peplink ...

Страница 92: ...er s computers One of the most common uses is to query the available balance Enter your USSD code under the USSD Code text field and click Submit You will receive a confirmation To check the SMS response click Get After a few minutes you will receive a response to your USSD code https www peplink com 92 Copyright 2021 Peplink ...

Страница 93: ...SMS The SMS option allows you to read SMS text messages that have been sent to the SIM in your Peplink routers https www peplink com 93 Copyright 2021 Peplink ...

Страница 94: ...ined and managed in this section Click Add to create a new network profile or click the existing network profile to modify its settings SSID Settings SSID This setting specifies the Router SSID that Wi Fi clients will see when scanning Enable Click the drop down menu to choose predefined schedules as your starting point Please note that https www peplink com 94 Copyright 2021 Peplink ...

Страница 95: ...to unicast traffic for associated clients select this option Layer 2 Isolation Layer 2 refers to the second layer in the ISO Open System Interconnect model When this option is enabled it will block communication between Wi Fi clients within the same VLAN SSID or subnet as a security measure that best suits a company Guest Visitor Wi Fi access scenario Do refer to this link https forum peplink com ...

Страница 96: ...ey is used for data encryption and authentication When using this configuration the Shared Key option should be enabled Key length must be between eight and 63 characters inclusive The security level of this method is known to be high NOTE When WPA2 WPA3 Personal is configured if a managed AP which is NOT WPA3 PSK capable the AP Controller will not push those WPA3 and WPA2 WPA3 SSID to that AP Man...

Страница 97: ...ginating from the MAC addresses in this list will be either denied or accepted based on the option selected in the previous field RADIUS Server Host Specifies the IP address or hostname of the RADIUS server host Secret This field is for entering the secret key for communicating to the RADIUS server Authentication Port This setting specifies the UDP destination port for authentication requests By d...

Страница 98: ...vailable options are Device Name LAN Mac Address Device Serial Number and Custom Value Firewall Settings Firewall Mode The settings allow administrator to control access to the SSID based on Firewall Rules Available options are Disable Lockdown Block all except and Flexible Allow all except Firewall Exceptions Create Firewall Rules based on Port IP Network MAC address or Domain Name https www pepl...

Страница 99: ...Settings Navigating to AP Settings displays a screen similar to the one shown below https www peplink com 99 Copyright 2021 Peplink ...

Страница 100: ...for the Wi Fi AP There are 4 relative power levels available Max High Mid and Low The actual output power will be bound by the regulatory limits of the selected country Client Signal Strength ThresholdA This field determines that maximum signal strength each individual client will receive The measurement unit is dBm Maximum number of clients Enter the maximum number of clients that can simultaneou...

Страница 101: ...utA This field is for setting the wait time to receive an acknowledgement packet before performing a retransmission By default this field is set to 48 µs Frame AggregationA This option allows you to enable frame aggregation to increase transmission throughput A Advanced feature Click the button on the top right hand corner to activate AP Status Access Point A detailed breakdown of data usage for e...

Страница 102: ...affic and download traffic On the right hand side of the table you will see the following icons Clicking on the icon displays a table with a list of clients and their usage Clicking on the icon allows you to configure the AP device s details For easier network management you can give each client a name and designate its location You can also designate which firmware pack if any that this client wi...

Страница 103: ... and client information for that device using that SSID at that point in time On the Data Usage by menu you can display the information by SSID or by AP send receive rate Click the Event tab next to Wireless Usage to view a detailed event log for that particular device https www peplink com 103 Copyright 2021 Peplink ...

Страница 104: ...SID In depth wireless SSID reports are available under AP Wireless SSID Click the blue arrow on any SSID to obtain more detailed information on usage for each SSID https www peplink com 104 Copyright 2021 Peplink ...

Страница 105: ...Wireless Client Here you will be able to see your network s heaviest users as well as search for specific users Clicking on the icon bookmarks the specific user and clicking on the icon displays additional details about the user https www peplink com 105 Copyright 2021 Peplink ...

Страница 106: ...https www peplink com 106 Copyright 2021 Peplink ...

Страница 107: ...tribution system WDS or mesh network Track activity by MAC address by navigating to AP Mesh WDS This table shows the detailed information of each AP including protocol transmit rate sent received signal strength and duration https www peplink com 107 Copyright 2021 Peplink ...

Страница 108: ...y Device Suspected Rogue Devices Hovering over a device s MAC address will result in a popup with information on how the device was detected Clicking on the icons will mark the device and move them to the table of identified devices https www peplink com 108 Copyright 2021 Peplink ...

Страница 109: ...ent log displays all of the activity on your AP network down to the client level Use a filter to search for events by MAC address SSID AP Serial Number or AP Profile name Click View Alerts to see only alerts and click the More for additional records https www peplink com 109 Copyright 2021 Peplink ...

Страница 110: ...t s serial number Admin User Name Admin User Name is set as admin by default but can be changed if desired Admin Password This field allows you to specify a new administrator password Confirm Admin Password This field allows you to verify and confirm the new administrator password Read only User Name Read only User Name is set as user by default but can be changed if desired User Password This fie...

Страница 111: ...t to Local Account Available options Local Account RADIUS Authentication Protocol This specifies the authentication protocol used Available options are MS CHAP v2 and PAP Authentication Host This specifies the IP address or hostname of the RADIUS server host Authentication Port This setting specifies the UDP destination port for authentication requests Authentication Secret This field is for enter...

Страница 112: ...ents or to LAN clients only CLI SSH Port This field determines the port on which clients can access CLI SSH Security This option is for specifying the protocol s through which the web admin interface can be accessed HTTP HTTPS HTTP HTTPS HTTP to HTTPS redirection is enabled by default to force HTTPS access to the web admin interface Web Admin Access This option is for specifying the network interf...

Страница 113: ...s takes will depend on your internet connection s speed The firmware will now be applied to the router The amount of time it takes for the firmware to upgrade will also depend on the router that s being upgraded Upgrading the firmware will cause the router to reboot Web admin interface install updates manually In some cases a special build may be provided via a ticket or it may be found in the for...

Страница 114: ... advising to download the Current Active Configuration Please click on the underlined download text After downloading the current config click the Ok button to start the upgrade process The firmware will now be applied to the router The amount of time it takes for the firmware to upgrade will depend on the router that s being upgraded Upgrading the firmware will cause the router to reboot The InCo...

Страница 115: ...me Server This setting specifies the NTP network time server to be utilized by the Pepwave router Schedule Enable and disable different functions such as WAN connections outbound policy and firewalls at different times based on a user scheduled configuration profile The settings for this are located at System Schedule Enable scheduling and then click on your schedule name or on the New Schedule bu...

Страница 116: ... schedules as your starting point Please note that upon selection previous changes on the schedule map will be deleted Schedule Map Click on the desired times to enable features at that time period You can hold your mouse for faster entry Email Notification Email notification functionality provides a system administrator with up to date information on network status The settings for configuring em...

Страница 117: ... automatically SMTP Port This field is for specifying the SMTP port number By default this is set to 25 when STARTTLS is selected the default port number will be set to 587 When SSL TTS is selected the default port number will be set to 465 You may customize the port number by editing this field SMTP User Name Password This setting specifies the SMTP username and password while sending email These...

Страница 118: ...ation button to test the settings before saving After Test Email Notification is clicked you will see this screen to confirm the settings Click Send Test Notification to confirm In a few seconds you will see a message with detailed test results https www peplink com 118 Copyright 2021 Peplink ...

Страница 119: ...https www peplink com 119 Copyright 2021 Peplink ...

Страница 120: ...epwave router can also send push notifications to mobile devices that have our Mobile Router Utility installed Check the box to activate this feature For more information on the Router Utility go to www peplink com products router utility URL Logging This setting is to enable event logging at the specified log server URL Logging Host This setting specifies the IP address or hostname of the URL log...

Страница 121: ...NMP Port This option specifies the port which SNMP will use The default port is 161 SNMPv1 This option allows you to enable SNMP version 1 SNMPv2 This option allows you to enable SNMP version 2 SNMPv3 This option allows you to enable SNMP version 3 SNMP Trap This option allows you to enable SNMP Trap To add an SNMP community click the Add SNMP Community button in the Community Name table the follo...

Страница 122: ...ch the following screen is displayed SNMPv3 User Settings User Name This setting specifies a user name to be used in SNMPv3 Authentication Protocol This setting specifies via a drop down menu one of the following valid authentication protocols NONE MD5 SHA When MD5 or SHA is selected an entry field will appear for the password Privacy Protocol This setting specifies via a drop down menu one of the...

Страница 123: ...will only report its status but can t be managed or configured by InControl Alternatively you can also privately host InControl Simply check the box beside the Privately Host InControl open and enter the IP Address of your InControl Host You can sign up for an InControl account at https incontrol2 peplink com You can register your devices under the account monitor their status see their usage repo...

Страница 124: ...ettings based on a configuration file click Choose File to locate the configuration file on the local computer and then click Upload The new settings can then be applied by clicking the Apply Changes button on the page header or you can cancel the procedure by pressing discard on the main page of the web admin interface Feature Add ons Some Pepwave routers have features that can be activated upon ...

Страница 125: ...the current system boot up firmware Please note that a firmware upgrade will always replace the inactive firmware partition Tools Ping The ping test tool sends pings through a specific Ethernet interface or a SpeedFusionTM VPN connection You can specify the number of pings in the field Number of times to a maximum number of 10 times Packet Size can be set to a maximum of 1472 bytes The ping utilit...

Страница 126: ...t The traceroute test tool traces the routing path to the destination through a particular Ethernet interface The traceroute test utility is located at System Tools Traceroute Tip A system administrator can use the traceroute utility to analyze the connection path of a LAN WAN connection https www peplink com 126 Copyright 2021 Peplink ...

Страница 127: ...alysis The WAN Analysis feature allows you to run a WAN to WAN speed test between 2 Peplink devices You can set a device up as a Server or a Client One device must be set up as a server to run the speed tests and the server must have a public IP address The default port is 6000 and can be changed if required The IP address of the WAN interface will be shown in the WAN Connection Status section htt...

Страница 128: ...e that the Control Port matches what s been entered on the server side Select the WAN s that will be used for testing and enter the Servers WAN IP address Once all of the options have been set click the Start Test button https www peplink com 128 Copyright 2021 Peplink ...

Страница 129: ...The test output will show the Data Streams Parameters the Throughput as a graph and the Results https www peplink com 129 Copyright 2021 Peplink ...

Страница 130: ...The test can be run again once it s complete by clicking the Start button or you can click Close and change the parameters for the test https www peplink com 130 Copyright 2021 Peplink ...

Страница 131: ...ur model uses a product code it will appear here Hardware Revision This shows the hardware version of this device Serial Number This shows the serial number of this device Firmware This shows the firmware version this device is currently running PepVPN Version This shows the current PepVPN version Modem Support This shows the modem support version For a list of supported modems click Modem Support...

Страница 132: ...Report The Download link is for exporting a diagnostic report file required for system investigation Remote Assistance Click Turn on to enable remote assistance The second table shows the MAC address of each LAN WAN interface connected To view your device s End User License Agreement EULA follow the Legal link Important Note If you encounter issues and would like to contact the Pepwave Support Tea...

Страница 133: ... for additional information This screen also indicates the number of sessions initiated by each WAN port In addition you can see which clients are initiating the most sessions You can also perform a filtered search for specific sessions You can filter by subnet port protocol and interface To perform a search navigate to Status Active Sessions Search https www peplink com 133 Copyright 2021 Peplink...

Страница 134: ...nd outbound sessions of each WAN connection on the Pepwave router A filter is available to sort active session information Enter a keyword in the field or check one of the WAN connection boxes for filtering https www peplink com 134 Copyright 2021 Peplink ...

Страница 135: ...es retrieved from the DHCP reservation table or defined by users current download and upload rate and MAC address Clients can be imported into the DHCP reservation table by clicking the button on the right You can update the record after import by going to Network LAN https www peplink com 135 Copyright 2021 Peplink ...

Страница 136: ...is section PepVPN Status PepVPN Status shows the current connection status of each connection profile and is displayed at Status PepVPN SpeedFusion Click on the corresponding peer name to explore the WAN connection s status and subnet information of each VPN peer https www peplink com 136 Copyright 2021 Peplink ...

Страница 137: ...Click button for a chart displaying real time throughput latency and drop rate information for each WAN connection https www peplink com 137 Copyright 2021 Peplink ...

Страница 138: ...When pressing the button the following menu will appear The Speedfusion status page shows all related information about the PepVPN connection https www peplink com 138 Copyright 2021 Peplink ...

Страница 139: ...ng throughput tests Peplink also published a whitepaper about Speedfusion which can be downloaded from the following url http download peplink com resources whitepaper speedfusion and best practices 2019 pdf https www peplink com 139 Copyright 2021 Peplink ...

Страница 140: ...tatus Event Log The log section displays a list of events that has taken place on the Pepwave router Check Auto Refresh to refresh log entries automatically Click the Clear Log button to clear the log https www peplink com 140 Copyright 2021 Peplink ...

Страница 141: ...WAN Quality WAN Quality allows you to select each WAN and view current WAN Quality Detailed information can be seen when selecting a point on the graph https www peplink com 141 Copyright 2021 Peplink ...

Страница 142: ...pass is neither recorded nor shown Real Time The Data transferred since installation table indicates how much network traffic has been processed by the device since the first bootup The Data transferred since last reboot table indicates how much network traffic has been processed by the device since the last boot up https www peplink com 142 Copyright 2021 Peplink ...

Страница 143: ...ows the hourly bandwidth usage for all WAN connections with the option of viewing each individual connection Select the desired connection to check from the drop down menu https www peplink com 143 Copyright 2021 Peplink ...

Страница 144: ...dwidth Monitoring feature the Current Billing Cycle table for that WAN connection will be displayed Click on a date to view the client bandwidth usage of that specific date This feature is not available if you have selected to view the bandwidth usage of only a particular WAN connection The scale of the graph can be set to display megabytes MB or gigabytes GB https www peplink com 144 Copyright 20...

Страница 145: ...ection and view the information by Billing Cycle or by Calendar Month Click the first two rows to view the client bandwidth usage in the last two months This feature is not available if you have chosen to view the bandwidth of an individual WAN connection The scale of the graph can be set to display megabytes MB or gigabytes GB https www peplink com 145 Copyright 2021 Peplink ...

Страница 146: ...e factory default settings on your Pepwave Surf SOHO unit follow the steps below 1 Locate the reset button on the back panel of the Pepwave Surf SOHO 2 With a paperclip press and keep the reset button pressed https www peplink com 146 Copyright 2021 Peplink ...

Страница 147: ...n This equipment generates uses and can radiate radio frequency energy and if not installed and used in accordance with the instructions may cause harmful interference to radio communications However there is no guarantee that interference will not occur in a particular installation If this equipment does cause harmful interference to radio or television reception which can be determined by turnin...

Страница 148: ...CE Statement for Pepwave Routers Surf SOHO https www peplink com 148 Copyright 2021 Peplink ...

Страница 149: ...https www peplink com 149 Copyright 2021 Peplink ...

Страница 150: ...class This equipment complies with CE radiation exposure limits set forth for an uncontrolled envi ronment This equipment should be installed and operated with a minimum distance of 20cm between the radiator your body contact as https www peplink com https www peplink com 150 Copyright 2021 Peplink ...

Страница 151: ...USB WAN Modem Port Specification Surf SOHO Series Surf SOHO Output Rating 5V DC 2A https www peplink com 151 Copyright 2021 Peplink ...

Отзывы: