background image

© 2020, Amazon Web Services, Inc. or its affiliates. All rights reserved. 

 

 

5.2.2 Adding an IAM Role for the AWS IoT Core for LoRaWAN Destination 

The second role to be configured for the AWS account is AWS IoT Core destination role. This role is allows your 

AWS account to operate with the AWS IoT Core for LoRaWAN and is configured by first defining the policy 

associated with the role, and then creating the role itself. 

 

To create a policy that gives the role permission to describe the IoT endpoint and publish messages to AWS IoT 

Core, follow these steps: 

1.

 

Connect to the 

IAM console 

and select 

Policies

 from the menu on the left. 

2.

 

In the 

Policies

 menu, select 

Create Policy

 and then the 

JSON

 tab. Selecting the 

JSON

 tab will open the 

policy editor where you will replace the existing policy template with the following trust policy 

information: 

    "Version": "2012-10-17",  

    "Statement": [ 

      { 

        "Effect": "Allow",  

        "Action":  

  [  

    "iot:DescribeEndpoint",  

    "iot:Publish"  

  ], 

        "Resource": "*" 

      } 

    ] 

3.

 

After updating the policy, select 

Review Policy

 to open the 

Review Policy

 page and specify a policy name 

of your choice in the 

Name

 field and a description of your choice in the 

Description

 field. 

4.

 

After reviewing the policy and specifying the name and description, select 

Create Policy

 to create the 

policy. A confirmation message indicating that the policy has been created is displayed. 

 

Once the policy for the destination role has been successfully created, you can begin configuring the destination 

role itself. To create the destination role, connect to th

IAM console

 and follow these steps: 

1.

 

Select 

Roles

 from the menu on the left and then select 

Create Role

2.

 

In the 

Create Role

 menu, under 

Select type of trusted entity

, select 

Another AWS Account

.  

3.

 

Enter your account ID in the 

Account ID

 field and select 

Next: Permissions

4.

 

In the 

Permissions

 menu, enter the name of the policy you just created for the destination role in the 

Filter Policies

 search field and select search. Select the check box next to the appropriate policy name to 

begin configuring role to which this policy will be applied. 

5.

 

Once the correct policy is selected from the list, select 

Next: Tags

 and then 

Next: Review 

to review the 

role’s configuration settings. 

6.

 

In the role review page, enter a role name of your choice in the 

Role

 

Name

 field and a description of your 

choice in the 

Description

 field and select 

Create Role 

to the create the IAM destination role. 

7.

 

Once the role is created, you will need to specify the trust relationships and policies for the role to grant 

the AWS IoT Core for LoRaWAN permission to assume this IAM role when delivering messages from 

devices to your AWS account. In the confirmation message that indicates the role has been created, select 

the name you specified for this role

 

to edit the role. 

8.

 

In the resulting role 

Summary

 page, select the 

Trust Relationships

 tab and then select 

Edit Trust 

Relationship

. The principal AWS role in your trust policy document defaults to root and must be changed. 

9.

 

To change the principal AWS role in the trust policy document, navigate to the 

Policy Document

 for the 

role’s trust relationship and replace the existing policy with the following: 

    "Version": "2012-10-17", 

    "Statement": [ 

      { 

Содержание 7310-8

Страница 1: ...2020 Amazon Web Services Inc or its affiliates All rights reserved 7310 8 LoRaWAN Gateway with AWS IoT Core Getting Started Guide...

Страница 2: ...nt Information 3 2 Overview 3 3 Hardware Description 3 4 Configuring your AWS Account and Permissions 3 5 Getting Started with ADTRAN s 7310 8 Gateway 4 6 Configuring the ADTRAN 7310 8 LoRaWAN Gateway...

Страница 3: ...3 1 Data Sheet The data sheet for the ADTRAN 7310 8 gateway can be found here 3 2 Standard Kit Contents The ADTRAN 7310 8 gateway includes the following items in the standard kit ADTRAN s 8 channel En...

Страница 4: ...re required for configuring roles and policies in IAM First you must create an IAM role for the Configuration and Update Server CUPS and review its associated policies and then you must create an AWS...

Страница 5: ...ou MUST enter the role name as IoTWirelessGatewayCertManagerRole and cannot use a different name This is for consistency with future releases 7 Once the role is created you will need to specify the tr...

Страница 6: ...e connect to the IAM console and follow these steps 1 Select Roles from the menu on the left and then select Create Role 2 In the Create Role menu under Select type of trusted entity select Another AW...

Страница 7: ...t the documentation for your gateway to locate this value 5 3 2 Registering the LoRaWAN Gateway To register the LoRaWAN gateway with AWS IoT Core for LoRaWAN connect to the AWS IoT console and follow...

Страница 8: ...in the following sections 5 4 1 Preparation To complete the endpoint device registration process you will need the following information available LoRaWAN region This must match the gateway LoRaWAN r...

Страница 9: ...DlBucketSize4096 AddGwMetadatatrue DevStatusReqFreq 24 DrMax15 TargetPer5 MinGwDiversity1 Proceed in the device configuration only if you have a device and service profile that will work for you 5 4 3...

Страница 10: ...reparation Be sure to enter a name for your device in the Wireless device name optional field 5 Navigate to the Profiles section under Wireless device profile select the appropriate profile from the d...

Страница 11: ...ce s serial number for example 0007 4 To connect to a discovered device select the device from the list and enter your PIN when prompted The PIN will always be the last 5 digits of the of the gateway...

Страница 12: ...mitted and received encapsulated LoRaWAN packets on the port LED Color State Description NET TXNET RX Green Off Indicates no traffic is being passed on the port Flashing Indicates transmitted TX or re...

Страница 13: ...t your gateway from the list by pressing it entering your unique 5 digit PIN and selecting Connect NOTE The PIN is last 5 digits of the device serial number and also the default gateway name For secur...

Страница 14: ...can use the ADTRAN IoT app to verify the 7310 8 gateway information including hardware and software versions serial number part numbers and model information as well as traffic statistics errors and c...

Страница 15: ...nu and select Gateway Status The relevant information is listed in this menu NOTE The Connected Devices count is not currently integrated with AWS Basic Station To verify and configure gateway Etherne...

Страница 16: ...nu Select Reset to Factory Default to return the device to the factory default settings NOTE Restoring the gateway to the factory default settings will clear existing certificates reset counters and r...

Страница 17: ...tions to the 7310 8 Gateway The first step in provisioning the ADTRAN 7310 8 gateway for use with AWS is to upload the configured CUPS certifications to the gateway To upload the CUPS certificates fol...

Страница 18: ...r use with AWS to is provisioning and starting the device s packet forwarding program To provision and start the device s packet forwarding program follow these steps 1 Open the ADTRAN IoT app on your...

Страница 19: ...y and device configuration are completed provisioned OTAA devices can join the AWS IoT network and start to send messages Messages from devices are received by AWS IoT Core for LoRaWAN and then forwar...

Страница 20: ...from the Runtime drop down menu 5 Click on Create function 6 Navigate to provide your github repository URL and copy the code for the lambda function 7 Under Function code paste the copied code into t...

Страница 21: ...o topic The output should look similar to this 8 3 Creating the Destination Rule In this step you create the IoT rule that forwards the device payload to your application This rule is associated with...

Страница 22: ...s been given permission to execute the action 12 Choose Add action 13 Add one more action to invoke the Lambda function Under Set one or more actions choose Add action 14 Choose Send a message to a La...

Страница 23: ...e number you entered is valid you will receive a text message and your phone number will be confirmed 8 Create an Amazon SNS Topic as follows a In the navigation pane choose Topics b Select Create top...

Страница 24: ...to create an IoT analytics rule configure AWS IoT analytics and configure Amazon QuickSight The steps required to perform this configuration are provided in the following sections 8 5 1 Creating an Io...

Страница 25: ...d then select Refresh or Schedule Refresh for periodic refresh of dataset 8 6 Testing your Hello World Application Using your device create a condition to generate an event such as a high temperature...

Страница 26: ...tion connected to AWS The LoRa Radio Sub Band page on the ADTRAN IoT app is not used for AWS 11 OTA Updates The following outlines the OTA update upgrade procedure 1 Connect to the gateway via the ADT...

Отзывы: