background image

www.vscom.de

VPNRouter Manual

Edition: Juli 2016

Edition: Juli 2016

Edition: Juli 2016

Edition: Juli 2016

Edition: Juli 2016

Edition: Juli 2016

Edition: Juli 2016

Edition: Juli 2016

Edition: Juli 2016

Edition: Juli 2016

Edition: Juli 2016

Edition: Juli 2016

Edition: Juli 2016

Edition: Juli 2016

Edition: Juli 2016

Edition: Juli 2016

Edition: Juli 2016

Tel: +49 40 528 401 0

Fax: +49 40 528 401 99

Web:

www.visionsystems.de

Support:

[email protected]

Summary of Contents for VPNRouter iR 2110

Page 1: ...016 Edition Juli 2016 Edition Juli 2016 Edition Juli 2016 Edition Juli 2016 Edition Juli 2016 Edition Juli 2016 Edition Juli 2016 Edition Juli 2016 Edition Juli 2016 Edition Juli 2016 Edition Juli 2016 Edition Juli 2016 Tel 49 40 528 401 0 Fax 49 40 528 401 99 Web www visionsystems de Support service visionsystems de ...

Page 2: ... is without warranty of any kind either expressed or implied including but not limited to its particular purpose Vision Systems reserves the right to make improvements and or changes to this manual or to the products and or the programs described in this manual at any time Information provided in this manual is intended to be accurate and reliable However Vision Systems assumes no responsibility f...

Page 3: ...ons of VPNRouter iR 5221 and VPNRouter iR 3220 15 4 1 Power 15 4 1 1 Connection and Polarity 15 4 1 2 Grounding 17 4 2 WLAN Switch 17 4 3 Digital I O 17 4 3 1 Digital Input 18 4 3 2 Digital Output 18 4 3 3 I C Interface 18 4 3 4 Auxiliary Power 18 4 4 Antenna Locations 18 4 5 LED 19 4 6 LAN 19 4 7 WAN 19 4 8 USB 19 4 9 Serial 20 4 9 1 DIP Con guration for Serial Ports 20 4 10 SD Slot 20 4 11 SIM S...

Page 4: ... 2 by 3G 4G Connection 32 7 1 3 3 by Wi Connection 32 7 2 Wi 33 7 2 1 Networks 33 7 2 1 1 WLAN scanned 34 7 2 2 Adapter 34 7 2 3 Local Network 35 7 2 4 Con guration Procedures 36 7 2 4 1 as Access Point 36 7 2 4 2 as Client 36 7 3 3G 4G 37 7 4 DHCP 38 7 4 1 DHCP Server 38 7 4 2 Active Leases 39 7 4 2 1 Automatic Detection of local Devices 39 7 4 3 Static Leases 39 7 4 4 Issues 41 8 System 41 8 1 G...

Page 5: ... 64 9 4 2 3 Client Settings 65 9 4 2 3 1 Client LAN IPv4 Address 65 9 4 2 3 2 Client LAN IPv4 Netmask 65 9 4 2 3 3 Upload Client Certi cates and Keys 65 9 4 2 4 Delete a Client 66 9 4 3 Generate Certi cates and Keys 67 A History 68 B License 68 List of Figures 1 Appearance VPNRouter iR 5221 12 2 Appearance VPNRouter iR 3220 13 4 Mounting Positions VPNRouter iR 5221 VPNRouter iR 3220 14 3 Appearanc...

Page 6: ...G 4G Con guration 32 41 Wi Con guration 32 42 Wi Networks 33 43 Wi Scan Results 34 44 Wi Radio Parameters 34 45 Wi Network 35 46 3G 4G Interface 37 47 DHCP Address Range 38 48 Active Leases 39 49 Static Leases 39 50 Menu System 41 51 System General Information 42 52 Select Language 43 53 Set Admin Password 43 54 Backup Restore 44 55 Flash Firmware 44 56 Reboot the Device 45 57 Menu Services 46 58 ...

Page 7: ...rivate addresses 61 73 SimpleVPN Server LAN Netmask 62 74 SimpleVPN Transport Protocol 62 75 OpenVPN Port 63 76 OpenVPN client to client 63 77 Add a Client 64 78 Client overview 64 79 SimpleVPN Client LAN IPv4 Address 65 80 SimpleVPN Client LAN Netmask 65 81 Client delete 66 82 Generate Certi cates and Keys 67 83 Buttons Generate and Generate DH Parameters 67 Juli 2016 VPNRouter Software Manual 7 ...

Page 8: ... is supported by showing the text in certain styles Software text is written in a slanted style Such item represents text output written on the screen User Input Input forms require the user to type some data on the keyboard Text written in style of a typewriter represents this input A Button Controling the software will also require to click some buttons These buttons are represented by the name ...

Page 9: ...1000 Gigabit Ethernet WLAN optional IEEE 802 11b g n CAN Bus 1 x CAN Bus 20 kbps to 1 Mbps VPNRouter iR 5221 only Serial Ports 2 x RS232 RS422 RS485 up to 3 7 Mbps Digital I O 4 x input signals 4 x output signals 32 mA max Console Port RS232 up to 115200bps I C max 400 kHz RTC yes Watch Dog Timer yes MiniPCIe Slot yes with SIM Card Slot Reset Button HW Reset Power Input 12 50V DC Power Consumption...

Page 10: ... 1 Ethernet Two independent ports for Ethernet are available in VPNRouter with separate MAC Addresses One port is implemented as GigaLAN for 10 100 1000 Mbit s the other provides an internal Eth ernet switch for Fast Ethernet function 10 100 Mbit s The VPNRouter iR 5221 provides four Fast Ethernet ports on VPNRouter iR 3220 there are two of them and VPNRouter iR 2110 has only one missing the Ether...

Page 11: ...s Table 3 Serial Interface Speci cations 2 1 5 Digital I O Four input and four output signals at TTL level are provided For input signals the change of at least one input signal generates an interrupt See Section 4 3 on page 17 for electrical characteristics The VPNRouter iR 2110 does not have these 2 1 6 I C One port for external I C function is provided The signals originate in a repeater to pro...

Page 12: ...3 Appearance 3 1 VPNRouter iR 5221 a Top View b Front View c Bottom View Figure 1 Appearance VPNRouter iR 5221 Juli 2016 VPNRouter Software Manual 12 ...

Page 13: ...3220 a Top View b Front View c Bottom View Figure 2 Appearance VPNRouter iR 3220 The VPNRouter iR 3220 provides two ports for LAN the CAN Bus connector and the USB OTG port are not implemented Juli 2016 VPNRouter Software Manual 13 ...

Page 14: ... slot for a microSD card The rear side provides the socket for the terminal block power connector On this side also a DIN Rail clamp may be mounted The DIP switches de ne the operation mode of the serial port There is a possible location for a WLAN antenna The Reset button is pushed by a small prick 3 4 Mechanics for Mounting This are the positions of screws for mounting The groups of three on the...

Page 15: ...e Connect the cable to the power jack at the top side of VPNRouter and plug the adapter into the socket The Power LED red on VPNRouter will light You can connect a power supply of your choice providing the technical requirements are met Warning disconnect the VPNRouter from power supply before performing installation or wiring The wire size must follow the maximum current speci cations The maximum...

Page 16: ...4 Position of Connectors and Functions of VPNRouter iR 5221 and VPNRouter iR 3220 a Front Side b Rear Side Figure 5 Mounting Positions VPNRouter iR 2110 Juli 2016 VPNRouter Software Manual 16 ...

Page 17: ...Protective Earth This is the purpose of the dedicated PE Screw on the case top rear side Figure 7 PE Screw 4 2 WLAN Switch The WLAN switch on the top side is used to disable the WLAN function Provided the VPNRouter is equipped with a WLAN module Otherwise software may just read this switch for other purposes Figure 8 WLAN Switch 4 3 Digital I O The functions of Digital Input and Output are located...

Page 18: ...4mA TTL 0 0 to 0 6V Table 7 Digital Output Electrical Characteristics 4 3 3 I C Interface The I C interface operates with a maximum frequency of 400 kHz Fast Mode The connector for I C is located on the terminal digital I O block and has three contacts SCL SDA and GND clamps 11 to 13 When required the I C device can be powered with the VCC auxiliary output of the digital I O terminal block 4 3 4 A...

Page 19: ... LED on RJ45 right will light When data tra c occurs on the network this LED will blink It depends on your network or devices whether a 100 Mbit or a 10 Mbit connect will be established The Speed LED left lights for 100Mbps connections Figure 12 LAN ports 4 7 WAN The second Ethernet port in VPNRouter is for 10 100 1000 Mbps Gigabit Ethernet The connector is the usual RJ45 integrated with USB ports...

Page 20: ...5 wire respectively With the exception of very special con gurations a serial connection in RS422 RS485 mode without GND connection violates the speci cations for RS422 and RS485 standards 4 9 1 DIP Con guration for Serial Ports The right side of the case has a small opening slit This is provided to access the DIP switches for serial con guration With a small pen or screw driver the con guration c...

Page 21: ...n RJ45 connector on the bottom side An adapter cable to DSub 9 female is available as part of the Starter Kit Pin Signal 3 GND 4 TxD 5 RxD a Console RJ45 Pin Signal 2 TxD 3 RxD 5 GND b Console DSub 9 female Table 9 Serial Console Port Figure 18 Console Port 4 14 USB OTG Only available on VPNRouter iR 5221 A connector of micro AB type pro vides one extra USB channel This port can operate in Host or...

Page 22: ...aximum possible current in the power wires as well as in the common wires must be taken under consideration If the current rises above the maximum ratings the wiring can overheat causing serious damage to your equipment When powered the VPNRouter internal components generate heat and consequently the outer case may feel warm to the touch 5 1 1 Connection and Polarity Power is connected via three c...

Page 23: ... special purpose coupled to the switches Customers softwar can read the con guration and evaluate for own intentions Figure 23 DIP Switches 5 3 Antenna Locations The VPNRouter is prepared for adding one antenna socket of the usual SMA type Possible locations are on the rear and on the left side top wide when mounted on a DIN Rail Both are covered by plastic caps Figure 24 Antenna location 5 4 Rese...

Page 24: ...nRISC VPNRouter iR 2110 provides a USB 2 0 Host inter face This can be used for Mass Storage Devices like Flash or Hard Drive Bluetooth and WLAN adapters etc Figure 27 USB Connector 5 7 LED The front side holds a group of three LEDs PWR Red lights when power is applied to the VPNRouter System soft ware may generate short blinks for certain events WIFI Blue signals operation status of WLAN function...

Page 25: ...n same signal assignment as the RS 422 The RS485 Standard Mode is alternatively referred to as Half Duplex Mode 2 wire connection or Bus Mode It uses the same two wires for transmit and receive So it would be possible to simultaneously receive the same data the port just transmitted this is often named an Echo The serial port in VPNRouter intentionally suppresses this Echo In the rare situations w...

Page 26: ...rk connection to the Device where you then open your browser to access the web interface Basically there is one way to get the required access In the description here it is assumed the Device is in factory con guration 6 1 Connect to the Device 6 1 1 Ethernet Cable to LAN Port That is the option for on site access i e you are in front of the Device Plug the Ethernet cable from your PC into a LAN p...

Page 27: ...o views Administation and Essentials of the web interface we only describe the Essentials view Use the Administration view if you are experienced and need special features a Save and Reset but tons b Apply Changes Figure 34 Save Con guration Changes The pages use two buttons on the bottom right to apply the parameters or discard the changes Button Save will save the new parameters and apply them a...

Page 28: ...WLAN function and 3G 4G con gures an in terface for 3G UMTS or 4G LTE communication via mobile com munication networks These two items only appear if the required interface hardware is available otherwise they are hidden A click on the top button Network opens the item General Juli 2016 VPNRouter Software Manual 28 ...

Page 29: ...here are many sections on the web page explained block by block Figure 36 Network General Overview Save con guration changes using the buttons on the bottom line see gure 34a on page 27 Juli 2016 VPNRouter Software Manual 29 ...

Page 30: ... all these values counted from the last reboot or power on of the Device 7 1 2 Local Network The Local Network references the Ethernet ports labelled LAN on the front side Figure 38 Local Network Con guration This adress should be from the IPv4 address ranges assigned to private networks The following IP blocks are reserved for private IP addresses Class Starting IP Address Ending IP Address of Ho...

Page 31: ...Address Assignment on WAN interface is done by DHCP automatic With this con guration on startup the Device will send a special request to get a valid con guration Figure 39 WAN connection If that automatic is disabled by selecting static in the drop down the next four input elds appear A static IP Address con guration is necessary and the network administrator has to provide this information to yo...

Page 32: ... WLAN function Then this is con gured for the Operation Mode as Client see section 7 2 3 on page 35 Figure 41 Wi Con guration By default the con guration of the WLAN Client connection is automatic like for the WAN port see 7 1 3 1 on the previous page Then the other parameters are hidden from view If the eld Protocol has a the value static a static IP Address con guration is necessary Again the ne...

Page 33: ...n the bottom line gure 34a on page 27 A suggested sequence of con guration steps is at the end of this section 7 2 4 Con guration Transfer If the Wi Adapter in target and source is con gured for operation as Access Point there is no risk in transfering the con guration However if either is con gured in Client Mode often it is used for Internet Access then A transfer of parameters will likely disru...

Page 34: ...n provided by the network administra tor In Client mode you do not need to select the Channel the Adapter follows the con guration of the Access Point it connects to gure 43 In AP mode you have to select the channel to operate on please check with the network administrator which parameter to use The selectable values range from 1 2 4GHz to 14 2 4GHz plus auto Please also check with local regulatio...

Page 35: ... that in Client Mode when the WLAN net does not support better security WPA PSK WPA2 PSK and WPA PSK WPA2 PSK Mixed Mode This is state of the art encryption Use this in Access Point Mode and select a secure Pre Shared Key PSK WPA2 is the best choice but WPA is still secure WPA Radius and WPA2 Radius These are usable in Client Mode only since in AP Mode the Device does not have access to a Radius S...

Page 36: ...rt 8 Click on the Save button and wait for the changes to be applied 7 2 4 2 as Client 1 Under Adapter check Enable 2 Under Local Network select Operation as Join Client 3 Click on the Save button and wait for the changes to be applied 4 Under Networks click the button for Scan and wait for the results Check if the target WLAN network is visible 5 Under Adapter select the Mode according to the res...

Page 37: ...interface are provided by the mobile communication provider together with the SIM Card In the eld Mode may select from a set of options like All LTE UMTS GSM UMTS or CDMA The actual values available depend on the model of communication card and what is provided by use of the given SIM Card Enter APN for Internet access and PIN to authenticate for the SIM Card The PAP CHAP username and PAP CHAP pas...

Page 38: ...nt IP Address An IP Address assigned to a client is named as a Lease in context of DHCP The server has a list of known clients it will identify them by their MAC Address If the client is on this list it gets the pre de ned IP Address reserved for this client as an o er No other client will ever get this IP Address For clients not on this list on their rst contact to the server they receive an o er...

Page 39: ...on of local Devices happens under a few restrictions If a device uses static IP Address con guration it will not send a request to the DHCP server So at rst the server has no knowledge about that device But the server monitors certain local network tra c and will detect static devices when they become active on the network These are added to the list of Active Leases for information Since This pag...

Page 40: ...t this happens when the client previously was active on the local network Or select custom from the list and manually type the value e g 03 10 17 76 0D 0A 3 Select the IP Address If the client was active on the local network you may just select the entry from the drop down list Or again select custom and type the complete IP Address You may later change the entry by modifying the values in the sam...

Page 41: ...the IP Address is not in the Start to End range of the server or better there shall be an entry in the Static Leases to reserve this address Wi When the Wi adapter is operating in AP mode connected clients receive their IP Address con guration from the Device s DHCP server In general this is a positive e ect 8 System Figure 50 Menu System The Menu System lists the items of General Language Admin P...

Page 42: ... the VPNRouter Router Model with its Hardware Revision these are xed The rmware in the Device consists of two components so the Firmware Version actually displays two values With rmware upgrades these values will change of course The Serial Number is printed on the case of the Device Some statistical parameters like Uptime System Load and usable Memory are shown Juli 2016 VPNRouter Software Manual...

Page 43: ...not need explanation Save the con guration using the button Save as usual 8 3 Admin Password Figure 53 Set Admin Password By default there is no password set On this page you can set a password Click on the button Submit and wait for the changes to be applied A password protects the Web UI User Interface against unauthorized access 8 4 Backup Restore The purpose of this functions are given on the ...

Page 44: ... the device To discard the con guration in the Device click on the Perform reset link 8 4 3 Restore backup To restore con guration les you can upload a previously generated backup archive 8 5 Flash Firmware Figure 55 Flash Firmware To ash the rmware upload the new rmware image The current rmware image of the VPNRouter can be downloaded from Attention By default the checkmark is set Please make sur...

Page 45: ...m 8 6 Reboot Figure 56 Reboot the Device In normal circumstances it is not necessary to reboot the Device If you feel you need to do this click on the Perform reboot link Juli 2016 VPNRouter Software Manual 45 ...

Page 46: ...ace NetCom refers to the two serial ports and allows to use them in the same way as the VScom NetCom Mini de vices And NET CAN refers to a CAN bus interface available for remote control via the VPNRouter tunnel in the same way as the VScom NET CAN 110 The function of NET CAN is only available if a CAN bus interface exists on the model SimpleVPN serves for con guration of an virtual private network...

Page 47: ...r IN1 In this example gure 58 the Mode is xed as Input and Output For Input direction you can read the State of the external signal 0 is for low voltage or an inactive signal while 1 represents high voltage on an active signal For Output direction you may check a signal to make it active then the output is high voltage Without checkmark the State is inactive i e low voltage Juli 2016 VPNRouter Sof...

Page 48: ...the DIP switches is select by software OFF OFF ON ON the con guration of the SW Mode is valid The SW Mode supports the modes RS 232 RS 422 RS 422 with termination RS 485 full duplex RS 485 full duplex with termination RS 485 half duplex RS 485 half duplex with termination DIP switches con gured mode and loopback mode The connection for remote control is via TCP IP so a TCP Port is required By defa...

Page 49: ... RFC2217 The remote control functions are not limited to transmit and receive serial data to a connected machine It is also possible to control the status and operation mode of the serial port The Telnet Protocol extension known as RFC 2217 is used for that purpose the other choice is TCP raw With that second choice indeed only transmit and receive with a xed con guration is possible Let the Telne...

Page 50: ... values At the bottom the entry of custom let you type the desired rate into the box e g 31250 The DataBits are possible as 8 or 7 The Parity is available with the choice of None Even and Odd The StopBit may have a duration of 1 or 2 data bits Finally the FlowType is usable as None no control XON XOFF software ow control and RTS CTS hardware handshake Activate the new con guration using the Save b...

Page 51: ...rom remote locations and the LAN ports It supports the same VSCAN library as the VScom NET CAN CAN Gateways Figure 62 NET CAN Con guration The con guration for remote control just requires to de ne the network parameters Here only the TCP Port is necessary the default value is 5030 Juli 2016 VPNRouter Software Manual 51 ...

Page 52: ...ial routers so that all routers have a functional con guration after this dialog Note The service SimpleVPN is only important if you have a set of industrial routers There are several options on this web page that will be explained block by block You can make all relevant settings which are needed for a virtual private network VPN on this page Figure 63 Overview SimpleVPN Juli 2016 VPNRouter Softw...

Page 53: ...lients see section 9 4 1 1 on the next page Note This point is only important if you are con guring the industrial routers for the rst time 2 Modify existing con gurations and transfer the new con guration to VPNRouter Clients see section 9 4 1 2 on page 55 Figure 65 Overview transfer SimpleVPN The gure 65 shows the di erent ways to transfer con gurations Juli 2016 VPNRouter Software Manual 53 ...

Page 54: ...at e 2 via USB corresponds to point 2 of gure 65 on the previous page a Make sure that the USB stick is connected to the USB port on the device b Check that the con guration is correct and certi cates and keys are present c When you use the button via USB in the area Send Save Partner con guration a new folder will be created on the USB Stick with con gurations certi cates and keys in it d Disconn...

Page 55: ... green j Continue with the remaining Routers at e 9 4 1 2 Existing con gurations Attention Changes in the exsiting VPN network should only be made if it is necessary There are two options to modify existing con gurations 1 via Cable a Make sure that the devices are connected together via the LAN port b Using the button via Cable in the area Get Partner con guration to get the con guration from the...

Page 56: ...ings hnd cannot be used The following table shows the gener alave been made click on the button Save Apply and wait for the changes to be applied f Transfer the con guration see section 2 on page 54 Juli 2016 VPNRouter Software Manual 56 ...

Page 57: ...e network VPN to connect two or more locations with an encrypted tunnel The advantage of a VPN is that it expands an existing network over the Internet while ensuring to transmit sensitive data in a way that protects it from tampering and interception This service helps to make the necessary settings step by step The current device is automatically the Server It allows to con gure multiple devices...

Page 58: ...ecessary The resulting DNS name belongs in this eld in that case To make the Router accessible you may need to do a few more steps explained in the following section 9 4 2 1 2 Server Mode and Client Mode It is possible to use the devices in two di erent varia tion You can use the device as Internet Router or VPN Gateway a Server Mode b Client Mode Figure 68 Server and Client Mode Di erence between...

Page 59: ...9 Services Figure 69 Internet Router Juli 2016 VPNRouter Software Manual 59 ...

Page 60: ...nel If the VPNRouter acts as VPN Server the router of the existing local network has to assign the VPN port to this VPN router port forwarding Every device that may use the VPN has to have a route to the VPNRouter for every subnet it may access This may be done in the router or in every device Figure 70 VPN Gateway Juli 2016 VPNRouter Software Manual 60 ...

Page 61: ...ou can use one of the other classes In an IP network two addresses are always automatically assigned For example in 192 168 1 0 24 0 is the assigned network address In 192 168 1 255 24 255 is the assigned broadcast address The 0 and 255 are always assigned and should not be used for hosts Please do not use the two IPv4 addresses which are used to connect the encrypted VPN tunnel also do not use ad...

Page 62: ... selected Figure 74 SimpleVPN Transport Protocol TCP is a connection oriented stream over an IP network It guarantees that all sent packets will reach the destination in the correct order This imply the use of acknowledgement packets sent back to the sender and automatic retransmission causing additional delays and a general less e cient transmission than UDP UDP is a connection less protocol Comm...

Page 63: ...if you would like connecting clients to be able to reach each other over the VPN By default clients will only be able to reach the server Figure 76 OpenVPN client to client 9 4 2 1 8 Upload Server Certi cates and Keys You will need the following certi cates and keys for the server Certi cate authority Di e Hellman parameters Server certi cate Server private key Click on the button Browse and selec...

Page 64: ... client in the appropriate eld For example Client_1 To add the client please click on the button Add Figure 77 Add a Client It appears an area where you can con gure the Client See section 9 4 2 3 Figure 78 Client overview Juli 2016 VPNRouter Software Manual 64 ...

Page 65: ...ncrypted VPN tunnel also do not use addresses of the 10 8 0 0 24 range The gure 72 shows the di erence between public and private IP addresses 9 4 2 3 2 Client LAN IPv4 Netmask Please choose the corresponding netmask for the private IPv4 address A netmask is a 32 bit mask used to divide an IP address into subnets and specify the networks available hosts Figure 80 SimpleVPN Client LAN Netmask The t...

Page 66: ... It is possible to delete a created client The client will be removed from the virtual private network VPN Use the button Delete on the right side to remove a created client Figure 81 Client delete Juli 2016 VPNRouter Software Manual 66 ...

Page 67: ...Parameters If you click on the button Generate the certi cates and keys will automatically be generated in the background A set of Di e Hellman parameters are already on the Router because the generation process on the device may take a considerable time They will become visible after the generation the other keys and certi cates Use the button Generate DH Parameters to calculate and get new Di e ...

Page 68: ...istory Juli 2016 Release Manual B License Figure 66 69 70 65 72 build upon VRT Network Equipment Shape Gallery for LibreO ce OpenO ce by VRT Systems licensed under CC BY SA 3 0 Juli 2016 VPNRouter Software Manual 68 ...

Reviews: