background image

GATEWAY USER MANUAL

For all Broadcom chipset-based models including:

ADSL 3xx series: 

SR300n, SR350n, SR360n

VDSL 5xx series: 

SR500n, SR505n, SR510n, SR550n, SR552n  

Release 3.0
June, 2014

Summary of Contents for SR552n

Page 1: ...GATEWAY USER MANUAL For all Broadcom chipset based models including ADSL 3xx series SR300n SR350n SR360n VDSL 5xx series SR500n SR505n SR510n SR550n SR552n Release 3 0 June 2014 ...

Page 2: ...15 WAN Service 16 xTM 17 xDSL 18 Route 22 ARP 23 DHCP 24 Advanced Setup Layer2 Interface 25 ATM Interface 25 PTM Interface 27 ETH Interface 29 WAN Service 29 PPP over Ethernet 29 IP Over Ethernet 35 NAT Virtual Servers Port Forward 40 Port Triggering 41 DMZ Host 43 Security IP Filtering 44 Incoming 45 MAC Filtering 46 Parental Control 48 URL Filter 49 Quality of Service 50 QoS Config 50 QoS Classi...

Page 3: ...etup 92 Network Authentication Mixed WPA2 WPA PSK 92 MAC Filter 93 Wireless Bridge 94 Advanced 95 Station Info 99 Diagnostics Diagnostics 100 Fault Management 101 Management Settings 102 Backup 102 Update 103 Restore Default 104 System Log 104 Security Log 105 Management Server 106 TR 069 Client 106 STUN Config 108 Internet Time 109 Access Control 110 Services 110 Passwords 112 Update Software 113...

Page 4: ...f the FCC Rules Operation is subject to the following two conditions This device may not cause harmful interference This device must accept any interference received including interference that may cause undesired operation This equipment has been tested and found to comply with the limits for a Class B digital device pursuant to part 15 of the FCC Rules These limits are designed to provide reason...

Page 5: ...ous high voltage points or other risks ONLY qualified service personnel can service the device Please contact your vendor for further information Use ONLY the dedicated power supply for your device Connect the power cord or power adaptor to the correct supply voltage 110V AC in North America or 230V AC in Europe Do NOT use the device if the power supply is damaged as it might cause electrocution I...

Page 6: ...he very latest in broadband access and home networking technologies SmartRG solutions enable service providers to improve their bottom line by reducing service costs and increasing customer satisfaction Learn more at www SmartRG com Purpose Scope The purpose and scope of this document is to provide the customers of SmartRG with installation configuration and monitoring information for all CPE plat...

Page 7: ...AN LAN 1 4 WLAN WPS DSL 1 or 2 INTERNET Power up test failure DSL sync acquired and gateway online No sync to DSL line DSL sync in progress Modem authenticatio n in progress DSL sync acquired and gateway online Gateway online and data transf er in progress IP connec tion failure Connec tion dropped attempting re authentication LAN device on network connec ted Wi Fi enable d on modem PC network act...

Page 8: ... trols across the back of the unit Refer to the Quick Start Guide enclosed with your gateway for specifics regarding installation of your particular model The ports depicted in this example are described as follows DSL The grey RJ12 port labeled DSL is specifically intended for connection to an internet provider via a DSL Digital Subscriber Line service The center pair carries the first DSL line F...

Page 9: ...scribe above When this port is serving as a LAN port the corre sponding LED on the face of the unit is labeled WAN See the ETH Interface section of this manual for further instructions to enable this SmartPortTM feature USB USB ports on SmartRG products currently provide 5 DC volts Future firmware updates will enable data transfer via USB POWER Use only the power supply included with your gateway ...

Page 10: ...R550n SR510n SR552n and SR630n the button is located on the left side of the unit For the SR350n and SR500n models an exterior button is not present however WPS is supported via the on board soft ware Reference the Quick Start Guide included with your gateway for specific instructions Reset Button The Reset button is a small hole in the gateway s enclosure with the actual button mounted behind the...

Page 11: ...r SmartRG Gateway s UI To manually configure the SmartRG Gateway access the gateway s embedded web UI 1 Attach your computer s RJ45 connection to any of the SmartRG gateway s LAN ports 1 4 2 Configure your computer s IP interface to acquire an IP address using DHCP See the IMPORTANT note below for in structions on logging in to a SmartRG gateway configured for bridge mode operation 3 Open a browse...

Page 12: ...e modem operation your PC will NOT be able to acquire an address via CPE s DHCP Instead manually configure your PC s interface with an IP address on the default network e g 192 168 1 100 The balance of this guide is dedicated to a sequential walk through of the user interface of your gateway Here you will find a visual refer ence of each screen along with a Description for each of the parameters d...

Page 13: ...s section Summary Upon successful login Device Info is the first screen to appear This is screen is dedicated to the display of hardware and software details associated with your gateway In addition the current status of the WAN connection if present is shown Wan Info The Device Info WAN status screen provides a high level overview for the connection between your Internet Service Provider and the ...

Page 14: ...Displays the connection interface layer 2 interface through which gateway handles the traffic Description Displays the service description pppoe ipoe br Type Displays the service type PPPoE IPoE Bridge VlanMuxId Displays the VLAN ID Disabled 0 4094 IPv6 Displays the state of IPv6 Enabled Disabled Igmp Displays the state of IGMP Enabled Disabled MLD Displays the state of MLD Enabled Disabled NAT Di...

Page 15: ...s NOTE Not all SmartRG gateway models support the SmartPort feature wherein a LAN port can be re purposed to function as a WAN port as displayed in the Interface column below note LAN3 LAN2 LAN1 WAN Only models SR5xxn and SR360n support this functionality The individual fields on this screen are defined as follows Field Name Description Interface Received Transmitted LAN1 LAN2 LAN3 LAN4 Ethernet W...

Page 16: ...pppoe ipoe br Bytes RX TX total quantity of packets in Bytes Pkts RX TX total quantity of packets Errs RX TX total quantity of error packets Drops RX TX total quantity of dropped packets Reset Statistics Resets the Statistics to zero WAN Service Device Info Statistics WAN displays the TX RX Bytes Packets Error and Drops for each WAN interface for your SmartRG Gateway All WAN interfaces configured ...

Page 17: ... Packets Total quantity of received Packets Out Packets Total quantity of transmitted Packets In OAM Cells Total quantity of received OAM Cells Out OAM Cells Total quantity of transmitted OAM Cells In ASM Cells Total quantity of received ASM Cells Out ASM Cells Total quantity of transmitted ASM Cells In Packet Errors Total quantity of received Packet Errors In Cell Errors Total quantity of receive...

Page 18: ...Reset Statistics button located on the xTM screen as shown below Use the Reset Statistics button near the bottom of the screen to reset these counters Also featured is an xDSL Bit Error Rate BER test which determines the quality of the xDSL connection Scroll to the bot tom of the table of statistics and click xDSL BER Test The test transfers idle cells containing a known pattern and com pares the ...

Page 19: ...Page 19 501 SE Columbia Shores Boulevard Suite 500 Vancouver Washington 98661 USA l 1 360 859 1780 SmartRG Inc Propriety and Confidential All Rights Reserved Copyright 2014 smartrg com ...

Page 20: ...tream Transmit power from the gateway to the DSL loop Attainable Rate Kbps Downstream Upstream The typically obtainable sync rate PhyR Status Inactive Active Physical Layer Retransmission feature status Downstream Upstream Rate Kbps Path 0 1 Downstream Upstream Current sync rate MSGc of bytes in over head channel message Path 0 1 Downstream Upstream B of bytes in Mux Data Frame Path 0 1 Downstream...

Page 21: ...Codewords received RS Codewords Corrected Path 0 1 Downstream Upstream Total number of Reed Solomon Codewords corrected RS Codewords Uncorrected Path 0 1 Downstream Upstream Total number of Reed Solomon Codewords Uncorrected HEC Errors Path 0 1 Downstream Upstream Total number of Header Error Checksum errors OCD Errors Path 0 1 Downstream Upstream Total number of Out of Cell Delineation errors LCD...

Page 22: ...dividual fields on this screen are defined as follows Field Name Description Destination Including IPv6 Route Displays the Destination IP addresses Gateway Displays the Gateway IP address Subnet Mask Displays the Subnet Masks Flag Including IPv6 Route Displays the status of the flags Metric Including IPv6 Route Displays the number of hops to reach the default gateway Service Including IPv6 Route D...

Page 23: ...ddresses for each LAN Cli ent connected to the SmartRG Gateway via a LAN Ethernet port or Wireless LAN The individual fields on this screen are defined as follows Field Name Description IP address The IP address of the host Flags Complete Permanent Published Each entry in the ARP cache will be marked with one of these flags HW Address The hardware MAC address of the host Device br n atm n eth n at...

Page 24: ...tion Hostname Displays the Host name of each connected LAN device MAC Address Displays the MAC Address for each connected LAN device IP Address Displays the IP Address for each connected LAN device Expires In Displays the time until the DHCP lease expires for each LAN device DHCP Device Info DHCP displays a list of locally connected LAN hosts and their DHCP lease status which are directly connecte...

Page 25: ...lation mode and more Note that devices routers on both ends of the connection must support ATM PVC ATM is becoming popular as a wide area network WAN medium ATM offers small cell size and strict quality of service allowing voice video and data to coexist Terms VPI Virtural Path Identifier VCI Virtual Circuit Identifier VC Virtual Circuit After selecting Advanced Setup Layer2 Interface ATM Interfac...

Page 26: ...uely identify a network path for ATM cell packets to reach its destination Every ATM path requires a unique VPI number to associate Works together with the VCI Each individual DSL circuit cannot have the same VPI VCI combination VCI 32 65535 Enter a Virtual Channel Identifier VCI is a 16bit identifier that has a unique channel Select DSL Latency Path0 Fast No error correction and can provide lower...

Page 27: ...his category does not rely on timing synchronization between the destination and source Realtime VBR Realtime Variable Bit Rate Same as above but relies on timing and synchronization between the destination and source Commonly used in networks with compressed video traffic Minimum Cell Rate cells s 1 indicates no shaping Minimum allowable rate at which cells can be sent on a ATM network Scheduler ...

Page 28: ... known as cyclic executive Weighted Fair Queuing A data packet scheduling technique allowing different scheduling priorities to statistically multiplexed data flows Since each data flow has its own queue an ill behaved flow who has sent larger packets or more packets per second than the others since it became ac tive will only punish itself and not other sessions Default Queue Weight 1 63 Enter a ...

Page 29: ...p down menu in the center pane simply select the LAN port you wish to act as a WAN port WAN Service There are several variations of WAN Service available to configure The three core variations are PPP over Ethernet PPPoE IP over Ethernet Bridging This chapter will illustrate a sample configuration scenario down each of these three variations and define the available fields to customize your WAN se...

Page 30: ...elds The individual fields on this screen are defined as follows Next configure the PPP Username Password and related information Field Name Description WAN service type PPP over Ethernet PPPOE IP over Ethernet IPoE Bridging Enter Service Description Enter a name to describe this configuration Network Protocol Selection A data packet scheduling technique allowing different scheduling priorities to...

Page 31: ...Page 31 501 SE Columbia Shores Boulevard Suite 500 Vancouver Washington 98661 USA l 1 360 859 1780 SmartRG Inc Propriety and Confidential All Rights Reserved Copyright 2014 smartrg com ...

Page 32: ...pond to the Keepalive how many additional at tempted packets will the gateway send before giving up and declaring the connection Failed Dial on Demand 1 4320 Enables Inactivity Timeout minutes Default 0 not applicable Connection automatically starts when there is outbound traffic to the Internet It automati cally terminates if the connection is idle based on the value in the Idle Timeout setting P...

Page 33: ...ulticast routers No Multicast VLAN Filter Disables multicast filtering between WAN and LAN VlanMux network MTU size 1370 1492 Edit the Maximum Transmission Units MTU for PPP service Use Base MAC Address on this WAN interface Use SmartRG Devices Base Primary MAC address When unchecked a unique MAC per ser vice is assigned ADDITIONAL OPTIONS WHEN IPV4 IPV6 or IPV6 Only are selected at the WAN Servic...

Page 34: ... selection from left to right or for right to left Alternatively you may use the lower portion of the screen to manually key in static DNS IP addresses Click Next after completing the desired parameters Lastly the summary screen will appear indicating that your PPPoE WAN setup is complete Review the summary and either click Apply Save to commit your changes or choose Back to step through this prog...

Page 35: ... of each screen First select the Layer2 interface to use for the WAN service Click the Next button to advance to the next step Next select the type of WAN service you wish to create For this example choose IP over Ethernet Click Next after completing the necessary fields The individual fields on this screen are defined as follows Field Name Description WAN service type PPP over Ethernet PPPOE IP o...

Page 36: ...ng the necessary fields The individual fields on this screen are defined as follows Field Name Description WAN service type PPP over Ethernet PPPOE IP over Ethernet IPoE Bridging Enter Service Description Enter a name to describe this configuration Network Protocol Selection IPV4 Only IPV4 IPV6 Dual Stack IPV4 and IPV6 running concurrently IPV6 Only Note When selecting IPV4 IPV6 or IPV6 the subseq...

Page 37: ...gn the WAN IP to the gateway Option 60 Vendor ID Optional Broadcast a specific vendor ID for the DHCP server to accept the device Option 61 IAID Optional Interface Association Identifier IAID A unique identifier for an IA chosen by the client Option 61 DUID Optional DHCP Unique Identifier DUID is used by the client to get an IP address from the DHCP server Use the following Static IP address Use t...

Page 38: ... IPv6 address automatically When you wish the ISP to automatically assign the WAN IP to the gateway Dhcpv6 Address Assignment IANA Select this option for CPE to receive WAN IP from ISP Dhcpv6 Prefix Delegation IAPD Select this option for CPE to generate WAN IP s prefix from server rest by MAC address Use the following Static IPv6 address Use this section to manually declare v6 the Static IP inform...

Page 39: ...assign to LAN devices End interface ID Enter the ending IPv6 available addresses for DHCP to assign to LAN devices Leased Time hour Amount of time before a new IPv6 lease is requested by the LAN cli ent Enable RADVD Optional Router Advertisement Daemon RADVD service that sends router advertisements to LAN clients Enable ULA Prefix Advertisement Check this option to enable unique local address ULA ...

Page 40: ...ward Virtual Servers more commonly known as Port Forward is a technique used to facilitate communications by external hosts with services provided within a private local area network After Selecting Advanced Setup NAT Virtual Servers from the left navigation bar click the Add button The following screen will appear Customize the fields to create your port forwarding entry Click Apply Save to commi...

Page 41: ...with Protocol Protocol used Transmission Control Protocol TCP or User Datagram Protocol UDP or TCP UDP Internal Port Start Internal Port to start with Internal Port End Internal Port to end with The individual fields on this screen are defined as follows Port Triggering Some applications require that specific ports in the gateway s firewall be opened for access by remote parties Port Trigger dy na...

Page 42: ... creating a Port Trigger entry Trigger Port Start 1 65535 An outgoing trigger port number Set the beginning of the range of available ports Trigger Port End 1 65535 An outgoing trigger port number Set the end of the range of available ports Trigger Protocol TCP UDP TCP UDP Select the protocol required by the application that will be using the ports in the specified range Open Port Start 1 65535 An...

Page 43: ...kets from the WAN that do not belong to any of the applications configured in the Virtual Servers table to the DMZ host computer If it is desired to route all internet traffic with no filtering or security to a specific LAN device add the IP address of that device to this field After selecting Advanced Setup NAT DMZ Host from the left navigation bar enter the DMZ Host IP Address Click Apply Save t...

Page 44: ...ess as described below must be specified in IPV6 format e g the following is an IPV6 compliant hexadecimal address 2001 0DB8 AC10 FE01 0000 0000 0000 0001 Protocol TCP UDP TCP UDP or ICMP Sets the protocol profile for the filter you are defining TCP UDP is most commonly used Source IP address prefix length Enter the source IP address of a LAN side host for which you wish to filter block it s outgo...

Page 45: ...r block it s outgo ing traffic for the specified protocol s Note The address specified here can be a particular address or a block of IP address on a given network subnet This is done through appending the address with the routing prefix length decimal value preceded with the slash associated Use of a valid decimal routing prefix for defining the subnet mask per CIDR notation is required Destinati...

Page 46: ... to all interfaces First WAN interface e g pppoe based checkbox Last WAN interface e g ipoe based checkbox Check each as applicable to effect rule on specific WAN interface s WAN interface s available for selection will be those configured in Routing mode and with firewall enabled First LAN interface checkbox Second LAN interface as applica ble checkbox Check each as applicable for desired rule Br...

Page 47: ...yright 2014 smartrg com Field Name Description Interface Interface s associated with established policy rule s Policy FORWARD BLOCKED The current active policy type that is in place Change Check this box then click the Change Policy button to toggle the policy type Next click the Add button The following screen will appear Click Apply Save to commit the changes ...

Page 48: ...MAC address Frame Direction Select the incoming outgoing packet interface WAN Interfaces Applies the filter to the selected interface s The individual fields on this screen are defined as follows Parental Control The Parental Control features of your SmartRG gateway enable restriction of internet access on a LAN host by LAN host basis This is achieved without the need for client software to be ins...

Page 49: ...locking Enter the range of time that the above stated device s is to be restricted from access to the internet The individual fields on this screen are defined as follows URL Filter The other side of the Parental Controls coin is URL filtering From the left navigation bar select Advanced Setup Parental Control Url Filter Choose the Exclude List radio button to add a URL to be blocked Note that the...

Page 50: ...g added default 80 Quality of Service QOS enables prioritization of internet content to help ensure the best possible performance This is particularly useful for stream ing video and audio content to minimized potential for drop outs QoS becomes significant when the sum of the traffic audio video data exceeds the capacity of the line QoS Config Use the QOS Config screen to enable QOS and set the D...

Page 51: ...F23 010110 EF 101110 AF22 010100 CS5 101000 AF21 010010 CS6 110000 CS2 010000 CS7 111000 AF33 011110 When this option is checked it exposes the QoS Queue Management Configuration drop down menu where selection of the de fault Differentiated Services Code Point DSCP Mark classification value to be associated can be declared If this option was already enabled and the check is removed QoS for ALL int...

Page 52: ...ll mark according to the highlighted selection therein The associated default marking will then automatically be applied to all incoming packets without reference to a particular classification NOTE An default DSCP Mark of value Default 000000 will mark all egress packets that do NOT match any classification QoS Queue Config Use the QoS Queue Config to configure a queue and add it to a selected La...

Page 53: ...WRR WFQ Note Lower value higher priority Exposed only if SP WRR WFQ Queue Precedence priority as defined above is selected Scheduler Algorithm Algorithms for data priority in queue Strict Priority Allows shaping of rate and burst size for packets in queue Weighted Round Robin Applies a fair round robin scheme weighting effective for e g ATM networks with fixed packets size Weighted Fair Queuing Ap...

Page 54: ...inimum shaping rate defined for packets in QoS queue Shaping Rate 1 100000 Kbps 1 value indicates no minimum shaping applied Shaping rate defined for packets in QoS queue defined QoS Classification Use QoS Classification to create traffic class rule to classify the ingress traffic into a priority queue Optionally you may also mark the DSCP or Ethernet priority of the packet After selecting Advance...

Page 55: ... IP Address Mask Enter the source IP Address and Source IP Mask applied to classification Destination IP Address Mask Enter the source IP Address and Source IP Mask applied to classification Protocol Optional Enter the Protocol specified for classification criteria UDP TCP Source Port Optional Enter the Source Port applicable for classification criteria Expressed as a range or single port port por...

Page 56: ...he following screen will appear Click the Apply Save button to commit the changes entered Field Name Description Interface Each line item in the table represents one of the Ethernet LAN ports on the back of your SmartRG gateway Type LAN WAN Describes the function for which each physical port is configured on the gateway Shaping Rate Kbps 1 1 000 000 Kbps Sets the data rate for packets on the speci...

Page 57: ...ection from left to right or for right to left Click the Apply Save button to commit the changes entered Field Name Description Available Routed WAN Interfaces Choose from the list of available WAN interfaces identify as the Default Gateway Selected Default Gateway Interfaces When populated this becomes a prioritized list of Default Gateways selections Selected WAN Interface Select the WAN interfa...

Page 58: ... Save button to commit the changes entered Up to 32 entries may be added Field Name Description IP Version IPv4 IPv6 Select the IP version associated with the static route you wish to create Destination IP address prefix length Enter the destination network address subnet mask for route Interface WAN Interface s available for selection This list filtered by to IP Version set in the first drop down...

Page 59: ...ablish similar policies After selecting Advanced Setup Routing Policy Route click the Add button and the following screen will appear Click the Apply Save button to commit the changes entered Field Name Description Policy Name A free form text field Enter a descriptive name for this entry to the policy routing table Physical LAN Port Select a physical LAN interface for the policy route from the dr...

Page 60: ...anced Setup Routing RIP click the Add button and the following screen will appear Click the Apply Save button to commit the changes entered Field Name Description Interface This column shows a list of available WAN interfaces Complete the line item s as sociated with the interface you wish to emply RIP Version 1 2 Both Select the version of Routing Interface Protocol you desire Reference RFC 1058 ...

Page 61: ...ll Rights Reserved Copyright 2014 smartrg com DNS DNS Server Use the features of this screen to input the Domain Name Server information supplied by the service provider After selecting Advanced Setup DNS DNS Server from the left navigation bar the following screen will appear Enter your desired settings Click Apply Save to commit changes ...

Page 62: ...ary DNS server WAN Interface Selected Alter this field only if IPv6 environment Primary IPv6 DNS Server Enter the IP address of the primary IPv6 primary DNS Secondary IPv6 DNS Server Enter the IP address of the primary IPv6 primary DNS The individual fields on this screen are defined as follows Dynamic DNS Dynamic DNS DDNS automatically updates a name server in the DNS with the active DNS configur...

Page 63: ...ter the password of the dynamic DNS server The individual fields on this screen are defined as follows Static DNS The Static DNS service allows you to resolve DNS queries on the Broadband Router by adding static Host Name to IP Address mappings After selecting Advanced Setup DNS Static DNS from the left navigation bar click the Add button The following screen will appear Enter your desired setting...

Page 64: ... 2014 smartrg com DSL Advanced settings for the DSL interface CAUTION Altering these settings unnecessarily could result in the gateway being unable to attain DSL synchronization After selecting Advanced Setup DSL from the left navigation bar click the Add button The following screen will appear Enter your desired settings then click Apply Save to commit your changes ...

Page 65: ...x Downstream 28 Mbps Max Upstream 1 0 Mbps AnnexM Annex L of ITU T G 992 5 standard which supports extended upstream bandwidth Max Downstream 24 Mbps Max Upstream 3 Mbps VDSL2 ITU T G 993 2 standard Max Downstream 100 Mbps Max Upstream 60 Mbps Parameter 8a 8b 8c 8d 12a 12b 17a Max DS Tx Power dBm 17 5 20 5 11 5 14 5 Max US Tx Power dBm 14 5 Min bidirectional net data rate 50Mbps 68Mbps 100Mbps The...

Page 66: ...ode sending only a REVERB signal Medley Puts the DSL PHY in test mode sending only a MEDLEY signal No Retrain The DSL PHY will attempt to establish a connection as in Normal mode but once the connection is up it will not retrain even if the signal is lost L3 Puts the DSL modem in the L3 power state Click the Apply button place the gateway in test mode CAUTION Do not modify the tones selected unles...

Page 67: ...ure supported only on SmartRG models SR550n and SR552n Bonding enables two DSL lines to feed the same modem Utilize this screen to leverage the bandwidth of both lines Bonded they will behave as a single higher bandwidth connection After selecting Advanced Setup DSL Bonding from the left navigation bar The following screen will appear Check the checkbox to enable Bonding Click Apply Save to commit...

Page 68: ...ht 2014 smartrg com UPnP Enable UPnP when 3rd party devices on your LAN support this Universal Plug and Play standard Common client devices include gaming consoles IP cameras printers and others After selecting Advanced Setup UPnP from the left navigation bar The following screen will appear Check the checkbox to en able UPnP Click Apply Save to commit your changes ...

Page 69: ... domain lookup performance for clients by creating a historical cache of lookups Navigate to Advanced Setup DNS Proxy to enable and configure this feature After selecting Advanced Setup DNS Proxy from the left navigation bar The following screen will appear Check the checkbox to enable DNS Proxy mode and specify a Hostname and Domain Name of the LAN in the fields that follow Click Apply Save to co...

Page 70: ...tep 2 dynamic or step 3 static below 2 To automatically add LAN clients to a WAN Interface in the new group add the DHCP vendor ID string By configuring a DHCP vendor ID string any DHCP client request with the specified vendor ID DHCP option 60 will be denied an IP address from the local DHCP server 3 Select an interface from the Available Interface list and add it to the Grouped Interface list us...

Page 71: ...Page 71 501 SE Columbia Shores Boulevard Suite 500 Vancouver Washington 98661 USA l 1 360 859 1780 SmartRG Inc Propriety and Confidential All Rights Reserved Copyright 2014 smartrg com ...

Page 72: ...Pv6 as well IPv6inIPv4 After selecting Advanced Setup IP Tunnel IPv6inIPv4 from the left navigation bar click the Add button The screen shown on the next page will appear 1 Enter a Tunnel Name 2 Currently only the 6rd Mechanism is supported 3 Select the appropriate LAN and WAN interfaces from the drop down lists associated with the tunnel you wish to estab lish 4 IPv4 Mask Length 6rd Prefix with P...

Page 73: ... button The screen shown on the next page will appear 1 Enter a Tunnel Name 2 Currently only the DS Lite Mechanism is supported Consult RFC6333 for further information regarding DS Lite 3 Select the appropriate LAN and WAN interfaces from the drop down lists associated with the tunnel you wish to establish 4 AFTR Address Family Transition Router may be configured automatically Select the Manual ra...

Page 74: ...t level encryption and authentication Use the IPSec page to enable and remove connections or edit existing connections The IPSec configuration screen is dynamic Some options are revealed or hidden depending on the selected connection After selecting Advanced Setup IP Sec from the left navigation bar click the Add New Connection The following screen will ap pear Enter your connection details by com...

Page 75: ...et for authentication and integrity Local Gateway Interface Select the WAN connection from the drop down list to be associated with this tunnel Remote IPSec Gateway Address Enter the he WAN IP for tunnel Tunnel Access From Local IP Addresses Subnet Single Address Select IP information for site A and B Subnet indicates entire LAN For single host select Single Address Key Exchange Method Manual Auto...

Page 76: ...tificate page to configure certificates for the gateway Local certificates are used to identify the gateway to other users You can create a new certificate request locally and have it signed by a certificate authority or import an existing certificate Consult ITU T X 509 for additional info regarding Public Key Infrastructure PKI After selecting Advanced Setup Certificate Local from the left navig...

Page 77: ...s an IP address may be Organization Name A free form text field Typically the company name creating the request Country Region Select the Country Region in which this certificate will be employed Click Apply to complete the request Reference ITU X 509 standard for certificate related details The Import Certificate button on the Local landing page facilitates putting the signed Certificate and corr...

Page 78: ...re four trusted certificates on the gateway Store up to four peer certificates using this feature After selecting Advanced Setup Certificate Trusted CA from the left navigation bar click the Import Certificate button The following screen will appear Enter acscert for the Certificate Name field then paste the Certificate details as indicated between the BEGIN and END markers Click Apply to commit t...

Page 79: ...mation simultaneously to multiple destinations The most common scenario being internet television and other streaming media In IP multicast the implementation occurs at the IP routing level where routers create the most efficient distribution paths for packets sent to a destination Select Advanced Setup Multicast from the left navigation bar The screen pictured below will appear Update or complete...

Page 80: ...v1 this value is fixed at 10 seconds Last Member Query Interval Enter the maximum response time within which the host must respond to the Out of Sequence query from the router Default 1000ms IGMP uses this value when router receives and IGMPv2 Leave report indicating at least one host wants to leave the group Upon receiving the Leave report the router confirms the interface is not configured for I...

Page 81: ...This page allows you to configure basic features of the Wi Fi LAN interface You can enable or disable the Wi Fi LAN interface hide the network from active scans set the Wi Fi network name also known as SSID and restrict the channel set based on country requirements After selecting Wireless Basic from the left navigation bar you may modify settings as desired Click Apply Save to commit your setting...

Page 82: ...f Service QOS for applications Enable Wireless Multicast Forwarding Check to enable Wireless Multicast Forwarding WMF Forwards multicast traffic across wireless clients when enabled SSID Enter the the Wi Fi Service Set Identifier SSID here BSSID Enter the Basic Service Set Identifier BSSID Provides the MAC address assigned to the wireless router Country Set the country in which the gateway is depl...

Page 83: ...ity features of the wireless LAN interface You may configuration it manually or via Wi Fi Protected Setup WPS After selecting Wireless Security from the left navigation bar you may modify settings as desired Click Apply Save to commit your settings Note When both STA PIN and Authorized MAC are empty PBC becomes the default value If Hide Access Point is enabled or the MAC filter list is empty with ...

Page 84: ...IN field and Set Authorized Station MAC are left blank the PBC push button mode is automatically made active Set Authorized Station MAC When manually pairing via WPS enter the MAC address of the client device you are trying to connect Set WPS AP Mode Configured Unconfigured Select Configured to have the gateway assign security settings to clients Select Unconfigured when you wish to have an extern...

Page 85: ...re defined as follows Field Name Description Select SSID Select the SSID from the drop down list for the wireless network to which this secu rity configuration will apply WEP Encryption Enabled Disabled Select Enabled to turn on Wired Equivalent Privacy mode Encryption Strength 128 bit 64 bit Select the length of the encryption method 128 bit being the more robust option for security Current Netwo...

Page 86: ...structure RADIUS Port Port 1812 for authentication is a standard for RADIUS authentication per the IETF RFC 2865 Your RADIUS deployment may differ from this Older servers may use port 1645 RADIUS Key Optional Enter the encryption key if required to authenticate to the RADIUS Server specified via the Server IP address above WEP Encryption Enabled Disabled Select Enabled to turn on Wired Equivalent ...

Page 87: ...tion Reference the above table for field descriptions not found in the table for WPA below The individual fields on this screen are defined as follows Field Name Description WPA Group Rekey Interval 1 65535 seconds The frequency with which the gateway automatically updates the group key and sends it to connected LAN client devices WPA WAPI Encryption AES TKIP AES Choose from Advanced Encryption St...

Page 88: ...ny content in the WPA WAPI passphrase field will be ignored WPA Group Rekey Interval 1 65535 seconds The frequency with which the gateway automatically updates the group key and sends it to connected LAN client devices WPA WAPI Encryption AES TKIP AES Choose from Advanced Encryption Standard AES or AES com bined with Temporary Key Integrity Protocol TKIP This field has been pre popu lated with the...

Page 89: ...IP address for the Remote Authentication Dial In User Service server as sociated with your infrastructure RADIUS Port 1 65535 Port 1812 for authentication is a standard for RADIUS authentication per the IETF RFC 2865 Your RADIUS deployment may differ from this Older servers may use port 1645 RADIUS Key Enter the encryption key required to authenticate to the Radius Server specified via the Server ...

Page 90: ...he Base MAC address to be substi tuted for the password When this box is checked any content in the WPA WAPI passphrase field will be ignored WPA Group Rekey Interval 1 65535 seconds The frequency with which the gateway automatically updates the group key and sends it to connected LAN client devices WPA WAPI Encryption AES TKIP AES Choose from Advanced Encryption Standard AES or AES com bined with...

Page 91: ...ion Dial In User Service server as sociated with your infrastructure RADIUS Port Port 1812 for authentication is a standard for RADIUS authentication per the IETF RFC 2865 Your RADIUS deployment may differ from this Older servers may use port 1645 RADIUS Key Enter the encryption key required to authenticate to the Radius Server specified via the Server IP address above WPA WAPI Encryption AES TKIP...

Page 92: ...terval 0 2 147 483 647 seconds The interval that the client must re authenticate with the gateway WPA Group Rekey Interval 1 65535 seconds The frequency with which the gateway automatically updates the group key and sends it to connected LAN client devices WPA WAPI Encryption AES TKIP AES Choose from Advanced Encryption Standard AES or AES com bined with Temporary Key Integrity Protocol TKIP This ...

Page 93: ... network After selecting Wireless MAC Filter from the left navigation bar select an SSID to filter from the drop down list Next select the MAC Restrict Mode Disabled Allow or Deny Use the Add button to add a MAC address to the filter list Click Apply Save to commit the completed entry The individual fields on this screen are defined as follows Field Name Description Select SSID Select the SSID to ...

Page 94: ...point func tionality Wireless bridge functionality will still be available and wireless stations will be able to associate to the Access Point Selecting Disabled in Bridge Restrict will disable wireless bridge restriction Any wireless bridge will be granted access Select ing Enabled or Enabled Scan enables wireless bridge restriction Only those bridges specified via their MAC address in Remote Bri...

Page 95: ...striction When disa bled any wireless bridge will be granted access Choose Enabled or Enabled Scan to turn on wireless bridge restriction Only those bridges selected in the Remote Bridges list will be granted access Use the Refresh button to update the station list when Bridge Restrict is enabled Remote Bridge MAC Address Enter the MAC address es of the remote bridges to be allowed Advanced At Wir...

Page 96: ...Page 96 501 SE Columbia Shores Boulevard Suite 500 Vancouver Washington 98661 USA l 1 360 859 1780 SmartRG Inc Propriety and Confidential All Rights Reserved Copyright 2014 smartrg com ...

Page 97: ...t 20MHz bands Control Sideband Upper Lower Select the appropriate sideband to minimize RF interference from adjacent channels and maximize the throughput Sideband controls only available in 40MHz mode 802 11n rate Select the desired physical transmission rate 802 11n protection Off Auto Select Auto for maximum security but there is a noticeable impact on throughput Select Off for best throughput S...

Page 98: ...en necessary Multicast rate 1 54 Mbps Enter the desired packet transmit rate for multicast Basic Rate Fragmentation Threshold 256 2346 bytes Enter the threshold for what sized packets will be fragmented to a smaller unit size The primary consideration for this setting being the size capability of the circuit A high packet error rate is an indication that a slightly increased Fragmentation Threshol...

Page 99: ...ransmit Power Set the desired output power by percentage WMM Wi Fi Multimedia Auto Enabled Disabled When enable this technology allows multimedia services audio video and voice packets to get higher priority WMM No Acknowledgement Enabled Disabled Refers to the acknowledge policy used at the MAC level Enable no Acknowledgement for better throughput but in the event of a noisy RF environment higher...

Page 100: ...ics Diagnostics from the left navigation bar click the Test button at the bottom of the screen The table will be updated with fresh diagnostic information regarding connection integrity There is significant in line documenta tion regarding each individual test Simply click the Help link at the far right of each line item to learn more about what is being tested and what actions to take in the even...

Page 101: ...er the applicable if any 802 1Q VLAN ID Reference IEEE 802 1ag for additional details The individual fields on this screen are defined as follows Field Name Description Maintenance Domain MD Level 0 7 Maintenance Domains are management space on a network typically owned and operated by a single entity MDs are configured with Names and Levels where the eight levels range from 0 to 7 A hierarchical ...

Page 102: ...ed up to a file stored on your computer After selecting Management Settings Backup from the left navigation bar the following screen will appear Select the type of backup you desire The individual fields on this screen are defined as follows Field Name Description Backup Running Settings This button will locally save a backup file of the currently running settings Backup Default Settings This butt...

Page 103: ...ate from the left navigation bar the following screen will appear Click the appropri ate Choose File button for the type of setting you wish to restore Next browse to the desired conf file located on your personal computer Lastly click the Update button The individual fields on this screen are defined as follows Field Name Description Update Running Settings This button will allow you to select a ...

Page 104: ... Backup and Restore Settings sections of this user guide After selecting Management Settings Restore Default from the left navigation bar the following screen will appear Click the Restore Default Settings button System Log In the System Log you will find a history of error conditions and other events encountered by your gateway Use the features on this screen to view or alter the behavior of the ...

Page 105: ...ooting a situation with a subscriber for which increased detail is required Display Level Options are displayed in top down order of least verbose to most verbose Error option is rec ommended least verbose unless actively troubleshooting a situation with a subscriber for which increased detail is required Mode Control where log events will be sent Choose Remote or Both to send to the specified IP ...

Page 106: ...ers significant advantages in terms of automation and productivity when managing subscriber devices in the field TR 069 Client SmartRG gateways support TR 069 based standards for remote management Utilize this screen to configure the gateway with details about the management ACS Auto Configuration Server to which this gateway will be linked Select Management Management Server TR 069 Management fro...

Page 107: ...o connect to the ACS using the CPE WAN Management Protocol This parameter MUST be in the form of a valid HTTP or HTTPS URL An HTTPS URL indicates that the ACS supports SSL The host portion of this URL is used by the CPE for validating the certificate from the ACS when using certificate based authen tication ACS User Name User name by which this gateway logs in to the ACS ACS Password Password to a...

Page 108: ...Server An entity that receives STUN requests and sends STUN responses STUN servers are generally attached to the public Internet When a STUN server is present within the infrastructure of the Service Provider utilize this screen to configure this gateway with the connectivity specifics for that server After selecting Management Management Server STUN Config check the STUN Server Support button to ...

Page 109: ...smartrg com Internet Time Sync the clock in your gateway with reliable external clocking servers available on the internet After selecting Management Internet Time you may check the checkbox on the first line to enable the Network Time Protocol You may select or input your own NTP servers Select the desired time zone for the gateway Click Apply Save to commit your settings ...

Page 110: ...l All Rights Reserved Copyright 2014 smartrg com Access Control Services Utilize this screen to establish a Service Control List You many control which services FTP HTTP Telnet etc are to be restricted on the LAN After selecting Management Access Control Services you may modify settings as desired Click Apply Save to commit your settings ...

Page 111: ...ewall WAN Port Number Specifies the port the access control applies to on the WAN side for the given service See port information below Service Control List service FTP FTP Service access For WAN this is with default port Service Control List service HTTP HTTP Service access For WAN this is in association with port specified default is port 80 Service Control List service ICMP ICMP Service access ...

Page 112: ...d being acted on for the entered User Name It is termed the old password as the subsequent fields will replaces it with a new password New Password The new password being chosen for the entered User Name Max 16 characters Confirm Password Re enter the desired new password exactly as entered for the previous field Passwords Establish or alter the passwords associated with access to the Gateway Thre...

Page 113: ...ghts Reserved Copyright 2014 smartrg com Update Software Utilize this feature to update the firmware of your SmartRG gateway Software updates for SmartRG product are available for download by SmartRGs direct customers Reboot Occasional troubleshooting measures may require that the router be rebooted The reboot function is located on this screen ...

Page 114: ...ACS Connection Configuration SmartRG gateways are designed to discover their service provider specific ACS management settings without the use of custom firmware SmartRG Inc maintains an activation server that associates a device s MAC address with its service provider s ACS set tings SmartRG gateways contact the activation server to have their ACS settings modified upon initial power up or after ...

Page 115: ... confirm maximum interoperability with the Affinegy ACS solution Cisco Prime Home ACS SmartRG gateways have a long history of Prime Home formerly ClearVision ACS interoperability Calix Compass Consumer Connect ACS In addition to being Calix physical layer certified to ensure Calix access equipment compatibility SmartRG gateways have been tested to confirm maximum interoperabil ity with the Calix C...

Page 116: ...ts LAN Device Discovery Managed Firewall Managed Wi Fi Wi Fi Signal Monitor IPv6 IPTV Ready SR552n Tri mode ADSL2 VDSL2 GigE 5 GE a a 802 11n a a a SR550n Tri mode ADSL2 VDSL2 GigE 3 FE 1 GE a a 802 11n a a a SR510n Tri mode ADSL2 VDSL2 GigE 4 FE 1 GE a a 802 11n a a a SR505n Tri mode ADSL2 VDSL2 GigE 3 FE 1 GE a a 802 11n a a a SR500n Tri mode ADSL2 VDSL2 GigE 4 FE 1 GE a a 802 11n a a a SR400ac ...

Page 117: ...s Boulevard Suite 500 Vancouver Washington 98661 USA l 1 360 859 1780 SmartRG Inc Propriety and Confidential All Rights Reserved Copyright 2014 smartrg com Document Revision History Rev Date Description 3 0 6 26 2014 Initial release ...

Reviews: