background image

SETUP 

Page 62

 

DOC_DEV_Router setup guide_A

 

 

19.2.4

 

Modbus client gateway 

This gateway allows to connect a serial modbus master to the 
serial interface of the product. 
 
The  gateway  can  be  connected  to  several  Modbus  TCP 
servers on the IP network  
 
Other slaves can be connected to the serial link. 

 

 

How the Modbus Client Gateway works :  

In order to access a Modbus TCP server on the IP network, a mapping table between a Modbus slave address 
and an IP address is set ; so when the Modbus master sends a request to the Modbus slave at address A, the 
mapping table allow to transmit the request to the corresponding IP address. 
In addition, the Modbus address field of the Modbus TCP frame is set to A.  
The mapping table can contain 32 lines allowing a Modbus master to address 32 servers on the IP network. 
 

 

 

 

To configure the gateway : 

 

In the menu, choose 

Setup > IP-RS gateways > Modbus > Modbus client

 

Tick the 

Enable Modbus client

 checkbox. 

 

Configure the following parameters. 

 

COM port 

Select the serial link 1 or 2 of the product. 

 

Bitrate, Parity, Data, stop bits 

Allow to set the bitrate and the format of the asynchronous serial link. 
 

Modbus protocol 

Select RTU (hexa) or ASCII. 
 

Inter-character time 

Set up the maximum delay the gateway will have to wait between a received character of a Modbus answer packet and 
the following character of the same packet.  
 

Содержание RAS Series

Страница 1: ...DOC_DEV_Router setup guide_A RAS IPL SIG _________________ SETUP GUIDE _________________ ...

Страница 2: ...EV_Router setup guide_A The product family RAS IPL et SIG are manufactured by ETIC TELECOM 13 Chemin du vieux chêne 38240 MEYLAN FRANCE TEL 33 0 4 76 04 20 05 E mail hotline etictelecom com web www etictelecom com ...

Страница 3: ...interface setup 17 3 Cellular interface setup 19 3 1 SIM 1 or SIM 2 set up 19 3 2 Using the SIM cards 1 and 2 20 3 3 Cellular connection control 21 4 Wi Fi WAN interface setup 22 5 LAN interface setup 23 5 1 Overview 23 5 2 Ethernet IP menu 24 5 3 Wi Fi access point set up 25 5 4 Device list set up 26 5 5 DHCP server menu 27 6 IPSec VPNs setup 28 6 1 Overview 28 6 2 IPSec VPN connection set up 29 ...

Страница 4: ...48 12 HTTPS connection and portal for smartphone tablets or PCs 49 12 1 Overview 49 12 2 Set up 50 12 3 Operation 50 13 M2Me_Connect connection setup 51 14 Users list 52 15 Assigning rights to remote users 54 16 Firewall setup 55 16 1 Overview 55 16 2 Main filter 56 17 Adding a certificate 58 18 Alarm email or SMS 59 19 Serial to Ip gateways 60 19 1 Overview 60 19 2 Modbus gateway 61 19 3 Raw TCP ...

Страница 5: ...in functions of these Routeurs IP router The router provides powerful flexible and comprehensive solutions to route IP packets from one network to other networks Static routes to reach nested networks Network address translation d adresse NAT DNAT port forwarding Routing protocol RIP Domain name management DNS et DynDNS IPSec OpenVPN tunnels The Router features IPSec and OpenVPN tunnels to provide...

Страница 6: ...RP redundancy VRRP makes possible to use two Routers shaping a redundant solution Automatic backup of an ADSL link over the cellular network The IPL DAC provides an ADSL interface and a cellular interface It is designed for critical industrial remote SCADA systems In normal situation the data are transmitted via the main interface usually the ADSL one In case of a failure the data are transmitted ...

Страница 7: ... software can easily detect all ETIC branded products connected to an Ethernet network to display their MAC address and their IP address Serial gateway Optionally the Router provides 1 or 2 serial RS232 RS485 RS422 interfaces The serial gateway features the following modes Raw TCP client or server Raw UDP Telnet Modbus master or slave Unitelway ...

Страница 8: ......

Страница 9: ...connect the PC directly to the LAN interface of the Router Subsequent changes can be made remotely Restoring the factory IP address The factory IP address 192 168 0 128 can be restored see the User guide of the product Restricted access to the administration server If you do not have access to the administration server it is probably that access has been restricted for security reasons or for othe...

Страница 10: ...raight or cross wired Step 3 Launch the web browser Launch the web browser and then enter the IP address of the Router 192 168 0 128 The Home page of the administration server is displayed Note Access to the administration server is not protected when configuring the Router for the first time 1 3 Changing the configuration later Thereafter the Router administration server is accessible from the lo...

Страница 11: ... the Enable access from the WAN s checkbox The administration server is accessible with HTTPS through the WAN or the LAN interface 3 Working with HTTPS Once HTTPS has been selected proceed as follows The port 4433 is assigned to administration server Open the web browser and enter the IP address of the Router administration server Example https 192 168 38 191 4433 Click Next when a warning message...

Страница 12: ...boot the product The product can be reached at the registered IP address Note If the IP address of the Router is unknown the software tool EticFinder can be used This software detects all ETIC branded products on a local network After starting the software click on the Search button and when the product list is displayed double click on the product address to access the html server 5 Restoring the...

Страница 13: ...rotect the web site access checkbox If the username and password to access the administration server are lost you have to temporarily return to the factory settings access to the administration server is then free 7 Configuration steps To configure the product we advise to proceed as follows Set up the LAN interface Set up the WAN interface Set up the routing functions Set up VPNs Set up the remot...

Страница 14: ......

Страница 15: ...iguration Speed Duplex parameter Select 10 or 100 Mb s full or half duplex IP set up of the Ethernet WAN port Connection type list The Ethernet value is the default value It has to be selected when another router connected to the Ethernet WAN interface of the ETIC Router is in charge of routing the IP frames to the internet The PPPOE value must be selected only in a particular situation When it is...

Страница 16: ...the DNS servers Enable address translation NAT checkbox If that option is selected the source IP address of any IP frame coming from a device connected to the LAN interface and routed to the WAN interface is replaced by the Router WAN IP address Remark Select that checkbox if a device of the LAN interface needs to set a connection with a device connected to the Internet FTP server Proxy Arp checkb...

Страница 17: ...Otherwise ask your provider the modulation which as to be used VPI parameter Range is 0 255 Leave the default value 8 Virtual Channel Identifier parameters Range is 0 65535 Leave the default value 35 Multiplexing parameters Value LLC or VC Leave the default value LLC Encapsulation parameter PPPoE PPP over Ethernet PPPoA PPP over ATM EoA Ethernet over ATM RFC1483 RFC2684 Bridged IPoA Routed IP over...

Страница 18: ...ary DNS IP address secondary DNS IP address parameters Leave that option selected if the provider is supposed to provides that addresses automatically through the line default Otherwise unselect that option and enter the IP of the primary and secondary DNS server Enable address translation NAT checkbox If that option is selected the source IP address of any IP frame coming from a device connected ...

Страница 19: ...rst the interface having received the highest priority the other interface will be used as a backup path SIM card parameter It is possible to select the SIM card Nr1 or the SIM card Nr2 or both SIM card parameter Value SIM1 The SIM 1 is selected default value SIM2 The SIM 2 is selected default value SIM 1 backup to SIM2 The SIM 1 is used first the SIM 2 is used as backup 3 1 SIM 1 or SIM 2 set up ...

Страница 20: ...heckbox If that option is selected the source IP address of any IP frame coming from a device connected to the LAN interface and routed to the WAN interface is replaced by the router WAN IP address Remark Select that checkbox if a device of the LAN interface needs to set a connection with a device connected to the Internet FTP server 3 2 Using the SIM cards 1 and 2 Each SIM card can be associated ...

Страница 21: ...re router However with particular mobile service providers or in particular situations that PPP connection is declared active while the data transmission service is not provided by the mobile service provider It is why the Router is able to ping a particular server to check if the data service is really provided If it is not the PPP connection is reset That function must be enabled only if connect...

Страница 22: ...EP key according to the access point set up Wi Fi WAN IP set up WiFi WAN priority parameter Enter a medium value Obtain an IP address automatically checkbox Leave that checkbox selected if the IP address on the WAN interface is assigned by a DHCP server Otherwise unselect that checkbox and enter the IP address the netmask and the default gateway address Obtain the DNS server IP address automatical...

Страница 23: ...the LAN network Example IP address Remark LAN network 192 168 12 0 24 From 192 168 12 1 to 192 168 12 254 Netmask 255 255 255 0 Router IP addr 192 168 12 1 Remote users IP pool start 192 168 12 2 In this example two remote users can simultaneously connect to the LAN network one will receive the IP address 192 168 12 2 and the other 192 168 12 3 Remote users IP pool end 192 168 12 3 IP addresses av...

Страница 24: ...aves like a hub LAN network IP address netsmask parameters Enter the IP address assigned to the Router over the LAN interface That IP address is also the IP address of the administration server of the Router Default gateway parameter If another router is connected to the LAN network giving access to other networks and acting as the default gateway for the Router enter the address of the router Rem...

Страница 25: ...t up LAN interface Wi Fi access point menu Select the Wi Fi access point checkbox Network name SSID parameter Enter the name assigned to the Wi Fi network to which the Router has to connect Attention The SSID is case sensitive Preshared key parameter Enter the WPA preshared key at least 8 characters Country code parameter The RF channels allocated to the Wi Fi service are not the same in all the c...

Страница 26: ...y the channels used by the Wi Fi networks active at the same location 5 4 Device list set up To set up the device list Select the Set up LAN interface device list menu To add a device to the list Click the Add button Assign a name and an IP address to the device Remark it is possible to enter a subnet and only a device Example 192 168 38 8 29 192 168 38 8 to 192 168 38 15 ...

Страница 27: ...Wi Fi office devices like tablets or smartphones do not support a fixed IP address Select the Set up LAN interface DHCP server IP address pool start IP addresses pool end parameters Enter the first and the last IP address reserved to the DHCP server IP address netsmask parameters Enter the IP address assigned to the Router over the LAN interface That IP address is also the IP address of the admini...

Страница 28: ...oduced by ETIC TELECOM is registered in the Router Other kinds of X509 certificates can be added see the Set up Security X509 certificate The certificate used by each participant to the VPN must be delivered by the same authority Setting up an IPSec tunnel in the case where the source IP address is modified along the way from the initiator to the responder router To provide a strong mutual authent...

Страница 29: ...tup guide_A page 29 6 2 IPSec VPN connection set up Select the Set up Network IPSec VPN menu The IPSec VPN home page is displayed To add an IPSec VPN connection click Add The set up page of the new VPN connection is displayed ...

Страница 30: ...e of the active certificate of the current router If the active certificate is an ETIC TELECOM certificate that field is the email field Remote SubjectAlt name parameter Enter the SubjectAltName value of the active certificate of the remote router If the active certificate is an ETIC TELECOM certificate that field is the email field Authentication section Case 2 Use of a preshared key Preshared ke...

Страница 31: ...e IKE security association After that period of time the IKE step 1 is carried out again IKE phase 2 Section The purpose of IKE phase two is to negotiate the IPSec parameters general parameters encryption SA life time The result of the IKE phase 2 is the encrypted tunnel between the two routers Protocol parameter This parameter enables to set up the IPSec transport protocol AH insures authenticati...

Страница 32: ...ive period parameter A DPD is a message sent periodically by each end point to the other one to make sure that the VPN must be left active This parameters sets the amount of time in seconds between two of these requests Connection death time out parameter This parameter defines the maximum amount of time in seconds a VPN connection will stay established if no traffic or no DPD keep alive message a...

Страница 33: ...tion The authentication of the two participants to the VPN connection can also be carried out using certificates in addition to a Login and password Coming from factory a certificate produced by ETIC TELECOM is registered in the ETIC Router Other kinds of X509 certificates can be added see the Set up Security X509 certificate The certificate used by each participant to the VPN must be delivered by...

Страница 34: ...cept up to 16 ingoing connections from VPN clients VPN client set up If the Router behaves only like a VPN client the set up consists only of configuring the outgoing connection one or several Set up rules Common parameters The following parameters are common for the server and for all the clients supposed to set a VPN to that server Transport protocol UDP or TCP and port number Encryption algorit...

Страница 35: ...N server table Port number protocol parameters Select the port Nr and the type of level 3 protocol used to transport OpenVPN Attention The port number value must be different from the one used by remote users VPN network address VPN network netmask parameters The OpenVPN server Router assigns automatically an IP address to the VPN client router ...

Страница 36: ...instance Push local route to VPN clients parameter If that checkbox is selected the server broadcasts to the clients the route to the IP domain of its local network Leave that checkbox selected Push static routes to VPN clients parameter If that checkbox is selected the server broadcasts to the clients the static routes which have been set up in the VPN server Leave that checkbox selected Push cli...

Страница 37: ...ess Backup VPN server IP address parameter The client VPN Router is able to set a backup VPN if the main VPN fails Port number protocol parameters Select the port Nr and the type of level 3 protocol used to transport OpenVPN Attention The port number value must be different from the one used by remote users Encryption algorithm Authentication algorithm parameter AES provides a better encryption th...

Страница 38: ...ing as a VPN server To create an ingoing connection select the Add button located just below the Ingoing connection table Select the Enable option and assign a name to the connection Login Password parameter Enter the login and password of the remote router Remote LAN IP address Remote LAN netmask parameters Enter the IP address and netmask of the remote LAN Ex 192 168 2 0 255 255 255 0 Common nam...

Страница 39: ...k 2 A default gateway address must be entered in each device of the different networks 8 2 Static routes However the router R2 is not able to route frames between a device like L1 belonging to the LAN network and a device connected to network 6 see the drawing hereafter In that case it is necessary to enter the route to that hidden network 6 that route is called a static route A static route consi...

Страница 40: ...c routes click the Add a route button Destination IP address netmask parameters Enter the destination network IP address and netmask Gateway IP address parameters Enter the Ip address of the gateway through which the IP packets intended for that network must pass 8 3 RIP protocol RIP Routing Information Protocol is a routing protocol which enables each router belonging to a network to acquire the ...

Страница 41: ...nsferring IP frames intended for the IP router WAN interface to a particular device of the LAN interface using the destination port number The transfer criteria is the port number the port number is used as an additional destination address field Example Let us suppose the PC named W1 connected to the WAN network has to send frames to the device PLC1 connected to one Ethernet port of the Router If...

Страница 42: ...on IP addresses and port number of the frames received by the Router on its LAN or WAN interface It applies to all the frames received by the Router on any of its two interfaces except to the IP packets contained in a remote user connections One brings out the DNAT function which consists in replacing the destination port and IP address the SNAT function which consists in replacing the source IP a...

Страница 43: ...frames which must be modified by the DNAT rule Source IP address Destination IP address Protocol TCP UDP Source port Destination port Enter the new destination port number and IP address To create a new SNAT rule click Add a SNAT rule Select Yes to enable the rule Enter the characteristics of the IP frames which must be modified by the SNAT rule Source Destination IP address and transport protocol...

Страница 44: ...rg Step 2 Router set up Select the Set up Network DynDNS menu Select the Enable option Dynamic DNS service provider parameter Select DynDNS or NoIP DNS account login parameter Enter the login assigned by dyndns DNS account password parameter Enter the password assigned by dyndns Hostname parameter Enter the DynDNS domain name for instance mymachine dyndns org Remark If the IP address assigned to t...

Страница 45: ...er list When he connects the login and password of the remote user and optionally the certificate of his PC are checked The certificate can be delivered by ETIC TELECOM or by another authority Selective access rights Individual access rights can be assigned to each remote user according to his identity Transparent connection Once the remote connection has been launched the PC receives automaticall...

Страница 46: ...gin PWD Yes L2TP IPSec Login PWD and Preshared Key or certificate Yes HTTPS Login PWD Yes That four types of connection can be implemented in PCs tablets or smartphones They can be active at the same time The HTTPS connection is mainly dedicated to secure remote access to HTML pages embedded in supervision PCs HMIs or PLCs for instance It is described in the following chapter When a remote user se...

Страница 47: ... case the certificate of the remote PC must be stored in the Router see the table at the top of the page Encryption Algorithm Message digest algorithm Leave the default values Blowfish MD5 11 4 OpenVPN connection for smartphones It is possible to differentiate a remote user connection intended for PCs and another remote user connection intended for smartphones The protocol TCP or UDP or the port n...

Страница 48: ...n parameter Select the Login password value or the Login password certificate value if the certificate of the remote PC must be checked In that case the certificate of the remote PC must be stored in the Router see the table at the top of the User list page Encryption Algorithm Message digest algorithm parameters Leave the default values 3DES MD5 Authentication method parameter Select preshared ke...

Страница 49: ...secure remote access to HTML HHTP pages embedded in devices It means that a simple HTML HTTP unsecure server can be used remotely through the internet in a safe way When a remote user connects to the Router using an HTTPS secure connection the portal displays the list of the html servers to which he has the right to access That list can include as well HTTPS native servers or HTTP unsecured server...

Страница 50: ...tion server and to the HTTPS portal from the LAN or from the WAN are organized according to the table below From the Internet From the LAN HTTPS web portal https Internet IP address LAN IP address Administration web server https Internet IP address 4433 LAN IP address or https adr IP Internet 4433 12 3 Operation To access to the HTTPS internet portal from the Internet Launch the browser Enter http...

Страница 51: ...2Me_Connect server The VPN can be transported in UDP or TCP Select the Set up Remote access M2Me_Connect menu TCP port UDP ports parameters Enter the selected UDP and TCP ports the Router will have to test to set the M2Me VPN The Router will try to set the M2Me connection successively with the selected UDP and TCP ports beginning with UDP If a proxy server filters outgoing connections unselect the...

Страница 52: ...st is able to register 25 authorised remote users forms Each user form stores the identity of the user Login and password his email address to send alarm emails and his mobile telephone number to send alarm SMS to him To display the user list select the Set up Remote access User list menu Remark Coming from factory the user list is empty ...

Страница 53: ...EV_Router setup guide_A page 53 To register a remote user in the user list Click the ADD button located under the user list Enter the identity of the user Login and password his email address to send alarm emails ...

Страница 54: ...twork must have been registered previously LAN interface menu To grant access rights to a remote user Select the set up remote access access rights menu Click the Add button Select a remote user in the list Select a device in the list to authorise the remote user to access to that device Remark A device ca be a subnet or an IP address refer to the Set up LAN interface Device list ...

Страница 55: ... interface on one hand and on the other hand the WAN interface or a VPN see the drawing above The main filter checks source and destination IP addresses and the source and destination ports The main filter does not check the IP packets included in a remote user connection That packets are checked by the remote users filter The main filter does not check the IP packets defined in the Port forwardin...

Страница 56: ...ch line of which is a filter rule Main filter default policy The default policy is the decision which will be applied if a packet does not match any of the rules of the filter The WAN to LAN and the LAN to WAN traffic are regarded separately because the decision can be opposite for a packet coming from the WAN or coming from the LAN WAN to LAN The default policy can be Accept or drop LAN to WAN Th...

Страница 57: ...hes the rule How does the main filters works When the firewall receives a packet it checks if it matches the first rule If it does the decision is applied to the packet according to the Action field If it does not the firewall checks if it matches the second rule and so on If the packet does not match any of the rules of the table the default policy is applied to the packet Allow or Deny Remark Co...

Страница 58: ...nal X509 certificates provided by ETIC TEECOM or not can be registered into the Router To import a new certificate the file extension can be PKCS 12 with a password or PEM Even if more than one certificate have been downloaded into the Router only one certificate can be active To add a certificate Select the Set up Security Certificate menu Click the Add button located below the certificate table ...

Страница 59: ...meter SMS choice Enter the mobile telephone number Email sender parameter email choice Enter the sender email address Email Destination parameter email choice Enter the email destination address Subject parameter email choice Enter the subject of the alarm mail Text parameter Enter the alarm text SMTP client section Use the M2Mail service parameter email choice ETIC TELECOM provides a SMTP service...

Страница 60: ...IP network to transport serial data between two or several serial devices or directly with devices connected to the Ethernet network Communication between serial devices Communication between a serial device and a PC via a COM port emulation software Communication between serial devices and a PC software application able to encapsulate the serial data into UDP or TCP like a Modbus TCP software app...

Страница 61: ... to a Modbus slave device connected to the same serial network A Modbus slave device is a device connected to a serial asynchronous link and able to reply to Modbus requests connected to the same serial network Modbus address An address between 0 and 254 assigned to each participant to a Modbus network Remark the Modbus address must not be confused with the IP address of a Modbus device 19 2 2 Sel...

Страница 62: ...ansmit the request to the corresponding IP address In addition the Modbus address field of the Modbus TCP frame is set to A The mapping table can contain 32 lines allowing a Modbus master to address 32 servers on the IP network To configure the gateway In the menu choose Setup IP RS gateways Modbus Modbus client Tick the Enable Modbus client checkbox Configure the following parameters COM port Sel...

Страница 63: ...al modbus slaves to the serial interface of the product Up to 32 slaves can be connected to the RS485 port How the Modbus server Gateway works A Modbus TCP client send a Modbus TCP client to the gateway The gateway behave as a master on the serial link It transcode and transmit the request on the serial link The Modbus slave address of the request is Either the address contained in the Modbus TCP ...

Страница 64: ... query has not been sent since the time set by the cache refresh parameter Cache refresh Sets the minimum time between two identical requests to the same slave Inter character time Set up the maximum delay the gateway will have to wait between a received character of a Modbus answer packet and the following character of the same packet Modbus slave address If the value 0 is selected the gateway us...

Страница 65: ...p guide_A page 65 TCP port Set the port number the gateway has to use The default Modbus TCP port is 502 Local reiteration count Set up the number of times the gateway will repeat a request in case of no response from the slave ...

Страница 66: ...eive buffer size Set up the maximum length of an asynchronous string the gateway will store before transmitting it to the IP network RS end frame timeout Set up the delay the gateway will wait before declaring complete a string received from the asynchronous device Once declared complete the gateway will transmit the string to the IP network TCP idle Timeout Set the time the gateway will wait befo...

Страница 67: ... the asynchronous serial link Receive buffer size Set up the maximum length of an asynchronous string the gateway will store before transmitting it to the IP network RS end frame timeout Set up the delay the gateway will wait before declaring complete a string received from the asynchronous device Once declared complete the gateway will transmit the string to the IP network TCP idle Timeout Set th...

Страница 68: ...x Tick the Enable checkbox Configure the following parameters Bitrate Parity Data stop bits Allow to set the bitrate and the format of the asynchronous serial link Receive buffer size Set up the maximum length of an asynchronous string the gateway will store before transmitting it to the IP network RS end frame timeout Set up the delay the gateway will wait before declaring complete a string recei...

Страница 69: ...gure the following parameters Bitrate Parity Data stop bits Allow to set the bitrate and the format of the asynchronous serial link Receive buffer size Set up the maximum length of an asynchronous string the gateway will store before transmitting it to the IP network RS end frame timeout Set up the delay the gateway will wait before declaring complete a string received from the asynchronous device...

Страница 70: ...ay Tick the Enable checkbox Configure the following parameters COM port Select the serial link 1 or 2 of the product Bitrate Parity Data stop bits Allow to set the bitrate and the format of the asynchronous serial link Xway address Gateway address in the Xway network TCP idle Timeout Set the time the gateway will wait before disconnecting the TCP link if no characters are detected Unitelway slaves...

Страница 71: ...ing to the RFC2217 standard To configure the gateway In the menu choose Setup IP RS gateways Telnet Tick the Enable checkbox Configure the following parameters COM port Select the serial link 1 or 2 of the product Bitrate Parity Data stop bits Allow to set the bitrate and the format of the asynchronous serial link TCP idle Timeout Set the time the gateway will wait before disconnecting the TCP lin...

Страница 72: ...dress of the Router 19 8 2 Set up Select the Setup menu and then the USB menu Activate checkbox Select the Activate checkbox Use a specific IP address checkbox If modbus TCP traffic only has to be forwarded to the USB device that checkbox must not be selected If other kinds of traffic have to be forwarded that checkbox has to be selected Specific IP address parameter If modbus TCP traffic only has...

Страница 73: ...he Wifi scanner displays the main information about each WiFi network MAC address of the access point SSID reception level Remark The WiFi interface of the ETIC router needs to be registered as a WiFi client interface 4 Firmware update The firmware update can be carried out locally or remotely If the firmware update operation do not succeed for instance if the connection fails the Router restarts ...

Страница 74: ...13 Chemin du Vieux Chêne 38240 Meylan France Tel 33 0 4 76 04 20 00 contact etictelecom com www etictelecom com ...

Отзывы: