background image

 

136 

Configuring L2TP Dial-in in the head office 

The IP address 192.168.1.200 will be assigned to the router located in the branch office. Please make 
sure this IP is not used in the head office LAN.

  

 

Item 

Description 

Connection Name 

HS-LL 

Give a name of L2TP conneciton 

Connection Mode 

Dial in 

Operate as L2TP server 

Authentication Type 

Chap/Pap 

Authentication type 

Username 

Test 

Dial in authenticate user name 

Passwrod 

Test 

Dial in authenticate user password 

Assigned IP 

192.168.1.200 

An IP assigned to the dial in client 

Conneciton Type 

LAN to LAN 

LAN to LAN for dial in 

Remote Network IP 

129.168.0.0 

Remote access network 

Remote Network Netmask 

255.255.255.0 

 

 

 

Содержание BiPAC 4700AZ

Страница 1: ...Last revised date November 22 2017 BiPAC 4700AZ Wireless AC 4G LTE VPN Outdoor Router User Manual Version release 1 04 1 x...

Страница 2: ...n 13 Installation Reference 14 Cabling 17 Default Settings 18 Information from Your ISP 19 Chapter 4 Device Configuration 20 Login to your Device 20 Status 22 Device Info 23 System Status 25 System Lo...

Страница 3: ...102 Static DNS 107 Time Schedule 108 Mail Alert 109 VPN 110 IPSec 111 PPTP Server 121 PPTP Client 123 L2TP 132 GRE Tunnel 142 OpenVPN Server 147 OpenVPN Client 149 Access Management 154 Device Manage...

Страница 4: ...3 Problems with the Router 182 Problem with LAN Interface 182 Recovery Procedures 182 Appendix Product Support Contact 184...

Страница 5: ...nd the extreme weather conditions Also built in 6K surge K 21 and 15KV ESD EN 61000 4 5 protection design protects against storm lightning surges and ensuring robust and reliable operation Easy Instal...

Страница 6: ...col stacks either independently or in a hybrid form The hybrid form is commonly implemented in modern operating systems supporting IPv6 Quick Start Wizard Support a WEB GUI page to install this device...

Страница 7: ...ired Equivalent Privacy WEP support Wireless Hotspot Enterprise level routing functionality OSPF BGP Firewall Security with DoS Preventing and Packet Filtering Universal Plug and Play UPnP Compliance...

Страница 8: ...twork VPN Secured IPSec VPN with powerful DES AES Secured PPTP VPN with Pap Chap MPPE authentication Secured L2TP VPN with Pap Chap authentication Secured GRE VPN tunnels Secured OpenVPN Server and Cl...

Страница 9: ...or remote and local management Firmware upgrades and configuration data upload and download via web based GUI Supports DHCP server client relay Supports SNMP v1 v2 v3 MIB I and MIB II CWMP TR 069 1 su...

Страница 10: ...card slot One 1 Gigabit Ethernet WAN for Cable Fiber xDSL high WAN throughput One 1 Gigabit Ethernet LAN with PoE can obtain power via 802 3at PoE equipped switch or power injector Four 4 detachable 5...

Страница 11: ...7 Application Diagram BiPAC 4700AZ...

Страница 12: ...uter Do not use the router in high humidity or high temperature Do not open or repair the case yourself If the device becomes too hot turn off the power immediately and have it repaired at a qualified...

Страница 13: ...ors for the 802 11n 2 4GHz 2 Reset After the device is powered on press it 6 seconds or above to restore to factory default settings this is used when you cannot login to the router e g forgot your pa...

Страница 14: ...99 dBm Poor signal condition Orange No signal and the 4G LTE module is in service Off No LTE module or LTE module fails 7 Power LED The Power dual colour LED behaves as shown below Green System is up...

Страница 15: ...11 Index Item Description 12 WiFi Antenna Connectors for 5GHz Manually screw the two supplied wireless antennas 5G tight to the connectors for the 802 11ac 5GHz 12 12 12 12...

Страница 16: ...re starting recovery process please configure the IP address of the PC as 192 168 1 100 and proceed with the following step by step guide 1 Power the router off 2 Press reset button and power on the r...

Страница 17: ...ress in the range of 192 168 1 1 to 192 168 1 253 The best and easiest way is to configure the PC to get an IP address automatically from the router using DHCP If you encounter any problems accessing...

Страница 18: ...n Reference IMPORTANT It is recommended to put the Gigabit PoE Injector on an UPS or Surge Protector Use the supplied grounding wire to ground your BiPAC 4700ZU 4700ZUL ODU is REQUIRED I Grounding the...

Страница 19: ...the mental contacts gold plate facing down to the SIM slot then push it all the way in until you hear the clicking sound 3 Screw the cap back tightly Attention Please power off the device before inser...

Страница 20: ...f D 2 2 clip B on C 2 3 keep B close to D 2 4 then tighten A Step 3 Insert the other end of outdoor Ethernet cable RJ 45 to the supplied Gigabit PoE injector Data Power port Connect another Ethernet c...

Страница 21: ...uses of problems is bad cabling Make sure that all connected devices are turned on On the front panel of the product is a bank of LEDs Verify that the LAN Link and LEDs are lit If they are not verify...

Страница 22: ...Settings IP Address 192 168 1 254 Subnet Mask 255 255 255 0 DHCP Server DHCP server is enabled Start IP Address 192 168 1 100 IP pool counts 20 Attention If you ever forget the username password to lo...

Страница 23: ...ion from Your ISP Before configuring this device you have to check with your ISP Internet Service Provider what kind of service is provided such as 4G LTE or EWAN Dynamic IP address Static IP address...

Страница 24: ...IP address of your router which by default is 192 168 1 254 and click Go a user name and password window prompt appears The default username and password is admin and admin respectively for the Admin...

Страница 25: ...includes Status Device Info System Status System Log 4G LTE Status Wireless Status Hotspot Status Statistics DHCP Table IPSec Status PPTP Status L2TP Status GRE Status OpenVPN Status ARP Table VRRP S...

Страница 26: ...n check the router working status including Device Info System Status System Log 4G LTE Status Wireless Status Hotspot Status Statistics DHCP Table IPSec Status PPTP Status L2TP Status GRE Status Open...

Страница 27: ...e current date and time System Up Time The duration since system is up Physical Port Status Here the page shows the status of physical port of 4G LTE EWAN Ethernet Wireless 2 4G and Wireless 5G WAN In...

Страница 28: ...th Subnet mask for IPv4 or Prefix length for IPv6 on LAN DHCP Server LAN port DHCP information Wireless 2 4G Wireless 5G Mode The wireless mode in use SSID The SSID Channel The current channel Securit...

Страница 29: ...rent system CPU and Memory loading CPU Usage To show the current CPU Usage Memory Total To show the total memory of the system in KB Memory Free To show the current free memory or avalavle memory in K...

Страница 30: ...Log In system log you can check the operations status and any glitches to the router Refresh Press this button to refresh the statistics Backup Back up the current system log file and save it to your...

Страница 31: ...ength and is calculated based on both RSRP and RSSI SINR Signal to Interference plus Noise Ratio is also a measure of signal quality as well It is widely used by the operators as it provides a clear r...

Страница 32: ...ce the biling begins each month the beginning day counted Clean To clear the usage statistics Save Press to save the usage statistics to FLASH else the usage will be cleared after reboot Refresh Press...

Страница 33: ...eless connection information MAC The MAC address of wireless client SSID Index The SSID index which wireless client connects to RSSI The received signal strength indication Connected Time Connection t...

Страница 34: ...connect in IP Address The IP assigned to the client Authenticated Show the client is authorized or not User Name The username of the logined client in agreement mode no username showed Duration Time...

Страница 35: ...tted until the latest second since system is up Receive Frames of Current Connection This field displays the number of frames received until the latest second for the current connection Receive Bytes...

Страница 36: ...Receive Frames This field displays the number of frames received until the latest second Receive Multicast Frames This field displays the number of multicast frames received until the latest second R...

Страница 37: ...eive Frames This field displays the number of frames received until the latest second Receive Multicast Frames This field displays the number of multicast frames received until the latest second Recei...

Страница 38: ...the latest second Receive Frames This field displays the number of frames received until the latest second Receive Error Frames This field displays the number of error frames received until the latest...

Страница 39: ...he latest second Receive Frames This field displays the number of frames received until the latest second Receive Error Frames This field displays the number of error frames received until the latest...

Страница 40: ...ith clear information Index The index identifying the connected devices Host Name Show the hostname of the PC IP Address The IP allocated to the device MAC Address The MAC of the connected device Expi...

Страница 41: ...l is active for connection Connection State Show the IPSec phase 1 and phase 2 connecting status Statistics Display the upstream downstream traffic per session in KB The value clears when session disc...

Страница 42: ...tion Connection State Show the connecting status Connection Type Remote Access or LAN to LAN Assigned IP Address Show the IP assigned to the client by PPTP Server Server IP Address Show the IP of remo...

Страница 43: ...Active Show if the tunnel is active for connection Connection State Show the connecting status Connection Mode The L2TP mode is dialin or dialout Connection Type Remote Access or LAN to LAN Tunnel Re...

Страница 44: ...on Name Display the user defined GRE connection name Active Show if the tunnel is active for connection Remote Gateway IP The IP of the remote GRE gateway Remote Network Display the remote network Ref...

Страница 45: ...to demosntrate the rule is active or not Service Port Show the service port protocl Tunnel Network The virtual tunnel subnet of the server Status The status of the rule Remote Server Show the remote s...

Страница 46: ...le which shows the mapping of IP addresses to Ethernet MAC addresses Index The Index of the ARP rule item IP Address Shows the IP Address of the device that the MAC address maps to MAC Address Shows t...

Страница 47: ...43 VRRP Status Show the VRRP status Current Status Show VRRP current status Master or Backup Current Master Show the IP address of current master...

Страница 48: ...e For detailed instructions on configuring WAN settings see refer to the Interface Setup section Click Next to move on to Step 1 Step 1 Password Set new password of the admin account to access for rou...

Страница 49: ...xt to continue Input all relevant 3G 4G LTE parameters from your ISP 4 2 If selected EWAN If selected PPPoE please enter PPPoE account information provided by your ISP Click Next to continue Or others...

Страница 50: ...46 Step 5 Quick Start Completed The Setup Wizard has completed Click on Back to modify changes or mistakes Click Next to save the current settings Step 6 Quick Start Completed...

Страница 51: ...on Click to access and configure the available features in the following Interface Setup Dual WAN Hotspot Advanced Setup VPN Access Management and Maintenance These functions are described in the foll...

Страница 52: ...48 Interface Setup Here are the features under Interface Setup Internet LAN Wireless Wireless MAC Filter and Loopback...

Страница 53: ...er this circumstance often only one PC is connected to the device Network Mode There are some options of service standards Automatic UMTS 3G only GSM 2G Only LTE Only If you are not sure which mode to...

Страница 54: ...on Keep Alive IP Enter the IP address whic is used for ping and router will ping the IP to find whether the connection is on or not if not router will recover the connection Default Route Select Yes...

Страница 55: ...priate operator SMS Control SMS Short Message Service allows users to send short message using your smartphone to the SIM card s number to control the device remotely SMS Control Check to enable the S...

Страница 56: ...52 EWAN...

Страница 57: ...er will not accept the IP address if it is not in this format PPPoE Select this option if your ISP requires you to use a PPPoE connection Bridge Select this mode if you want to use this device as an O...

Страница 58: ...um Segment Size MSS IP Options Default Route Select Yes to use this interface as default route interface TCP MTU Option Enter the maximum packet that can be transmitted Default MTU is set to 1492 IPv4...

Страница 59: ...up Multicast Protocol is a network layer protocol used to establish membership in a Multicast group Choose whether enable IGMP proxy IPv6 Options only when choose IPv4 IPv6 or just IPv6 in IP version...

Страница 60: ...56 LAN A Local Area Network LAN is a shared communication system to which many computers are attached and is limited to the immediate area usually the same building or floor of a building...

Страница 61: ...at have members of that group Dynamic Route Select the RIP version from RIP1 or RIP2 DHCPv4 Server DHCP Dynamic Host Configuration Protocol allows individual clients to obtain TCP IP configuration at...

Страница 62: ...example 00 0A F7 45 6D ED When added you can see the ones listed as showed below IPv6 parameters The IPv6 address composes of two parts thus the prefix and the interface ID Interface Address Prefix L...

Страница 63: ...prefix message and generate an address using a combination of locally available information MAC address and information prefix advertised by routers but they can obtain such information like DNS from...

Страница 64: ...tion introduces the wireless LAN and some basic configurations Wireless LANs can be as complex as a number of computers with wireless LAN cards communicating through access points which bridge network...

Страница 65: ...e between 20 and 1000 A beacon is a packet broadcast by the Router to synchronize the wireless network RTS CTS Threshold The RTS Request To Send threshold number of bytes for enabling RTS CTS handshak...

Страница 66: ...reless access point AP to be distinguished from another For security propose change the default wlan ap to a unique ID name to the AP which is already built in to the router s wireless interface Make...

Страница 67: ...A There are five alternatives to select from WEP 64 bit WEP 128 bit WPA PSK WPA2 PSK and Mixed WPA WPA2 PSK If you require high security for transmissions please select WPA PSK WPA2 PSK or WPA WPA2 PS...

Страница 68: ...or 64 hexadecimal characters Key Renewal Interval The time interval for changing the security key automatically between wireless client and AP WDS Settings WDS Wireless distributed system is a wirele...

Страница 69: ...S 3 Launch the wireless client s WPS utility Set the Config Mode as Enrollee press the WPS button on the top bar select the AP e g Billion_AP from the WPS AP List column Then press the PIN button loca...

Страница 70: ...66...

Страница 71: ...less client s WPS utility Set the Config Mode as Registrar Enter the PIN number in the PIN Code column then choose the correct AP e g Billion_AP from the WPS AP List before pressing the PIN button to...

Страница 72: ...e that the setup is correctly done cross check to see if the SSID and the security setting of the registrar setting match with the parameters found on both Wireless Configuration and Wireless Security...

Страница 73: ...ddress of the devices you wish to filter SSID Index Select the targeted SSID you want the MAC filter rules to apply to Active Select Activated to enable MAC address filtering Action Define the filter...

Страница 74: ...s dual band 2 4G and 5G wireless router support 11b g n a ac wireless standards It allows multiple wireless users on 2 4G and 5G radio bands to surf the Internet You can choose the optimum radio band...

Страница 75: ...tween 1500 and 2347 Fragmentation Threshold The threshold number of bytes for the fragmentation boundary for directed messages It is the maximum data fragment size that can be sent Enter a value betwe...

Страница 76: ...rity is OPEN and to allow all wireless stations to communicate with the access points without any data encryption To prevent unauthorized wireless stations from accessing data transmitted over the net...

Страница 77: ...nd communication with other access point It is easy to be installed just define the peer s MAC of the connected AP WDS Mode select Activated to enable WDS feature and Deactivated to disable this featu...

Страница 78: ...BB 00 00 02 You need to know the MAC address of the devices you wish to filter Active Select Activated to enable MAC address filtering Action Define the filter action for the list of MAC addresses in...

Страница 79: ...disconnect every now and then The lookback interface can have its own IP and subnet mask It is often used for router management as Telnet management IP and involved in BGP as BGP Update Source involv...

Страница 80: ...ays on internet connection Users can set a WAN1 main WAN and WAN 2 backup WAN and when WAN1 fails it will switch to WAN2 and when WAN1 restores it will switch to WAN1 again General Setting Select Fail...

Страница 81: ...ry link WAN1 fails and vise versa Example Auto failover takes place after straight 3 consecutive failures in every 30 seconds meaning all traffic will hand over to backup link WAN2 after primary link...

Страница 82: ...onnectivity Decision Probe Cycle Set a number of times and time in seconds to determine when to turn off the Load Balancing service Example Disable Load Balance after straight 3 consecutive failures i...

Страница 83: ...nd less delay User can distribute outbound traffic based on Session Mechanism or IP Hash Mechanism Base on Session Mechanism Balance by Session Round Robin Balance session traffic based on a round rob...

Страница 84: ...the WAN interface the to be set rule will apply to and what type of traffic is to be bound to forward to the which WAN interface Source IP Address Enter the source IP address featuring the traffic ori...

Страница 85: ...llion Industrial LTE Router HotSpot Gateway provides authentication for clients before access to public networks It also allows users to access some web pages without authentication using Walled Garde...

Страница 86: ...WLAN1 it can be select in the future IP Address IP Subnet Mask The IP Subnet assigned to this Hotspot network The IP can be changed according to different user s need Primary Secondary DNS The DNS inf...

Страница 87: ...fered by UAM server Shared Secret Set the shared secret password offered NAS ID An assigned string for identification Location Name An assigned string for identification Authentication Authentication...

Страница 88: ...nt This part is to configure the account database for Built in UAM Server Up to 16 accounts can be created Rule Index 1 16 the valid user identifier index User Name Password Enter the username passwor...

Страница 89: ...y unlimited Upload Download Bandwidth These privilegd clients can be added by MACs Authorized of Client Activate or Deactivate the feature Rule Index 1 16 trusted users can be added each identified by...

Страница 90: ...es can be added Active Select Yes to activate the rule If activated the domain name or IP will be open without authentication to access Allow Type Choose between Host Network and Domain Host Domain En...

Страница 91: ...uccessfully logged in Advertisement Activate or deactivate the Advertisement feature Mode The mode the propaganda advertisement is shown in Rule Index The rule index identifying the URL 1 15 URLs can...

Страница 92: ...ped by Mail Alert How often to record the session log and to mail can be set here Session Log Activate session log or not Log Session data every Set how often to record the session log By default sess...

Страница 93: ...rs to customize their desired authenticate page strings if not default settings are showed on the authentication page Places where strings are to be shown are listed in the following screenshots in re...

Страница 94: ...tspot is running on SSID1 WLAN1 Change SSID to Billion Hotspot and set Security Type to Open 2 Move to Configuration Hotspot General Setting to set Hotspot Interface Captive Portal Authentication and...

Страница 95: ...r authtication create a valid client account Wireless Client Connection 1 Connect to the SSID M500 Hotspot on the laptop 2 Launch the web brower the hotspot welcome and authentication page pops up 3 I...

Страница 96: ...92...

Страница 97: ...is running on SSID1 WLAN1 Change SSID to Billion Hotspot and set Security Type to Open 2 Move to Configuration Hotspot General Setting to set Hotspot Interface Captive Portal Authentication and Sessio...

Страница 98: ...94 4 Add a new hotspot to SOCIFI dashboard https socifi doc atlassian net wiki display SC Billion M500 4G LTE...

Страница 99: ...95 Wireless Client Connection 1 Connect to the SSID Billion Hotspot on the smart phone 2 Launch the web browser the hotspot welcome and authentication page pops up...

Страница 100: ...96...

Страница 101: ...97 Advanced Setup Advanced Step provides advanced features including Firewall Routing Dynamic Routing NAT VRRP Static DNS Time Schedule and Mail Alert for advanced users...

Страница 102: ...nnot be directly accessed from the Internet Firewall To automatically detect and block Denial of Service DoS attacks such as Ping of Death SYN Flood Port Scan and Land Attack Enabled It activates your...

Страница 103: ...ts the cost of transmission for routing purposes The number need not be precise but it must be between 1 and 15 Interface Media channel selected to append the route Edit Edit the route this icon is no...

Страница 104: ...h will be our next topic the pricipal routing protocol between autonomous systems on the itnernet OSPF Enable to actiavte OSPF routing Rule Index A totoal 10 OSPF rules are allowed ranging from 0 to 9...

Страница 105: ...to 9 Neighbor IP Set your neighbor IP Neighbor AS Number Set your neghbor AS number Allowas in Enable to allow inter communication between devices in the same AS If the local and neighbor AS number ar...

Страница 106: ...communications In this session there are VPN Passthrough SIP ALG DMZ and Virtual Server provided to solve these nasty problems NAT Status Enabled It depends on ISP Connection Type in Internet setting...

Страница 107: ...activates your DMZ function Disabled It disables the DMZ function DMZ Host IP Address Give a static IP address to the DMZ Host when Enabled radio button is checked Be aware that this IP will be expose...

Страница 108: ...al service request to the appropriate server within the LAN network Virtual Server for Indicate the related WAN interface which allows outside network to connect in and communicate Protocol Choose the...

Страница 109: ...twork For this reason you are advised to use specific Virtual Server entries just for the ports your application requires instead of using DMZ As doing so will result in all connections from the WAN a...

Страница 110: ...and go to Configuration Advanced Setup NAT Virtual Server FTP server uses TCP protocol with port 21 Enter 21 to Start and End Port Number M100 will accept port 21 requests from WAN side Eneter the st...

Страница 111: ...erical identifiers associated with networking equipment for the purpose of locating and addressing these devices worldwide An often used analogy to explain the Domain Name System is that it serves as...

Страница 112: ...ol SNTP to get the current time from an SNTP server from the Internet Rule Index The rule index 0 15 for identifying each timeslot Rule Name User defined identification for each time period Day of Wee...

Страница 113: ...ord Enter the password of your email account Sender s Email Enter your email address SSL TLS Check to whether to enable SSL encryption feature Port the port default is 25 Account Test Press this butto...

Страница 114: ...mmunication infrastructures such as the Internet VPNs provide security through tunneling protocols and security procedures such as encryption For example a VPN could be used to securely connect the br...

Страница 115: ...ween agents at the beginning of the session and negotiation of cryptographic keys to be used during the session IPSec is an end to end security scheme operating in the Internet Layer of the Internet P...

Страница 116: ...blishing a VPN tunnel Local Access Range Set the IP address or subnet of the local network Single IP The IP address of the local host for establishing an IPSec connection between a security gateway an...

Страница 117: ...are IP addresses IPv4 and IPv6 supported Encryption Algorithm Select the encryption algorithm from the drop down menu There are several options DES and AES 128 192 and 256 3DES and AES are more powerf...

Страница 118: ...l i e over the Internet MODP stands for Modular Exponentiation Groups IPSec SA Lifetime SA Lifetime Specify the number of minutes that a Security Association SA will stay active before new encryption...

Страница 119: ...m 0 to 3600 second 0 second disables the function Ping to the IP Interval sec Ping to the IP Action 0 0 0 0 0 No 0 0 0 0 2000 No xxx xxx xxx xxx A valid IP Address 0 No xxx xxx xxx xxx A valid IP Addr...

Страница 120: ...116 Example How to establish an IPSec Tunnel 1 LAN to LAN connection Two VPN router want to setup a secure IPSec VPN tunnel Note The IPSec Settings shall be consistent between the two routers...

Страница 121: ...1 0 Local Netwrok Netmask 255 255 255 0 Remote Access Range Subnet Branch office network Remote Netwrok IP Address 192 168 0 0 Remote Netwrok Netmask 255 255 255 0 IPSec Proposal IKE Mode Main Securi...

Страница 122: ...8 0 0 Local Netwrok Netmask 255 255 255 0 Remote Access Range Subnet Branch office network Remote Netwrok IP Address 192 168 1 0 Remote Netwrok Netmask 255 255 255 0 IPSec Proposal IKE Mode Main Secur...

Страница 123: ...119 2 Host to LAN Router servers as VPN server and host should install the IPSec client to connect to head office through IPSec VPN...

Страница 124: ...92 168 1 0 Local Netwrok Netmask 255 255 255 0 Remote Access Range Signal IP Host Remote Netwrok IP Address 69 121 1 30 Remote Netwrok Netmask 255 255 255 255 IPSec Proposal IKE Mode Main Security Pla...

Страница 125: ...client When passed the authentication with MS CHAPv2 the MPPE encryption is supported Encryption Ley Length Available when using MS CHAPv2 authentication mode The data can be encrypted by MPPE algori...

Страница 126: ...N for remote gateway Private IP Address Assigned to Dial in User Specify the private IP address to be assigned to dialin clients and the IP should be in the same subnet as local LAN but not occupied R...

Страница 127: ...en using MS CHAPv2 authentication mode The data can be encrypted by MPPE algorithm with 40 bits or 128 bits Default is Auto it is negotiated when establishing a connection 128 bit keys provide stronge...

Страница 128: ...as Default Route Check to select the tunnel as the default route for traffic If selected all outgoing traffic will be forwarded to this tunnel and routed to the next hop Click Save button to save you...

Страница 129: ...tablishes a PPTP VPN tunnel with head office to connect two private networks over the Internet The routers are installed in the head office and branch offices accordingly Note Both office LAN networks...

Страница 130: ...ption Connection Name HS LL Give a name of PPTP conneciton Authentication Type MPPE 128bit Authentication type Username test Dial in authenticate user name Passwrod test Dial in authenticate user pass...

Страница 131: ...Name BC LL Give a name of PPTP conneciton Authentication Type MPPE 128bit Authentication type Username test Dial in authenticate user name Passwrod test Dial in authenticate user password Conneciton T...

Страница 132: ...Remote Access Dial in connection A remote worker establishes a PPTP VPN connection with the head office using Microsoft s VPN Adapter The router is installed in the head office connected to a couple o...

Страница 133: ...sed in the office LAN Item Description Connection Name HS RA Give a name of L2TP conneciton Authentication Type MPPE 128bit Authentication type Username test Dial in authenticate user name Passwrod te...

Страница 134: ...Remote Access Dial out connection A company s office establishes a PPTP VPN connection with a file server located at a separate location The router is installed in the office connected to a couple of...

Страница 135: ...n head office Item Description Connection Name HC RA Give a name of PPTP conneciton Authentication Type MPPE 128bit Authentication type Username test Dial in authenticate user name Passwrod test Dial...

Страница 136: ...el Conneciton Mode Connection Mode Select Dial In to operate as a L2TP server Authentication Type Default is Chap Pap CHAP Challenge Handshake Authentication Protocol PAP Password Authentication Proto...

Страница 137: ...the username for this account Password Please input the password for this account Conneciton Type Connection Type Remote Access for single user Connection Type If LAN to LAN is selected enter the pee...

Страница 138: ...elect Main or Aggressive mode IKE Local ID Type and Remote ID Type When the mode of IKE is aggressive Local and Remote peers can be identified by other IDs IKE Pre Shared Key This is for the Internet...

Страница 139: ...stablishes a L2TP VPN tunnel with head office to connect two private networks over the Internet The routers are installed in the head office and branch office accordingly Note Both office LAN networks...

Страница 140: ...HS LL Give a name of L2TP conneciton Connection Mode Dial in Operate as L2TP server Authentication Type Chap Pap Authentication type Username Test Dial in authenticate user name Passwrod Test Dial in...

Страница 141: ...of L2TP conneciton Connection Mode Dial out Operate as L2TP client Server IP 69 121 1 33 Dialed server IP Authentication Type Chap Pap Authentication type Username test Dial in authenticate user name...

Страница 142: ...Remote Access Dial in connection A remote worker establishes a L2TP VPN connection with the head office using Microsoft s VPN Adapter The router is installed in the head office connected to a couple o...

Страница 143: ...em Description Connection Name HS RA Give a name of L2TP conneciton Connection Mode Dial in Operate as L2TP server Authentication Type Chap Pap Authentication type Username test Dial in authenticate u...

Страница 144: ...Remote Access Dial out connection A company s office establishes a L2TP VPN connection with a file server located at a separate location The router is installed in the office connected to a couple of...

Страница 145: ...2TP conneciton Connection Mode Dial out Operate as L2TP client Server IP 61 121 1 33 Dialed server IP Authentication Type Chap Pap Authentication type Username test Dial out authenticate user name Pas...

Страница 146: ...tunnel Tunnel Network Netmask Please set the netmask for the local tunnel Tunnel Remote IP Address Set the peer IP address of the tunnel It is a virtual interface for the tunnel Remote Network IP Add...

Страница 147: ...A Select Main or Aggressive mode IKE Local ID Type and Remote ID Type When the mode of IKE is aggressive Local and Remote peers can be identified by other IDs IKE Pre Shared Key This is for the Intern...

Страница 148: ...blishes a GRE VPN tunnel with head office to connect two private networks over the Internet The routers are installed in the head office and branch office accordingly Note Both office LAN networks mus...

Страница 149: ...1 1 30 Authentication type Tunnel Local IP Address Virtual Interface 192 168 100 11 The local virtual interface IP address for the tunnel Tunnel Remote IP Address Virtual Interface 192 168 100 10 The...

Страница 150: ...1 1 3 Authentication type Tunnel Local IP Address Virtual Interface 192 168 100 10 The local virtual interface IP address for the tunnel Tunnel Remote IP Address Virtual Interface 192 168 100 11 The r...

Страница 151: ...d being the most robust and feature rich It uses the OpenSSL encryption library extensively allowing OpenVPN to use all the ciphers available in the OpenSSL package as well as the SSLv3 TLSv1 protocol...

Страница 152: ...ackage to encrypt both the data and channels Select the encryption method Hash To establish the integrity of the datagram and ensures it is not tampered with in transmission There are options Message...

Страница 153: ...under this circumstance all outgoing packets will be forwarded to this tunnel and routed to the next hop Remote Subnet IP Address Set the network address of the remote peer Netmask Set the subnet mask...

Страница 154: ...esistant to brute force attacks than MD5 However it is slower Keepalive Enable to allow the router to check the connectivity to the peer every 10 seconds can be changed based on need by sending ping p...

Страница 155: ...tablishes a OpenVPN tunnel with head office to connect two private networks over the Internet The routers are installed in the head office and branch office accordingly Note Both office LAN networks m...

Страница 156: ...ted in branch office The OpenVPN tunnel netwrok virtual interface is 192 168 100 0 24 Item Description Connection Name HS LL Give a name of GRE conneciton Tunnel Network Virtual Interface 192 168 100...

Страница 157: ...s 69 1 121 3 is the Public IP address of the router located in head office Item Description Connection Name BC LL Give a name of GRE conneciton Server IP Address 69 121 1 3 The IP address of OpenVPN s...

Страница 158: ...Management equipments the users with the ability of maintaining the access management including Device Management SNMP Remote Syslog Universal Plug Play Dynamic DNS Access Control Packet Filter CWMP...

Страница 159: ...f needed HTTPS Port The HTTPS Port number change if needed HTTPS Server Certificate Index Choose the server security certificate Users need to upload the certificate for the https server See Certifica...

Страница 160: ...anagement station Trap Manager IP Enter the IP of the server receiving the trap message when some exception occurs sent by this SNMP agent SNMPv3 Enable to activate the SNMPv3 Username Enter the name...

Страница 161: ...ator can set up a remote system log server for receiving and monitoring the system information by enabling remote system log feature on the router Remote System Log Select whether to activate Remote S...

Страница 162: ...natively support UPnP when the component is installed and Windows 98 users may install the Internet Connection Sharing client from Windows XP in order to support UPnP Windows 2000 does not support UPn...

Страница 163: ...interfaces with different DNS es But note that first users have to go to the Dynamic DNS registration service provider to register an account Dynamic DNS Select this check box to activate Dynamic DNS...

Страница 164: ...unt Note First users have to go to the Dynamic DNS registration service provider to register an account User test1 register a Dynamic Domain Names in DDNS provider http www dyndns org DDNS www hometes...

Страница 165: ...low The maximum number of entries is 16 Access Control Select whether to make Access Control function available Rule Index This is item number Active Select to activate the rule Secure IP Address The...

Страница 166: ...Default Rule 1 Index 0 a rule to allow only clients from LAN to have access to all embedded applications Web FTP etc Under this situation clients from WAN cannot access the router even from Ping Defa...

Страница 167: ...e List or block selecting Black List Rule Index This is item number Individual Active Select Yes to activate the rule Interface Select to determine which interface the rule will be applied to Directio...

Страница 168: ...that the rule applies to Time Schedule To determine when the rule takes effect The rule works always or winthin the set timeslot IP MAC Filter List Index Item number Active Whether the connection is...

Страница 169: ...com please first press Activated in URL Filter field and also Yes in Individual Active field if some time you want to allow access to this URL you simply select No in individual active field In a word...

Страница 170: ...ays set top box VoIP phones At the same time the configuration of this equipment became more complicated too complicated for end users For this reason TR 069 was developed It provides the possibility...

Страница 171: ...to send an Inform message to the ACS automatically Interval s Specify the inform interval time sec which CPE used to periodically send inform message to automatically connect to ACS When the inform in...

Страница 172: ...users Please get an account and configure at the selected Provider www opendns com in advance If activated the Parental Control has the top priority as DNS when accessing internet Host Name Username...

Страница 173: ...e users with the ability of maintaining the device as well as examining the connectivity of the WAN connections including User Management Certificate Management Time Zone Firmware Configuration System...

Страница 174: ...ment User Management controls the Router Web GUI permission to the specific account In factory setting the default accounts are admin admin The default root account admin has been authorized to web ac...

Страница 175: ...etup Index User account index User Name Users can create account s to give it them access to router New Password Enter a new password for this user account Confirmed Password Re enter the new password...

Страница 176: ...enance access Enable to have access to Interface Setup Advanced Setup and Access Management or disable to set the specifics yourself Interface Setup Enable to allowing access to Interface Setup with t...

Страница 177: ...PKCS is disabled Enable PKCS12 to put Certificate Private Key in the same file like p12 pfx Check PKS 12 Check PKS 12 when the certificate and private key are packed into one file Browser to locate th...

Страница 178: ...owse to locate the target file on PC before uploading it Click Save to submit the settings Trusted CA Listing Edit certificate Click move to Trusted CA editing page Index To identify the CA files 2 CA...

Страница 179: ...o use Current Date Time To show the current time based on the time synchronization mechanism users choose below Synchronize time with Select the methods to synchronize the time NTP Server automaticall...

Страница 180: ...ttings Restart the device with the current settings automatically when finishing upgrading Factory Default Settings Restart the device with factory default settings automatically when finishing upgrad...

Страница 181: ...177 DO NOT turn off power off the device or interrupt the firmware upgrading while it is still in process Improper operation could damage your Industrial LTE Router...

Страница 182: ...t settings for example after a firmware upgrade or if you have saved an incorrect configuration select Factory Default Settings to restore to factory default settings You may also restore your router...

Страница 183: ...e current configuration of router for users in line with scheduled timetable settings Enable to set the time schedule for rebooting For example the router is scheduled to reboot at 22 00 every single...

Страница 184: ...c Test page shows the test results for the connectivity of the physical layer and protocol layer for both LAN and WAN sides 4G LTE Click Start to begin to diagnose the connection Click Start Trace Rou...

Страница 185: ...181...

Страница 186: ...technical support You have forgotten your login username or password Try the default username admin and password admin If this fails you can restore your router to its factory settings by pressing the...

Страница 187: ...reset button and power on the router once the Power flashes Red and Green keeping press reset button over 6 seconds 3 Internet LED flashes Green and Red router entering recovery procedure and router s...

Страница 188: ...problems please contact the dealer from where you have purchased the product Contact Billion WORLDWIDE http www billion com MAC OS is a registered Trademark of Apple Computer Inc Windows XP Vista 7 8...

Страница 189: ...uipment and receiver Connect the equipment into an outlet on a circuit different from that to which the receiver is connected Consult the dealer or an experienced radio TV technician for help FCC Caut...

Отзывы: