GW7304 Series User Manual
Issue:
1.9
Date:
11 April 2017
Страница 1: ...GW7304 Series User Manual Issue 1 9 Date 11 April 2017 ...
Страница 2: ...3 5 Factory configuration extraction from SIM card 24 6 Accessing the router 25 6 1 Configuration packages used 25 6 2 Accessing the router over Ethernet using the web interface 25 6 3 Accessing the router over Ethernet using an SSH client 26 6 4 Accessing the router over Ethernet using a Telnet client 27 6 5 Configuring the password 27 6 6 Configuring the password using the web interface 27 6 7 C...
Страница 3: ...tion file syntax 67 10 7 Managing configurations 67 10 8 Exporting a configuration file 68 10 9 Importing a configuration file 69 11 Using the Command Line Interface 73 11 1 Overview of some common commands 73 11 2 Using Unified Configuration Interface UCI 76 11 3 Configuration files 81 11 4 Configuration file syntax 81 12 Management configuration settings 83 12 1 Activator 83 12 2 Monitor 83 12 3...
Страница 4: ...125 15 1 Maximum number of VLANs supported 125 15 2 Configuration package used 125 15 3 Configuring VLAN using the web interface 125 15 4 Viewing VLAN interface settings 128 15 5 Configuring VLAN using the UCI interface 129 16 QoS VLAN 802 1Q PCP tagging 130 16 1 Configuring VLAN PCP tagging 130 17 QoS type of service 133 17 1 QoS configuration overview 133 17 2 Configuration packages used 133 17 ...
Страница 5: ... from the router 164 21 7 Sending SMS to the router 164 22 Configuring Multi WAN 165 22 1 Configuration package used 165 22 2 Configuring Multi WAN using the web interface 165 22 3 Multi WAN traffic rules 170 22 4 Configuring Multi WAN using UCI 170 22 5 Multi WAN diagnostics 171 23 Automatic operator selection 174 23 1 Configuration package used 174 23 2 Configuring automatic operator selection v...
Страница 6: ...N 267 28 1 Prerequisites for configuring DMVPN 267 28 2 Advantages of using DMVPN 267 28 3 DMVPN scenarios 268 28 4 Configuration packages used 270 28 5 Configuring DMVPN using the web interface 270 28 6 DMVPN diagnostics 272 29 Configuring Terminal package 275 29 1 Configuration packages used 275 29 2 Configuring Terminal using the web interface 275 29 3 Configuring Terminal package using UCI 275...
Страница 7: ...m 303 33 1 Configuration package used 303 33 2 Implementation of the event system 303 33 3 Supported events 303 33 4 Supported targets 304 33 5 Supported connection testers 304 33 6 Configuring the event system using the web interface 304 33 7 Configuring the event system using UCI 304 33 8 Event system diagnostics 315 34 Configuring SLA reporting on Monitor 321 34 1 Introduction 321 34 2 Configur...
Страница 8: ...G wireless WAN connection Internal PSU DC power input 2 x antenna SMA connectors 1 2 Using this documentation You can configure your router using either the router s web interface or via the command line using UCI commands Each chapter explains first the web interface settings followed by how to configure the router using UCI The web interface screens are shown along with a path to the screen for ...
Страница 9: ...c 0 can be witten as network routename route network routename metric 0 However the documentation usually assumes that a section label is not configured The table below shows fields from a variety of chapters to illustrate the explanations above Web Field UCI Package Option Description Web Enable UCI cesop main enable Opt enable Enables CESoPSN services 0 Disabled 1 Enabled Web Syslog Severity UCI...
Страница 10: ...____________________________________________________________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 10 of 336 1 2 3 Diagnostics Diagnostics are explained at the end of each feature s chapter 1 2 4 UCI commands For detailed information on using UCI commands read chapters Router File Structure and Using Command Line Interface ...
Страница 11: ..._______________________________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 11 of 336 2 GW7304 Series hardware 2 1 Hardware specification 2 1 1 GW7304 Series model features 2 1 1 1 GW7304 3G AC 8 x Ethernet ports 3G wireless WAN connection Dual SIM 1 xRS232 console port 2 x antenna SMA connectors AC power input Figure 1 GW7304 AC ports diagram Figure 2 GW7304 AC ports ...
Страница 12: ...232 console port 2 x antenna SMA connectors DC power input Figure 3 GW7304 DC ports Figure 4 GW7304 DC ports 2 2 Power supply The GW7304 Series router has two power supply options depending on the model Model Power Input GW7304 3G AC 100 240V AC Max current 0 029A Max power 6 84W GW7304 3G DC 36 72V DC Max current 0 11A Max power 6 875W Table 2 Power input options 2 3 Serial port The GW7304 Series...
Страница 13: ...17 GW7304 Series User Manual Issue 1 9 Page 13 of 336 2 3 1 RS232 pinout Pin Name Direction from GW7304 router 1 RTS Out 2 DTR Out 3 Tx data Out 4 GND 5 GND 6 Rx In 7 DSR In 8 CTS In Table 3 Pinouts for the RS2323 serial connector 2 4 GSM technology HSPA EDGE GPRS Download up to 21 Mbps Upload up to 5 76 Mbps 2100 1900 900 850 MHz bands 2 5 Dimensions Height 150mm Width 200mm Depth 75mm Weight 800...
Страница 14: ...ected to the auxiliary AUX connector for antenna diversity Antenna diversity helps improve the quality of a wireless link by mitigating problems associated with multipath interference 2 8 Components To enable and configure connections on your GW7304 Series router it must be correctly installed The GW7304 Series router contains an internal web server that you use for configurations Before you can a...
Страница 15: ...ng the model number serial number S N and part number P N is located on the side of the packaging box Each GW7304 Series router is assigned a unique serial number Record your device serial number on your warranty card or somewhere you can easily access it You must reference your unique serial number S N when you contact Virtual Access support for installation and configuration confirmation Figure ...
Страница 16: ...DC serial number label on the top of the GW7304 DC router 2 9 2 Mounting the GW7304 on a DIN rail The GW7304 Series router is supplied with a DIN rail clip attached Offer the GW7304 Series unit down on to the DIN rail Hold the unit at a slight angle and slide the top teeth of the DIN rail clip down onto the DIN Rail When the top teeth and DIN rail are connected push the unit down and back in one m...
Страница 17: ... side facing down and the cut corner front left Gently push the SIM card into SIM slot 1 until it clicks in If using SIM 2 then hold the SIM with the cut corner front right Gently push the SIM card into SIM slot 2 until it clicks in 2 9 5 Connecting cables Connect one end of the Ethernet cable into port 1 and the other end to your PC or switch 2 9 6 Connecting the antenna Virtual Access offers a v...
Страница 18: ...plastic sleeve should be 2 5mm2 maximum or no greater than AWG 12 Attach the neutral wire blue to the far left receptical of the terminal block as shown in the figure below Attach the live wire brown to the second left receptical on the terminal block as shown in the figure below Note you must attach the live and neutral wires exactly as shown in the figure below Under no circumstance should they ...
Страница 19: ...witch on the power to the device The GW7304 takes approximately 2 minutes to boot up During this time the power LED flashes Other LEDs display different diagnostic patterns during boot up Booting is complete when the power LED stops flashing and stays on steady 2 9 9 Reset button Use a paperclip or similar sized piece of metal to press in the reset button when you need to reset the system When you...
Страница 20: ...0 of 336 2 9 10 Recovery mode Recovery mode is a fail safe mode where the router can load a default configuration from the routers firmware If your router goes into recovery mode all config files are kept intact After the next reboot the router will revert to the previous config file You can use recovery mode to manipulate the config files but should only be used if all other configs files are cor...
Страница 21: ... takes approximately 2 minutes to boot up During this time the power LED flashes Other LEDs display different diagnostic patterns during boot up Booting is complete when the power LED stops flashing and stays on steady Power On Power Off No power or boot loader does not exist Config On Unit running a valid configuration file Flashing slowly Unit running in recovery mode 5 Hz Flashing quickly Unit ...
Страница 22: ... with the cover removed DANGEROUS SUBSTANCES Semiconductor devices contain dangerous substances such as beryllium and arsenic Electronic devices must not be opened If they become damaged they must only be handled using protective gloves If the substances inside the electronic devices come into contact with broken skin or wounds hospital care must be sought immediately Electronic components must be...
Страница 23: ...sting and measurement techiques immunity to conducted disturbances induced by radio frequency fields EN61000 4 8 Electomagnetic compatibility EMC Part 4 8 testing and measurement techiques power frequency magnetic field immunity test EN61000 4 10 Electomagnetic compatibility EMC Part 4 10 testing and measurement techiques damped oscillatory magnetic field immunity test EN61000 4 11 Electomagnetic ...
Страница 24: ...u are inserting has the required configuration written on it 2 Ensure the router is powered off 3 Hold the SIM 1 card with the chip side facing down and the cut corner front left 4 Gently push the SIM card into SIM slot 1 until it clicks in 5 Power up the router Depending on the model the power LED and or the configuration LED flash as usual The SIM LED starts flashing This indicates the applicati...
Страница 25: ...hernet using the web interface DHCP is disabled by default so if you do not receive an IP address via DHCP assign a static IP to the PC that will be connected to the router PC IP address 192 168 100 100 Network mask 255 255 255 0 Default gateway 192 168 100 1 Assuming that the PC is connected to Port A on the router in your internet browser type in the default local IP address 192 168 100 1 and pr...
Страница 26: ...lient and connect to the router s management IP address on port 22 192 168 100 1 24 On the first connection you may be asked to confirm that you trust the host Figure 15 Confirming trust of the routers public key over SSH Figure 16 SSH CLI logon screen In the SSH CLI logon screen enter the default username and password Username root Password admin 6 3 1 SCP Secure Copy Protocol As part of accessin...
Страница 27: ...er reboot f To re enable SSH enter root VA_router etc init d dropbear enable root VA_router reboot f Note As SSH is enabled by default initial connection to the router to enable Telnet must be established over SSH 6 5 Configuring the password 6 5 1 Configuration packages used Package Sections system main 6 6 Configuring the password using the web interface To change your password in the top menu c...
Страница 28: ... jRX x8A U5kLCMpi9dcahRhOl7eZV1 If changing the password via the UCI enter the new password in plain text using the password option root VA_router uci system main password newpassword root VA_router uci commit The new password will take effect after reboot and will now be displayed in encrypted format via the hashpassword option 6 8 Configuring the password using package options The root password ...
Страница 29: ...m config system main option hostname VirtualAccess option timezone UTC config pam_auth option enabled yes option pamservice login option pammodule auth option pamcontrol sufficient option type radius option servers 192 168 0 1 3333 test 20 192 168 2 5 secret 10 config pam_auth option enabled yes option pamservice sshd option pammodule auth option pamcontrol sufficient it checks package management_...
Страница 30: ...nticates against remote RADIUS if password authentication fails then it tries local database user defined in package management_users Required If either authentication fails or RADIUS server is not reachable then user is not allowed to access the router success done new_authtok_reqd done authinfo_unavail ignore default die Local database is only checked if RADIUS server is not reachable UCI system...
Страница 31: ...tion pamservice sshd option pammodule account option pamcontrol sufficient option type tacplus option servers 192 168 0 1 49 secret option args service ppp config pam_auth option enabled yes option pamservice sshd option pammodule session option pamcontrol sufficient option type tacplus option servers 192 168 0 1 49 secret option args service ppp config pam_auth option enabled yes option pamservic...
Страница 32: ...mcontrol sufficient option type tacplus option servers 192 168 0 1 49 secret option args service ppp config pam_auth option enabled yes option pamservice login option pammodule auth option pamcontrol sufficient option type tacplus option servers 192 168 0 1 49 secret config pam_auth option enabled yes option pamservice login option pammodule account option pamcontrol sufficient option type tacplus...
Страница 33: ...management_users Required If either authentication fails or TACACS server is not reachable then user is not allowed to access the router success done new_authtok_reqd done authinfo_unavail ignore default die Local database is only checked if TACACS server is not reachable UCI system pam_auth 0 pammodule auth Opt pammodule Selects which TACACS module this part of configuration relates to auth auth ...
Страница 34: ...Page 34 of 336 The router uses a package called Dropbear to configure the SSH server on the box You can configure Dropbear via the web interface or through an SSH connection by editing the file stored on etc config_name dropbear 6 11 1 Configuration packages used Package Sections dropbear dropbear 6 11 2 SSH access using the web interface In the top menu click System Administration The Administrat...
Страница 35: ...dropbear dropbear 0 RootPasswordAuth Opt RootPasswordAuth Allows the root user to login with password 0 Disabled 1 Enabled Web Gateway ports UCI dropbear dropbear 0 GatewayPorts Opt GatewayPorts Allows remote hosts to connect to local SSH forwarded ports 0 Disabled 1 Enabled Web Idle Session Timeout UCI dropbear dropbear 0 IdleTimeout Opt IdleTimeout Defines the idle period where remote session wi...
Страница 36: ...ation about the key its owner s ID and the digital signature of an individual that has verified the content of the certificate In asymmetric cryptography public keys are announced to the public and a different private key is kept by the receiver The public key is used to encrypt the message and the private key is used to decrypt it To access certs and private keys in the top menu click System Admi...
Страница 37: ...iour of the server and default values for certificates generated for SSL operation uhttpd supports multiple instances that is multiple listen ports each with its own document root and other features as well as cgi and lua There are two sections defined Main this uHTTPd section contains general server settings Cert this section defines the default values for SSL certificates 6 14 1 Configuration pa...
Страница 38: ...0 0 0 80 Bind at port 80 only on IPv4 interfaces 80 Bind at port 80 only on IPv6 interfaces Range IP address and or port Web Secure Listen Address and Port UCI uhttpd main listen_https Opt list listen_https Specifies the ports and address to listen on for encrypted HTTPS access The format is the same as listen_http 0 0 0 0 443 Bind at port 443 only 443 Range IP address and or port Web Home path UC...
Страница 39: ...or CGI or lua requests in seconds Requested executables are terminated if no output was generated 60 Range Web Network timeout UCI uhttpd main network_timeout Opt network_timeout Maximum wait time for network activity Requested executables are terminated and connection is shut down if no network activity occured for the specified number of seconds 30 Range Web N A UCI uhttpd main realm Opt realm D...
Страница 40: ...y exist The init script will launch one webserver instance per section A standard uhttpd configuration is shown below root VA_router uci show uhttpd uhttpd main uhttpd uhttpd main listen_http 0 0 0 0 80 uhttpd main listen_https 0 0 0 0 443 uhttpd main home www uhttpd main rfc1918_filter 1 uhttpd main cert etc uhttpd crt uhttpd main key etc uhttpd key uhttpd main cgi_prefix cgi bin uhttpd main scri...
Страница 41: ...d UCI Package Option Description Web Days UCI uhttpd px5g days Opt days Validity time of the generated certificates in days 730 Range Web Bits UCI uhttpd px5g bits Opt bits Size of the generated RSA key in bits 1024 Range Web Country UCI uhttpd px5g country Opt country ISO code of the certificate issuer Web State UCI uhttpd px5g state Opt state State of the certificate issuer Web Location UCI uhtt...
Страница 42: ...blin option location Dublin option commonname 00E0C8000000 6 15 Basic authentication httpd conf For backward compatibility reasons uhttpd uses the file etc httpd conf to define authentication areas and the associated usernames and passwords This configuration file is not in UCI format Authentication realms are defined in the format prefix username password with one entry and a line break Prefix is...
Страница 43: ...curing uhttpd By default uhttpd binds to 0 0 0 0 which also includes the WAN port of your router To bind uhttpd to the LAN port only you have to change the listen_http and listen_https options to your LAN IP address To get your current LAN IP address enter uci get network lan ipaddr Then modify the configuration appropriately uci set uhttpd main listen_http 192 168 1 1 80 uci set uhttpd main liste...
Страница 44: ...ver the IP address changes the client notifies the DNS provider to update the corresponding domain name When the DNS provider responds to queries for the domain name it sets a low lifetime typically a minute or two at most on the response so that it is not cached Updates to the domain name are thus visible throughout the whole Internet with little delay Note most providers impose restrictions on h...
Страница 45: ...CI ddns name update_url Opt update_url Defines the customer DNS provider Displayed when the service is set to custom in the web UI Web Hostname UCI ddns name domain Opt domain Defines the fully qualified domain name associated with this entry This is the name to update with the new IP address as needed Web Username UCI ddns name username Opt username Defines the user name to use for authenticating...
Страница 46: ..._unit 10 Range Web Check time unit UCI ddns name check_unit Opt check_unit Defines the time unit to use for check for an IP change Used in conjunction with check_interval minutes hours Web Force update every UCI ddns name force_interval Opt force_interval Defines how often to force an IP update to the provider Used in conjunction with force_unit 72 Disabled Range Enabled Web Force time unit UCI dd...
Страница 47: ... 336 ddns ddns1 check_unit minutes ddns ddns1 force_interval 72 ddns ddns1 force_unit hours ddns ddns1 interface dsl0 Package options for DDNS root VA_router uci export ddns package ddns config service ddns1 option enabled 1 option service_name dyndns org option domain fqdn_of_interface option username test option password test option ip_source network option ip_network dsl0 option check_interval ...
Страница 48: ...SSH session Note this document shows no host name in screen grabs Throughout the document we use the host name VA_router The system configuration contains a logging section for the configuration of a Syslog client 8 1 Configuration package used Package Sections system main timeserver 8 2 Configuring system properties To set your system properties in the top menu click System There are four section...
Страница 49: ...zone UCI system main timezone Opt timezone Specifies the time zone that the date and time should be rendered in by default Web n a UCI system main timezone Opt time_save_interval_min Defines the interval in minutes to store the local time for use on next reboot 10m Table 12 Information table for general settings section 8 2 2 Logging Figure 26 The logging section in system properties Web Field UCI...
Страница 50: ...conditions 3 Alert Should be addressed immediately 2 Emergency System is unusable 1 Web Cron Log Level UCI system main cronloglevel Opt cronloglevel Sets the maximum log level for kernel messages to be logged to the console Only messages with a level lower or level equal to the configured level will be printed to the console Web value Description UCI Normal Normal operation messages 8 Warning Erro...
Страница 51: ...formation table for the language and style page 8 2 4 Time synchronization Figure 28 The time synchronization section in system properties Web Field UCI Package Option Description Web Enable built in NTP Server UCI system ntp Opt config timeserver Enables NTP server Web NTP update interval UCI system ntp interval_hours Opt interval_hours Specifies interval of NTP requests in hours Default value se...
Страница 52: ... time in the future In the top menu select System Reboot The System page appears Ensure you have saved all your configuration changes before you reboot Figure 29 The reboot page Check the Reboot now check box and then click Reboot 8 3 System settings using UCI root VA_router uci show system system main system system main hostname VA_router system main timezone UTC system main log_ip 1 1 1 1 system...
Страница 53: ...ver 0 VA_router pool ntp org list server 10 10 10 10 8 4 System diagnostics 8 4 1 System events Events in the system have a class sub class and severity All events are written to the system log 8 4 1 1 Logread To view the system log enter root VA_router logread Shows the log root VA_router logread tail Shows end of the log root VA_router logread more Shows the log page by page root VA_router logre...
Страница 54: ... log_size and log_type as below root VA_router uci export system package system config system main option hostname VA_router option zonename UTC option timezone GMT0 option conloglevel 8 option cronloglevel 8 option time_save_interval_hour 10 option log_hostname serial option log_ip 1 1 1 1 option log_port 514 option log_file root syslog messages option log_size 400 option log_type file The above ...
Страница 55: ...in persistent storage is validated To avoid any unrecoverable errors during the process you must follow several safety steps described in this chapter On successful completion of the process you can restart the device running the new firmware 9 1 Software versions If you have software versions prior to 72 002 to upgrade firmware using the web interface go to section 9 1 2 If you have software vers...
Страница 56: ...ure 31 The status page showing software version 72 002 In the Firmware Version row the first two digits of the firmware version identify the hardware platform for example LIS 15 while the remaining digits 00 72 002 show the software version 9 1 2 Upgrading router firmware for software versions pre 72 002 Copy the new firmware issued by Virtual Access to a PC connected to the router In the top menu...
Страница 57: ...or Browse Note the button will vary depending on the browser you are using Select the appropriate image and then click Flash Image The Flash Firmware Verify page appears Figure 33 The flash firmware verify page Click Proceed The System Flashing page appears Figure 34 The system flashing page When the waiting for router icon disappears the upgrade is complete and the login homepage appears To verif...
Страница 58: ...h operations page appears Figure 36 The flash operations page Under Flash Operations click Flash Image Only the inactive image is available to flash Select the appropriate image and then wait until image has loaded Note this process may take a while depending on the available connection speed When the image has loaded the Update Firmware page appears Figure 37 The flash firmware verify page Click ...
Страница 59: ... firmware if you click OK to return to the Flash Operations page There you can manually select Made Active after reboot Then click Reboot Now in the Reboot using Active Configuration section 9 1 5 Update flash image and reboot using new image immediately option Figure 39 The firmware update page after update flash image and reboot option selected If you select Update flash image and reboot using n...
Страница 60: ...event that the firmware upgrade fails the Failed verification File is most likely corrupt or similar message will appear in the Verify file integrity row No changes will be made to the system and the general message File verification failed appears 9 1 7 Verify the firmware has been upgraded successfully To check the firmware version in the top menu browse to System Flash Operations or after route...
Страница 61: ...er enter which curl which atftp The output shows the available application usr bin curl ATFTP Inline command usage atftp g r LIS 15 00 72 002 image l tmp LIS 15 00 72 002 image x x x x where x x x x is the IP address of your PC g is get operation and l r are local and remote file name to store CURL Inline command usage curl tftp x x x x LIS 15 00 72 002 image o tmp LIS 15 00 72 002 image where x x...
Страница 62: ...lication Note it is the user s responsibility to verify the image before starting to write image to flash process To use the image check on downloaded image enter image check tmp LIS 15 00 72 002 image In the case of any image corruption appropriate error message will be displayed Error no SquashFS filesystem after CRC d section data length 3 Error read failed expected at least 3 more bytes or oth...
Страница 63: ...sh alt After a while the checksum will be calculated Calculating checksum 08761cd03e33c569873bcc24cf2b7389 7006920 LIS 15 00 72 002 This MD5 Verify and compare the checksum with the MD5 sum of the downloaded image If the checksum of the written firmware in altimage matches the one from the downloaded image in tmp then the new firmware has been programmed successfully Setup an alternative image Pro...
Страница 64: ...outer s web interface and command line CLI When showing examples of the command line interface we use the host name VA_router to indicate the system prompt For example the table below displays what the user should see when entering the command to show the current configuration in use on the router root VA_router va_config sh 10 1 System information General information about software and configurat...
Страница 65: ...00E0C8121215 VA_MODEL GW0000 VA_ACTIVEIMAGE image2 VA_ACTIVECONFIG config1 VA_IMAGE1VER VIE 16 00 44 VA_IMAGE2VER VIE 16 00 44 10 2 Identify your software version To check which software version your router is running in the top menu browse to Status Overview Figure 43 The status page showing a software version prior to 72 002 Figure 44 The status page showing software version 72 002 In the Firmwa...
Страница 66: ...onfig1 and etc config2 Multiple configuration files exist in each folder Each configuration file contains configuration parameters for different areas of functionality in the system A symbolic link exists at etc config which always points to one of factconf config1 or config2 is the active configuration file Files that appear to be in etc config are actually in etc factconf config1 config2 dependi...
Страница 67: ... format It is used internally to evaluate configuration files as shell scripts import config Imports configuration files in UCI syntax add config section type Adds an anonymous section of type section type to the given configuration add_list config section option string Adds the given string to an existing list option show config section option Shows the given option section or configuration in co...
Страница 68: ...A_router etc config1 cp etc config2 etc config1 10 8 Exporting a configuration file If you have software versions prior to 72 002 to export a configuration file using the web interface go to section 10 8 1 If you have software version 72 002 or above export a configuration file using the web interface go to section 10 8 2 To export a configuration file using CLI for any software version go to sect...
Страница 69: ...operations page In the Flash Operation section click the configuration file in the Contents column to download it 10 8 3 Exporting a configuration file using UCI You can view any configuration file segment using UCI To export the running configuration file enter root VA_router uci export To export the factory configuration file enter root VA_router uci c etc factconf export To export config1 or co...
Страница 70: ...figuration file using the web interface for software versions pre 72 002 You can import a configuration file to the alternate configuration segment using the web interface This will automatically reboot the router into this configuration file In the top menu select System Backup Flash Firmware The Flash operations page appears Figure 47 The flash operations page Under Backup Restore choose Restore...
Страница 71: ...import a configuration file to the alternate configuration segment using the web interface In the top menu select System Flash Operations The Flash operations page appears Figure 49 The flash operations page In the Operations column click Upload new Select the appropriate file Figure 50 The flash operations succeed upload configuration page If you select Flash image and do not reboot the router wi...
Страница 72: ...____________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 72 of 336 10 9 3 Importing a configuration file using UCI You can import a configuration file to any file segment using UCI To import to config1 enter root VA_router uci c etc config1 import paste in config file CTRL D Note it is very important that the config file is in the correct format otherwise it will not impor...
Страница 73: ... uci set system main password root VA_router uci commit system To reboot the system enter root VA_router reboot The system provides a Unix like command line Common Unix commands are available such as ls cd cat top grep tail head more and less Typical pipe and redirect operators are also available such as The system log can be viewed using any of the following commands root VA_router logread root V...
Страница 74: ...current folder enter root VA_router ls bin etc lib opt sbin usr bkrepos home linuxrc proc sys var dev init mnt root tmp www For more details add the l argument root VA_router ls l drwxrwxr x 2 root root 642 Jul 16 2012 bin drwxr xr x 5 root root 1020 Jul 4 01 27 dev drwxrwxr x 1 root root 0 Jul 3 18 41 etc drwxr xr x 1 root root 0 Jul 9 2012 lib drwxr xr x 2 root root 3 Jul 16 2012 mnt drwxr xr x ...
Страница 75: ...prompt To view scheduled jobs enter root VA_router crontab l 0 slaupload 00FF5FF92752 TFTP 1 172 16 250 100 69 To view currently running processes enter root VA_router ps PID Uid VmSize Stat Command 1 root 356 S init 2 root DW keventd 3 root RWN ksoftirqd_CPU0 4 root SW kswapd 5 root SW bdflush 6 root SW kupdated 8 root SW mtdblockd 89 root 344 S logger s p 6 t 92 root 356 S init 93 root 348 S sys...
Страница 76: ...em UCI consists of a Command Line Utility CLI the files containing the actual configuration data and scripts that take the configuration data and apply it to the proper parts of the system such as the networking interfaces Entering the command uci on its own will display the list of valid arguments for the command and their format root VA_router lib config uci Usage uci options command arguments C...
Страница 77: ...ith a text editor but for scripts GUIs and other programs working directly with UCI files export config Exports the configuration in a UCI syntax and does validation import config Imports configuration files in UCI syntax changes config Lists staged changes to the given configuration file or if none given all configuration files add config section type Adds an anonymous section of type section typ...
Страница 78: ... 2 2 Export a configuration Using the uci export command it is possible to view the entire configuration of the router or a specific package Using this method to view configurations does not show comments that are present in the configuration file root VA_router uci export httpd package httpd config httpd option port 80 option home www 11 2 3 Show a configuration tree The configuration tree format...
Страница 79: ...switch 0 eth1 D It is also possible to display a limited subset of a configuration root VA_router uci show network wan network wan interface network wan username foo network wan password bar network wan proto 3g network wan device dev ttyACM0 network wan service umts network wan auto 0 network wan apn hs vodafone ie 11 2 4 Display just the value of an option To display a specific value of an indiv...
Страница 80: ...a_eventd va_eventd main enabled yes va_eventd main event_queue_file tmp event_buffer va_eventd main event_queue_size 128K va_eventd conn_tester 0 conn_tester va_eventd conn_tester 0 name Pinger va_eventd conn_tester 0 enabled yes va_eventd conn_tester 0 type ping va_eventd conn_tester 0 ping_dest_addr 192 168 250 100 va_eventd conn_tester 0 ping_success_duration_sec 5 va_eventd target 0 target va_...
Страница 81: ...d urls etc config monitor Monitor details Basic etc config dropbear SSH server options etc config dhcp Dnsmasq configuration and DHCP settings etc config firewall NAT packet filter port forwarding etc etc config network Switch interface L2TP and route configuration etc config system Misc system settings including syslog Other etc config snmpd SNMPd settings etc config uhttpd Web server options uHT...
Страница 82: ...be combined into a single list of values with the same order as in the configuration file The indentation of the option and list statements is a convention to improve the readability of the configuration file but it is not syntactically required Usually you do not need to enclose identifiers or values in quotes Quotes are only required if the enclosed value contains spaces or tabs Also it is legal...
Страница 83: ...iguration files when it boots up The router is installed with a factory config that will allow it to contact Activator The autoload feature controls the behaviour of the router in requesting firmware and configuration files this includes when to start the Activation process and the specific files requested The HTTP Client uhttpd contains information about the Activator server and the protocol used...
Страница 84: ...gnals the end of the autolaod sequence to Activator Activator identifies the device using the serial number of the router syntax is used to denote the serial number of the router when requesting a file The requested files are written to the alternate image or config segment You can change the settings either directly in the configuration file or via appropriate UCI set commands It is normal proced...
Страница 85: ...oad main StartTimer Opt StartTimer Defines how long to wait after the boot up completes before starting activation 10 Range 0 300 secs Web Retry Timer UCI autoload main RetryTimer Opt RetryTimer Defines how many seconds to wait between retries if a download of a particular autoload entry fails 30 Range 0 300 secs Web N A UCI autoload main NumberOfRetries Opt Numberofretries Defines how many retrie...
Страница 86: ...ge Opt BootUsingImage Specifies which image to boot up with after the activation sequence completes successfully Altimage Alternative image Image 1 image 1 Image 2 image 2 Entries Web Configured UCI autoload entry x Configured Opt Configured Enables the autoload sequence to process this entry 1 Enabled 0 Disabled Web Segment Name UCI autoload entry x SegmentName Opt SegmentName Defines where the d...
Страница 87: ...d main BootUsingConfig altconfig autoload main BootUsingImage altimage autoload entry 0 entry autoload entry 0 Configured yes autoload entry 0 SegmentName altconfig autoload entry 0 RemoteFilename ini autoload entry 1 entry autoload entry 1 Configured yes autoload entry 1 SegmentName altimage autoload entry 1 RemoteFilename img autoload entry 2 entry autoload entry 2 Configured yes autoload entry ...
Страница 88: ...e img config entry option Configured yes option SegmentName config1 option RemoteFilename vas 12 7 HTTP Client configuring activation using the web interface This section contains the settings for the HTTP Client used during activation and active updates of the device The httpclient core section configures the basic functionality of the module used for retrieving files from Activator during the ac...
Страница 89: ... that uses http port 80 This can be an IP address or FQDN The syntax should be x x x x 80 or FQDN 80 Multiple servers should be separated by a space using UCI Web Secure Server IP Address UCI httpclient default SecureFileServer Opt list SecureFileServer Specifies the address of Secure Activator that uses port 443 This can be an IP address or FQDN The syntax should be x x x x 443 or FQDN 443 Multip...
Страница 90: ... key etc httpclient key Range Web N A UCI ValidateServerCertificateFieldEnabled Opt ValidateServerCertificate Defines the field in the server certificate that the client should check 1 Enabled 0 Disabled Web N A UCI httpclient default ActivatorChunkyDownlo adPath Opt ActivatorChunkyDownloadPath Enables partial download activations and active updates The default value is httpclient default Activato...
Страница 91: ...icateKey etc httpclient key httpclient default ActivatorChunkyDownloadPath activator partial download httpclient default ChunkSize 100k httpclient default RateLimit 2 httpclient default CAFile httpclient default IgnoreServerCertificateStatus 0 12 9 Httpclient Activator configuration using package options root VA_router uci export httpclient package httpclient config core default option Enabled yes...
Страница 92: ...users user x password Opt password Specifies the user s password When entering the user password enter in plain text using the password option After reboot the password is displayed encrypted via the CLI using the hashpassword option UCI management_users user x hashpassword Opt hashpassword Note a SRP user password will be displayed using the srphash option Web n a UCI management_users user x webu...
Страница 93: ...in details 12 11 Configuring the management user password using UCI The user password is displayed encrypted via the CLI using the hashpassword option root VA_router uci show management_users management_users user 0 username test management_users user 0 hashpassword 1 XVzDHHPQ SKK4geFonctihuffMjS4U0 If you are changing the password via the UCI enter the new password in plain text using the passwor...
Страница 94: ...using UCI root VA_router uci show management_users management_users user 0 user management_users user 0 enabled 1 management_users user 0 username test management_users user 0 hashpassword 1 XVzDHHPQ SKK4geFonctihuffMjS4U0 management_users user 0 webuser 1 management_users user 0 linuxuser 1 management_users user 0 papuser 0 management_users user 0 chapuser 0 management_users user 0 srpuser 0 mana...
Страница 95: ... Page 95 of 336 12 15 Configuring user access to specific web pages To specify particular pages a user can view add the list allowed_pages Examples are listallowed_pages admin status The user can view admin status page only listallowed_pages admin system flashops The user can view flash operation page only To specify monitor widgets only enter listallowed_pages monitor widgetname Example widget na...
Страница 96: ...ction describes how to configure an Ethernet interface including configuring the interface as a DHCP server adding the interface to a firewall zone mapping the physical switch ports and defining loopback interface 13 1 Configuration packages used Package Sections network interface route va_switch alias firewall zone dhcp dhcp 13 2 Configuring an Ethernet interface using the web interface To create...
Страница 97: ...ernet interfaces Ports are marked with capital letters starting with A Type in space separated port character in the port map fields ATM Bridges ATM bridges expose encapsulated Ethernet in AAL5 connections as virtual Linux network interfaces which can be used in conjunction with DHCP or PPP to dial into the provider network 13 2 1 Interface overview editing an existing interface To edit an existin...
Страница 98: ...aces UCI network if name type Opt type If you select this option then the new logical interface created will act as a bridging interface between the chosen existing physical interfaces Empty Bridge Configures a bridge over multiple interfaces Web Cover the following interface UCI network if name ifname Opt ifname Physical interface name to assign to this logical interface If creating a bridge over...
Страница 99: ... IPv4 address of the interface This is optional if an IPv6 address is provided Web IPv4 netmask UCI network if name netmask Opt netmask Subnet mask to be applied to the IP address of this interface Web IPv4 gateway UCI network if name gateway Opt gateway IPv4 default gateway to assign to this interface optional Web IPv4 broadcast UCI network if name broadcast Opt broadcast Broadcast address This i...
Страница 100: ...ce to connect automatically on boot up 0 Disabled 1 Enabled Web Monitor interface state UCI network if name monitored Opt monitored Enabled if status of interface is presented on Monitoring platform 0 Disabled 1 Enabled Web Override MAC address UCI network if name macaddr Opt macaddr Override the MAC address assigned to this interface Must be in the form hh hh hh hh hh hh where h is a hexadecimal ...
Страница 101: ...fined in network if name ifname Empty Bridge Configures a bridge over multiple interfaces Web Enable STP UCI network if name stp Opt stp Enable Spanning Tree Protocol This option is only available when the Bridge Interfaces option is selected 0 Disabled 1 Enabled Web VLAN PCP to skb priority mapping UCI network if name vlan_qos_map_ingress Opt list vlan_qos_map_ingress VLAN priority code point to ...
Страница 102: ...th2 eth 3 Table 23 Information table for physical settings page 13 2 3 4 Loopback interfaces Loopback interfaces are defined in exactly the same way as ethernet interfaces Please see section above Note There is no software limitation as to how many loopback interfaces can exist on the router 13 2 3 5 Common configuration firewall settings Use this section to select the firewall zone you want to as...
Страница 103: ...n for this IP alias In this example the name ethalias1 is used Figure 58 The IP Aliases section Web Field UCI Package Option Description UCI network alias name ifname Opt config interface aliasname Assigns the alias name UCI network alias name interface Opt interface This maps the IP Alias to the interface UCI network alias name proto Opt proto This maps the interface protocol to the alias Table 2...
Страница 104: ...ay UCI network alias name gateway Opt gateway Defines the gateway for the IP alias Table 25 Information table for IP alias general setup page 13 2 4 4 IP aliases advanced settings Figure 60 The IP Aliases advanced settings section Web Field UCI Package Option Description Web IPv4 Broadcast UCI network alias name bcast Opt bcast Defines the IP broadcast address for the IP alias Web DNS Server UCI n...
Страница 105: ...b Field UCI Package Option Description Web Ignore interface UCI dhcp dhcp x ignore Opt ignore Defines whether the DHCP pool should be enabled for this interface If not specified for the DHCP pool then default is disabled i e dhcp pool enabled 0 Disabled 1 Enabled Web n a UCI dhcp dhcp x start Opt start Defines the offset from the network address for the start of the DHCP pool It may be greater tha...
Страница 106: ...ption Opt list dhcp_option Defines additional options to be added for this dhcp pool For example with list dhcp_option 26 1470 or list dhcp_option mtu 1470 you can assign a specific MTU per DHCP pool Your client must accept the MTU option for this to work Options that contain multiple vales should be separated by a space Example list dhcp_option 6 192 168 2 1 192 168 2 2 No options defined Syntax ...
Страница 107: ...1 network ethalias1 netmask 255 255 255 0 network ethalias1 gateway 10 10 10 10 network ethalias1 bcast 10 10 10 255 network ethalias1 dns 8 8 8 8 firewall zone 0 zone firewall zone 0 name lan firewall zone 0 input ACCEPT firewall zone 0 output ACCEPT firewall zone 0 forward ACCEPT firewall zone 0 network lan newinterface root VA_router uci show dhcp dhcp dhcp 0 dhcp dhcp dhcp 0 start 100 root VA_...
Страница 108: ...ast 2 2 2 255 list vlan_qos_map_ingress 1 2 list vlan_qos_map_ingress 2 1 config alias ethalias1 option proto static option interface newinterface option ipaddr 10 10 10 1 option netmask 255 255 255 0 option gateway 10 10 10 10 option bcast 10 10 10 255 option dns 8 8 8 8 root VA_router uci export firewall package firewall config zone option name lan option input ACCEPT option output ACCEPT option...
Страница 109: ... as to how many loopback interfaces can exist on the router An example showing a partial uci export of a loopback interface configuration is shown below root VA_router uci export network config interface loopback option proto static option ifname lo option ipaddr 127 0 0 1 option netmask 255 0 0 0 13 4 Configuring port maps 13 5 Port map packages Package Sections Network va_switch 13 5 1 Configuri...
Страница 110: ...ort C Web eth2 UCI network va_switch 0 eth2 Opt eth2 Defines eth0 physical switch port mapping Must be entered in upper case A Eth2 assigned to switch port A B Eth2 assigned to switch port B C Eth2 assigned to switch port C D Eth2 assigned to switch port C Web eth3 UCI network va_switch 0 eth3 Opt eth3 Defines eth0 physical switch port mapping Must be entered in upper case A Eth3 assigned to switc...
Страница 111: ...2 0 237 Mask 255 255 255 255 UP POINTOPOINT RUNNING NOARP MULTICAST MTU 1400 Metric 1 RX packets 6 errors 0 dropped 0 overruns 0 frame 0 TX packets 23 errors 0 dropped 0 overruns 0 carrier 0 collisions 0 txqueuelen 3 RX bytes 428 428 0 B TX bytes 2986 2 9 KiB eth0 Link encap Ethernet HWaddr 00 E0 C8 12 12 15 inet addr 192 168 100 1 Bcast 192 168 100 255 Mask 255 255 255 0 inet6 addr fe80 2e0 c8ff ...
Страница 112: ...5 255 255 0 inet6 addr fe80 2e0 c8ff fe12 1215 64 Scope Link UP BROADCAST RUNNING MULTICAST MTU 1500 Metric 1 RX packets 7710 errors 0 dropped 0 overruns 0 frame 0 TX packets 535 errors 0 dropped 0 overruns 0 carrier 0 collisions 0 txqueuelen 1000 RX bytes 647933 632 7 KiB TX bytes 80978 79 0 KiB 13 6 2 ARP table status To show the current ARP table of the router enter root GW7314 arp 10 67 253 14...
Страница 113: ...nterfaces and different subnets You can manually configure lease time as well as setting static IP to host mappings Domain Name Server DNS is responsible for resolution of IP addresses to domain names on the internet Dnsmasq is the application which controls DHCP and DNS services Dnsmasq has two sections one to specify general DHCP and DNS settings and one or more DHCP pools to define DHCP operati...
Страница 114: ..._______________________________________________________________________ _____________________________________________________________________________________________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 114 of 336 Figure 65 The DHCP and DNS page ...
Страница 115: ...ocal Opt local Specifies the local domain Names matching this domain are never forwarded and are resolved from DHCP or host files only lan Range Web Local Domain UCI dhcp dnsmasq 0 domain Opt domain Specifies local domain suffix appended to DHCP names and hosts file entries lan Range Web Log Queries UCI dhcp dnsmasq 0 logqueries Opt logqueries Writes received DNS requests to syslog 0 Disabled 1 En...
Страница 116: ...e given DHCP leases will be stored The DHCP lease file allows leases to be picked up again if dnsmasq is restarted tmp dhcp leas es Store DHCP leases in this file Range Web Ignore resolve file UCI dhcp dnsmasq 0 noresolv Opt noresolv Defines whether to use the local DNS file for resolving DNS 0 Use local DNS file 1 Ignore local DNS file Web Resolve file UCI dhcp dnsmasq 0 resolvfile Opt resolvfile...
Страница 117: ...ttings Figure 67 The TFTP settings section Web Field UCI Package Option Description Web Enable TFTP Server UCI dhcp dnsmasq 0 enable_tftp Opt enable_tftp Enables the TFTP server 0 Disabled 1 Enabled Web Enable TFTP Server UCI dhcp dnsmasq 0 tftp_root Opt tftp_root Defines root directory for file served by TFTP Web Enable TFTP Server UCI dhcp dnsmasq 0 dhcp_boot Opt dhcp_boot Defines the filename o...
Страница 118: ...s Figure 68 The advanced settings page Web Field UCI Package Option Description Web Filter private UCI dhcp dnsmasq 0 Opt boguspriv Enables disallow option for forwarding reverse lookups for local networks This rejects reverse lookups to private IP ranges where no corresponding entry exists in etc hosts 1 Enabled 0 Disabled Web Filter useless UCI dhcp dnsmasq 0 filterwin2k Opt filterwin2k Enables ...
Страница 119: ...order of the resolve file 1 Enabled 0 Disabled Web Bogus NX Domain override UCI dhcp dnsmasq 0 bogusnxdomain Opt list bogusnxdomain A list of hosts that supply bogus NX domain results When using UCI multiple servers should be entered with a space between them Empty list Range Web DNS server port UCI dhcp dnsmasq 0 port Opt port Listening port for inbound DNS queries 53 Set to 0 to disable DNS func...
Страница 120: ...I n a Opt n a Displays the remaining lease time Table 34 Information table for active leases section 14 2 6 Static leases Use static leases to assign fixed IP addresses and symbolic hostnames to DHCP clients Static leases are also required for non dynamic interface configurations where only hosts with a corresponding lease are served Click Add to add a new lease entry Figure 70 The static leases s...
Страница 121: ...ists all available options their default value as well as the corresponding dnsmasq command line option These are the default settings for the common options root VA_router uci show dhcp dhcp dnsmasq 0 dnsmasq dhcp dnsmasq 0 domainneeded 1 dhcp dnsmasq 0 boguspriv 1 dhcp dnsmasq 0 filterwin2k 0 dhcp dnsmasq 0 localise_queries 1 dhcp dnsmasq 0 logqueries 1 dhcp dnsmasq 0 rebind_protection 1 dhcp dn...
Страница 122: ...outer uci show dhcp config dnsmasq option domainneeded 1 option rebind_protection 1 option rebind_localhost 1 option local lan option domain lan option authoritative 1 option readethers 1 option leasefile tmp dhcp leases list interface lan list server 1 2 3 4 list server 4 5 6 7 list rebind_domain test1 domain list rebind_domain tes2 domain option logqueries 1 option resolvfile tmp resolv1 conf au...
Страница 123: ...type present in the etc config dhcp file to cover the LAN interface You can disable a lease pool for a specific interface by specifying the ignore option in the corresponding section A minimal example of a dhcp section is shown below root VA_router uci show dhcp lan dhcp lan dhcp dhcp lan interface lan dhcp lan start 100 dhcp lan limit 150 dhcp lan leasetime 12h dhcp lan ignore 0 root VA_router uc...
Страница 124: ...h list dhcp_option 26 1470 or list dhcp_option mtu 1470 you can assign a specific MTU per DHCP pool Your client must accept the MTU option for this to work No options defined Syntax Option_number option_value Web n a UCI dhcp pool_name dynamicdhcp Opt dynamicdhcp Defines whether to allocate DHCP leases 1 Dynamically allocate leases 0 Use etc ethers file for serving DHCP leases Web n a UCI dhcp poo...
Страница 125: ...es User Manual Issue 1 9 Page 125 of 336 15 Configuring VLAN 15 1 Maximum number of VLANs supported Virtual Access routers support up to 4095 VLANs 15 2 Configuration package used Package Sections Network 15 3 Configuring VLAN using the web interface 15 3 1 Create a VLAN interface To configure VLAN using the web interface in the top menu select Network Interfaces Click Add new interface The Create...
Страница 126: ... and netmask DHCP Client Address and netmask are assigned by DHCP Unmanaged Unspecified IPv6 in IPv4 RFC4213 Used with tunnel brokers IPv6 over IPv4 Stateless IPv6 over IPv4 transport GRE Generic Routing Encapsulation protocol IOT L2TP Layer 2 Tunnelling Protocol PPP Point to Point Protocol PPPoE PPP over Ethernet PPPoATM PPP over ATM LTE UMTS GPRS EV DO CDMA UMTS or GPRS connection using an AT st...
Страница 127: ...configuration with fixed address and netmask DHCP Client Address and netmask are assigned by DHCP Unmanaged Unspecified IPv6 in IPv4 RFC4213 Used with tunnel brokers IPv6 over IPv4 Stateless IPv6 over IPv4 transport GRE Generic Routing Encapsulation protocol IOT L2TP Layer 2 Tunnelling Protocol PPP Point to Point Protocol PPPoE PPP over Ethernet PPPoATM PPP over ATM LTE UMTS GPRS EV DO CDMA UMTS o...
Страница 128: ...t of DNS server IP addresses optional Table 38 Information table for VLAN general settings 15 3 3 Firewall settings VLAN Use this section to select the firewall zone you want to assign to the VLAN interface Select unspecified to remove the interface from the associated zone or fill out the create field to define a new zone and attach the interface to it Figure 73 Firewall settings page When you ha...
Страница 129: ... configure VLANs through CLI The VLAN configuration file is stored on etc config network uci export network package network config interface vlan100 option proto static option ifname eth0 100 option monitored 0 option ipaddr 192 168 100 1 option netmask 255 255 255 0 option gateway 192 168 100 10 option broadcast 192 168 100 255 option dns 8 8 8 8 Modify these settings by running uci set parameter...
Страница 130: ...network configuration shows how to configure VLAN priorities for specific interfaces VLANs root VA_router uci export network package network config va_switch option eth0 A E option eth1 B F option eth2 C G option eth3 D option eth4 H config interface VLAN_1 option type bridge option proto static option ipaddr 10 1 28 99 option netmask 255 255 0 0 option ifname eth0 eth4 config interface VLAN_2 opt...
Страница 131: ...lan_qos_map_egress 0 1 The above sample configuration specifies that any frames on VLAN2 VLAN3 and VLAN4 will be processed or have their PCP value adjusted according to QoS values set VLAN1 VLAN1 is an untagged VLAN so there are no 802 1Q tags on the frames VLAN2 Any frames received on VLAN2 destined to VLAN2 with PCP priority of 1 will be forwarded without altering the priority it will be still s...
Страница 132: ...ighest priority and 0 is the lowest These queues prioritise 802 1Q tagged frames as they are received on the port these are hardware defined When 802 1Q frames are received on the port they are processed according to the above queues on arrival even if not defined in the configuration Then if value vlan_qos_map_ingress is configured you can modify the PCP priority for egress if the frame was to be...
Страница 133: ...ce criteria parameters 17 1 QoS configuration overview A minimal QoS configuration usually consists of One interface section Some rules allocating packets to at least two buckets Configuration of the buckets 17 2 Configuration packages used Package Sections qos interface classgroup class classify 17 3 Configuring QoS using the web interface Browse to the router s IP address and login Select Networ...
Страница 134: ...nables or disables QoS interface 1 Enabled 0 Disabled Web Classification group UCI qos interface classgroup Opt classgroup Creates a mapping before previously created classgroup and interface to which it should be assigned to Web Calculate overhead UCI qos interface overhead Opt overhead Decreases upload and download ratio to prevent link saturation Web Half duplex UCI qos interface halfduplex Opt...
Страница 135: ...ource host Web Destination host UCI Opt Destination host Web Service UCI Opt Selectable service Web Protocol UCI Opt Protocol to classify Web Ports UCI Opt Upload speed kbits sec Web Number of bytes UCI Opt Number of bytes for bucket Table 40 Information table for classification rules 17 4 Configuring QoS using UCI You can also configure QoS using UCI The configuration file is stored on etc config...
Страница 136: ...ch it should be assigned to Web Calculate overhead UCI qos interface overhead Opt overhead Decrease upload and download ratio to prevent link saturation Web Half duplex UCI qos interface halfduplex Opt halfduplex Enables or disables half duplex operation 1 Enabled 0 Disabled Web Download speed UCI qos interface download Opt download Download speed limit in kbits sec Web Upload speed UCI qos interf...
Страница 137: ...tsize 1500 Opt packetsize Specifies packet size for the class in bytes UCI qos Normal avgrate 30 Opt avgrate Average rate for this class value in of bandwidth in UCI qos Normal priority 5 Opt priority Specifies priority for the class in UCI qos Express class Opt Express Specifies class name UCI qos Express packetsize 1000 Opt packetsize Specifies packet size for the class in bytes UCI qos Express ...
Страница 138: ... classify 0 target Express Opt target Specifies target class UCI qos classify 0 proto udp Opt proto Specifies protocol 17 5 Example QoS configurations config interface ADSL option classgroup Default option enabled 1 option overhead 1 option download 900 option upload 245 config classgroup Default option classes Express Normal option default Normal config class Normal option packetsize 1500 option ...
Страница 139: ...ols are not used or they are not configured for such subnets They can be created based on outgoing interface or next hop IP address 18 1 Configuration package used Package Sections network route 18 2 Configuring static routes using the web interface In the top menu select Network Static Routes The Routes page appears Figure 78 The routes page In the IPv4 Routes section click Add Web Field UCI Pack...
Страница 140: ...ackage Option Description Web Interface UCI network route 1 interface Opt interface Specifies the logical interface name of the parent or master interface this route belongs to It must refer to one of the defined interface sections Web target UCI network route 1 target Opt target Specifies the route network IP address or subnet in CIDR notation Eample 2001 0DB8 100 F00 BA3 1 64 Web Gateway UCI net...
Страница 141: ... example a route named myroute will be network myroute To define a named route using UCI enter network name_your_route route network name_your_route interface lan To define a named route using package options enter config route name_your_route option interface lan 18 5 IPv4 routes using UCI The command line example routes in the subsections below do not have a configured name root VA_router uci sh...
Страница 142: ...option interface lan option target 2 2 2 2 option netmask 255 255 255 255 option gateway 192 168 100 1 option metric 1 option mtu 1500 18 7 IPv6 routes using UCI root VA_router uci show network network route 1 route network route 1 interface lan network route 1 target 2001 0DB8 100 F00 BA3 1 64 network route 1 gateway 2001 0DB8 99 1 network route 1 metric 1 network route 1 mtu 1500 18 8 IPv6 route...
Страница 143: ..._______________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 143 of 336 18 9 Static routes diagnostics 18 9 1 Route status To show the current routing status enter root VA_router route n Kernel IP routing table Destination Gateway Genmask Flags Metric Ref Use Iface 192 168 100 0 255 255 255 0 U 0 0 0 eth0 Note a route will only be displayed in the routing table when the int...
Страница 144: ...between gateway hosts each with its own router in a network of autonomous systems BGP is often the protocol used between gateway hosts on the internet The routing table contains a list of known routers the addresses they can reach and a cost metric associated with the path to each router so that the best available route is chosen 19 1 Configuration package used Package Sections bgpd routing peer r...
Страница 145: ... UCI bgpd bgpd asn Opt asn Defines the ASN for the local router Type in the ASN Blank Range 1 4294967295 Web Network UCI bgpd bgpd network Opt list network Sets the list of networks that will be advertised to neighbours in prefix format 0 0 0 0 0 Separate multiple networks by a space using UCI Ensure the network prefix matches the one shown in the routing table See Routes section below Table 43 In...
Страница 146: ...atches AS path Route Metric Matches route metric BGP Community Matches BGP community Web Match value UCI bgpd ROUTEMAP match Opt match Defines the value of the match type Format depends on the Match Type selected In the case of IP address and BGP Community values the match value is parsed as a list of items to match Web Set Option UCI bgpd ROUTEMAP set_type Opt set_type Defines the set option to b...
Страница 147: ... of the neighbour Web Autonomous System Number UCI bgpd peer 0 asn Opt asn Sets the ASN of the remote peer Blank Range 1 4294967295 Web Route Map UCI bgpd peer 0 route_map Opt route_map Sets route map name to use with this neighbour Web Route Map Direction UCI bgpd peer 0 route_map_in Opt route_map_in Defines the direction the route map should be applied 1 In 0 Out Table 45 Information table for B...
Страница 148: ...68 101 1 32 bgpd ROUTEMAP set_type ip next hop bgpd ROUTEMAP set 192 168 101 2 32 To change any of the above values use UCI set command 19 4 Configuring BGP using packages options root VA_router uci export bgpd package bgpd config routing bgpd option enabled yes option router_id 3 3 3 3 option asn 1 list network 11 11 11 0 29 list network 192 168 103 1 32 config peer option route_map_in yes option...
Страница 149: ..._______________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 149 of 336 19 5 View routes statistics To view routes statistics in the top menu click Status Routes The routing table appears Figure 83 The routing table To view routes via the command line enter root support route n Kernel IP routing table Destination Gateway Genmask Flags Metric Ref Use Iface 10 1 0 0 0 0 0 0 2...
Страница 150: ...nnection using the web interface Note if you are creating multiple mobile interfaces simply repeat the steps in this chapter for each interface Multiple interfaces are required for dual SIM or multiple radio module scenarios Configuring static routes and or Multi WAN can be used to manage these interfaces In the top menu select Network Interfaces The Interfaces Overview page appears 20 2 1 Create ...
Страница 151: ...er 2 Tunnelling Protocol PPP PPPoE PPPoATM LTE UMTS GPRS EV DO CDMA UMTS or GPRS connection using an AT style 3G modem Web Create a bridge over multiple interfaces UCI network 3G type Opt type Enables bridge between two interfaces Not relevant when configuring a mobile interface 0 Disabled 1 Enabled Web Cover the following interface UCI network 3G ifname Opt ifname Select interfaces for bridge con...
Страница 152: ...UCI network 3G proto Opt proto Protocol type Select LTE UMTS GPRS EV DO Option Description Static Static configuration with fixed address and netmask DHCP Client Address and netmask are assigned by DHCP Unmanaged Unspecified GRE IOT L2TP Layer 2 Tunnelling Protocol PPP PPPoE PPPoATM LTE UMTS GPRS EV DO CDMA UMTS or GPRS connection using an AT style 3G modem Web Service Type UCI network 3G service ...
Страница 153: ...tor exactly To see the current operator using SSH enter the command cat var state mobile or using the web mobile stats page at Status Mobile Stats 0 Long character format 1 Short character format 2 PLMN code Web SIM UCI network 3G sim Opt sim Defines which SIM is used on this interface 1 SIM 1 2 SIM 2 any Automatically detect Web APN UCI network 3G apn Opt apn APN name of Mobile Network Operator W...
Страница 154: ...___________________________________________ _____________________________________________________________________________________________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 154 of 336 20 2 1 2 Mobile interface advanced settings Figure 86 The advanced settings tab ...
Страница 155: ...ied metric Lower number metrics are used first when route is up 0 Range Web Use DNS servers advertised by peer UCI network 3G peerdns Opt peerdns If unchecked the advertised DNS server addresses are ignored 0 Use static DNS 1 Use advertised DNS Web Use custom DNS servers UCI network 3G dns Opt dns Specify DNS server Only available if Use DNS servers advertised by peer is unselected When multiple D...
Страница 156: ...lowing previous options in child interfaces gre option local_interface lt2p option src_ipaddr iot option wan1 wan2 6in4 option ipaddr 6to4 option ipaddr Table 48 Information table for general set up page 20 2 1 3 Mobile interface firewall settings Use this section to select the firewall zone you want to assign to the interface Select unspecified to remove the interface from the associated zone or ...
Страница 157: ...nual Issue 1 9 Page 157 of 336 20 3 2 Package options root VA_router package network config interface 3G option proto 3g option monitored 0 option auto 1 option sim any option defaultroute 1 option service auto option apn test apn option username username option password password 20 4 Diagnositcs 20 4 1 Mobile status via the web To view mobile connectivity information in the top menu select Status...
Страница 158: ...m_slot 1 mobile 3g_1_1_1 sim_in yes mobile 3g_1_1_1 imsi 240016005892879 mobile 3g_1_1_1 registered 1 Home network mobile 3g_1_1_1 reg_code 1 mobile 3g_1_1_1 registered_pkt 1 Home network mobile 3g_1_1_1 reg_code_pkt 1 mobile 3g_1_1_1 area FFFE mobile 3g_1_1_1 cell 189150A mobile 3g_1_1_1 tech 7 mobile 3g_1_1_1 technology E UTRAN mobile 3g_1_1_1 operator 0 0 Vodafone 7 mobile 3g_1_1_1 sim1_iccid 8...
Страница 159: ... The Mobile Manager feature allows you to configure SIM settings Basic settings Enable SMS configure SIM pin code select roaming SIM collect ICCCIDs and set IMSI CDMA Configure Preferred Roaming List options Callers Configure callers that can use SMS Option available only for Telit CE910 SL module 21 1 Configuration package used Package Sections mobile Main Calllers Roaming template 21 2 Configuri...
Страница 160: ...de for SIM 2 Blank Range Depends on the SIM provider Web HDR Auto User ID UCI mobile main hdr_userid Opt hdr_userid AN PPP user ID Supported on Cellient CDMA modem only Blank Range Depends on the CDMA provider Web HDR Auto User Password UCI mobile main hdr_password Opt hdr_password AN PPP password Supported on Cellient CDMA modem only Blank Range Depends on the CDMA provider Web n a UCI mobile mai...
Страница 161: ... 15 digits Web MOB_TERM_HOME registration flag UCI mobile main cdma_mob_term_home_registration_flag Opt cdma_mob_term_home_registration_flag The MOB_TERM_HOME registration flag 0 Disabled 1 Enabled Web MOB_TERM_FOR_SID registration flag UCI mobile main cdma_mob_term_for_sid_registration_flag Opt cdma_mob_term_for_sid_registration_flag The MOB_TERM_FOR_SID registration flag 0 Disabled 1 Enabled Web...
Страница 162: ...Default 0 0 Web SID NID pairs UCI mobile main cdma_sid_nid_pairs Opt cdma_sid_nid_pairs Allows specification of SID NID pairs this takes the form SID1 NID1 SID2 NID2 Format SID1 0 65535 NID 0 65535 Default 0 65535 Table 50 Information table for mobile manager CDMA settings When you have made your changes click Save Apply and then reboot 21 3 Configuring mobile manager using UCI The following examp...
Страница 163: ...t_iccids yes config caller option name vasupport option number 353871234567 option enabled yes option respond yes config caller option name vasupport1 option number 353872345678 option enabled yes option respond yes 21 4 Configuring a roaming interface template via the web interface For more information on Roaming Interface Template configuration read the chapter Automatic Operator Selection 21 5 ...
Страница 164: ... 16 29 11 user notice VirtualAccess mobile 1737 Queue sms to 353879876543 hello 21 6 Sending SMS from the router You can send an outgoing message via the command line using the following syntax sendsms 353879876543 hello root VirtualAccess Aug 10 16 29 1 user notice VirtualAccess mobile 1737 Queue sms to 353879876543 hello 21 7 Sending SMS to the router The router can accept UCI show and set comma...
Страница 165: ...ce state pings to an ICMP target signal level checks using signal threshold RSCP threshold and ECIO threshold option values A fail for any of the above health checks results in a fail After a configurable number of health check failures Multi WAN will move to the next highest priority interface Multi WAN will optionally stop the failed interface and start the new interface if required In some circ...
Страница 166: ...nding on timer set by ifup_retry_sec 0 Disabled 1 Enabled Web Alternate Mode UCI multiwan config alt_mode Opt alt_mode Enables or disables alternate mode for Multi WAN If enabled the router will use an alternate interface after reboot 0 Disabled 1 Enabled Table 51 Information table for multi WAN page When you have enabled Multi WAN you can add the interfaces that will be managed by Multi WAN for e...
Страница 167: ..._____________________________ _____________________________________________________________________________________________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 167 of 336 Figure 92 Example interface showing failover traffic destination as the added multi WAN interface ...
Страница 168: ...ted then multiwan does not send a ping health check to the icmp_host otherwise a ping is sent as normal to the icmp_host By default the conntrack_hosts is checked if the health interval is greater than 5 minutes This time threshold currently cannot be manipulated Conntrack is generally used to limit the traffic sent on a GSM network Default Conntrack checks for traffic from icmp_host IP when healt...
Страница 169: ...he minimum signal strength in dBm before considering if the interface fails signal health check Uses the value stored for sig_dbm in mobile diagnostics 115 Disabled Range 46 to 115 dBm Web RSCP Threshold dBm UCI multiwan wan rscp_threshold Opt rscp_threshold Specifies the minimum RSCP signal strength in dBm before considering if the interface fails signal health check Uses the value stored for rsc...
Страница 170: ...terfaces when using multiple WAN interfaces simultaneously Figure 93 The multi WAN traffic rules page 22 4 Configuring Multi WAN using UCI Multi WAN UCI configuration settings are stored on etc config multiwan Run UCI export or show commands to see multiwan UCI configuration settings A sample is shown below root VA_router uci export multiwan package multiwan config multiwan config option preempt y...
Страница 171: ...n wan health_recovery_retries 5 multiwan wan priority 2 multiwan wan manage_state yes multiwan wan exclusive_group 0 multiwan wan ifup_retry_sec 36000 multiwan wan icmp_hosts disable multiwan wan timeout 3 multiwan wan icmp_interval 1 multiwan wan timeout 3 multiwan wan icmp_count 1 multiwan wan conntrack_hosts disable multiwan wan signal_threshold 111 multiwan wan rscp_threshold 90 multiwan wan e...
Страница 172: ...ce ADSL option health_interval 10 option icmp_hosts dns option timeout 3 option health_fail_retries 3 option health_recovery_retries 5 option priority 1 option manage_state yes option exclusive_group 0 option ifup_retry_sec 300 option ifup_timeout_sec 40 config interface Ethernet option health_interval 10 option icmp_hosts dns option timeout 3 option health_fail_retries 3 option health_recovery_re...
Страница 173: ... restart if that fails enable Enable service autostart disable Disable service autostart When troubleshooting make sure that the routing table is correct using route n Ensure all parameters in the multi WAN package are correct The name used for multi WAN interfaces must be identical including upper and lowercases to the interface name defined in the network configuration To check the names and set...
Страница 174: ...ltiwan package is used to run failover between interfaces Typically these auto generated interfaces are sorted by signal strength Details for these interfaces are provided in the mobile package When you have created the interfaces Multi WAN manages the operation of primary predefined and failover auto created interfaces Multi WAN periodically does a health check on the active interface A health ch...
Страница 175: ... time set by multiwan option ifup_timeout continue to step 2 Otherwise go to step 4 2 A health check is periodically done on the PMP interface as determined by the multiwan option health_interval If the health check fails for the number of retries multiwan option health_fail_retries disconnect the PMP interface 3 Connect the first auto generated interface 4 If the interface connects within the tim...
Страница 176: ...re 95 The create interface page Web Field UCI Package Option Description Web Name of the new interface UCI network 3g_s sim number _ short operator name Opt 3g_s sim number _ short operator name Type the name of the new interface Type the interface name in following format 3g_s sim number _ short operator name Where sim number is number of roaming SIM 1 or 2 and short operator name is first four a...
Страница 177: ...anaged Unspecified IPv6 in IPv4 RFC4213 IPv4 tunnels that carry IPv6 IPv6 over IPv4 IPv6 over IPv4 tunnel GRE Generic Routing Encapsulation IOT L2TP Layer 2 Tunnelling Protocol PPP Point to Point Protocol PPPoE Point to Point Protocol over Ethernet PPPoATM Point to Point Protocol over ATM LTE UMTS GPRS EV DO CDMA UMTS or GPRS connection using an AT style 3G modem Web Create a bridge over multiple ...
Страница 178: ...ocol over ATM LTE UMTS GPRS EV DO CDMA UMTS or GPRS connection using an AT style 3G modem Web Service Type UCI network x service Opt service Service type that will be used to connect to the network gprs_only Allows GSM module to only connect to GPRS network lte_only Allows GSM module to only connect to LTE network cdma Allows GSM module to only connect to CDMA network auto GSM module will automati...
Страница 179: ..._____________________________________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 179 of 336 23 2 1 4 Set multi WAN options for primary predefined interface On the web interface go to Network Multi Wan The Multi WAN page appears Figure 97 The multi WAN page In the WAN Interfaces section type in the name of the Multi WAN interface Click Add The Multi WAN page appears ...
Страница 180: ...les multiwan 0 Disabled 1 Enabled Web Preempt UCI multiwan config preempt Opt preempt Enables or disables pre emption for multiwan If enabled the router will keep trying to connect to a higher priority interface depending on timer set 0 Disabled 1 Enabled Web Alternate Mode UCI multiwan config alt Opt alt Enables or disables alternate mode for multiwan If enabled the router will use an alternate i...
Страница 181: ...is generally used to limit the traffic sent on a GSM network Default Conntrack checks for traffic from icmp_host IP when health_interval is greater than 5 minutes Disable Conntrack disabled Custom Specifies an IP other than the icmp_host for conntrack to track Web Health Monitor ICMP Timeout UCI multiwan x timeout Opt timeout Sets ping timeout in seconds Choose the time in seconds that the health ...
Страница 182: ... Range 46 to 115 dBm Web RSCP Threshold dBm UCI multiwan x rscp_threshold Opt rscp_threshold Specifies the minimum RSCP signal strength in dBm before considering if the interface fails signal health check Uses the value stored for rscp_dbm in mobile diagnostics 115 Disabled Range 46 to 115 dBm Web ECIO Threshold dB UCI multiwan x ecio_threshold Opt ecio_threshold Specifies the minimum ECIO signal ...
Страница 183: ... UCI Package Option Description Web SMS Enable UCI mobile main sms Opt sms Enables SMS no Disabled yes Enabled Web Collect ICCIDs UCI mobile main init_get_iccids Opt init_get_iccids Enables or disables integrated circuit card identifier ICCID s collection functionality If enabled then both SIM 1 and SIM 2 ICCIDs will be collected otherwise it will default to SIM 1 This will be display under mobile...
Страница 184: ...tion Description Web Name UCI mobile caller 0 name Opt name Name assigned to the caller Web Number UCI mobile caller 0 number Opt number Number of the caller allowed to SMS the router Add in specific caller numbers or use the wildcard symbol Web Enable UCI mobile caller 0 enabled Opt enabled Enables or disables incoming caller ID 0 Disabled 1 Enabled Web Respond UCI mobile caller 0 respond Opt res...
Страница 185: ..._________________________________________ _____________________________________________________________________________________________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 185 of 336 23 2 3 Roaming interface template Figure 100 The roaming interface template page ...
Страница 186: ...s_only Allows GSM module to only connect to 3G network gprs_only Allows GSM module to only connect to GPRS network cdma Allows GSM module to only connect to cdma network Web APN UCI mobile roaming_template 0 apn Opt apn APN name of Mobile Network Operator Web PIN UCI mobile roaming_template 0 pincode Opt pincode SIM card s PIN number Web PAP CHAP username UCI mobile roaming_template 0 username Opt...
Страница 187: ...cified in the priority field for the PMP interface 0 Range Web Minimum ifup interval UCI multiwan wan ifup_retry_sec Opt ifup_retry_sec Not used for a roaming interface 300 Retry primary interface every 300 seconds Range Web Interface Start Timeout UCI mobile roaming_template 0 ifup_timeo ut_sec Opt ifup_timeout Specifies the time in seconds for interface to start up If it is not up after this per...
Страница 188: ...health checks after expiration of the ifup_retry_sec timer Follow the instructions in the section above for creation of the PMP interface multi WAN and Mobile Manager roaming interfaces The only change in configuration compared to the PMP roaming pre empt enabled scenario is that you must disable the pre empt option in the multi WAN package 23 2 4 1 Set multi WAN options for pre empt disabled To d...
Страница 189: ...ailures Multi WAN will disconnect the failed interface and attempt to connect to the next best roaming interface 23 2 6 Set options for automatically created interfaces failover In the top menu on the web interface page select Services Mobile Manager The Mobile Manager page appears There are three sections Basic settings Configure SMS select roaming SIM and collect ICCCIDs Callers Configure caller...
Страница 190: ...e manager basic settings 23 2 6 2 Caller settings Web Field UCI Package Option Description Web Name UCI mobile caller 0 name Opt name Name assigned to the caller blank range Web Number UCI mobile caller 0 number Opt number Number of the caller allowed to SMS the router Add in specific caller numbers or use the wildcard symbol blank range Web Enable UCI mobile caller 0 enabled Opt enabled Enables o...
Страница 191: ...late page Web Field UCI Package Option Description Web Interface Signal Sort UCI mobile roaming_template 0 sort_sig_st rength Opt sort_sig_strength Sorts interfaces by signal strength priority so those that have a better signal strength will be tried first Web Roaming SIM UCI mobile main roaming_sim Opt roaming_sim Sets which slot to insert roaming SIM card 1 SIM slot 1 2 SIM slot 2 Web Firewall Z...
Страница 192: ... mobile roaming_template 0 health_int erval Opt health_interval Sets the period to check the health status of the interface The Health Monitor interval will be used for interface state checks ping interval signal strength checks Web Health Monitor ICMP Host s UCI mobile roaming_template 0 icmp_host s Opt icmp_hosts Specifies target IP address for ICMP packets Disable Disables the option DNS server...
Страница 193: ...nimum signal strength in dBm before considering if the interface fails signal health check Uses the value stored for sig_dbm in mobile diagnostics 115 dBm Disabled range 46 to 115 dBm Table 61 Information table for roaming interface template When you have configured your settings click Save Apply 23 2 7 1 Set multi WAN operation From the top menu select Network Multi Wan The Multi WAN page appears...
Страница 194: ... the network configuration file enter root VA_router uci export network package network config interface loopback option ifname lo option proto static option ipaddr 127 0 0 1 option netmask 255 0 0 0 config interface lan option ifname eth0 option proto static option ipaddr 192 168 100 1 option netmask 255 255 255 0 config interface 3g_s1_voda option auto 0 option proto 3g option service umts optio...
Страница 195: ...mts network 3g_s1_voda apn test IE network 3g_s1_voda username test network 3g_s1_voda password test network 3g_s1_voda sim 1 network 3g_s1_voda operator vodafone IE 23 3 1 2 Roaming interface configuration The roaming interface configurations are stored in the mobile package etc config mobile To view the mobile configuration file enter root VA_router uci export mobile config mobile main option sm...
Страница 196: ...ds no mobile caller 0 caller mobile caller 0 name Test mobile caller 0 number mobile caller 0 enabled yes mobile caller 0 respond yes mobile roaming_template 0 roaming_template mobile roaming_template 0 roaming_sim 1 mobile roaming_template 0 firewall_zone wan mobile roaming_template 0 apn test IE mobile roaming_template 0 username test mobile roaming_template 0 password test mobile roaming_templa...
Страница 197: ...ion health_fail_retries 3 option health_interval 3 option timeout 1 option icmp_hosts disable option priority 10 option exclusive_group 3g option signal_threshold 95 option ifup_retry_sec 350 option ifup_timeout_sec 180 option manage_state 1 To view the uci command of package multiwan enter root VA_router uci show multiwan multiwan config multiwan multiwan config enabled 1 multiwan config preempt ...
Страница 198: ...vailable values are 0 Disabled 1 Enabled 23 4 Configuring no PMP roaming using UCI The roaming interface configuration file is stored in the mobile package etc config mobile To view the mobile package enter root VA_router uci export mobile package mobile config mobile main option sms yes option roaming_sim 1 option debug 1 config caller option name Eval option number option enabled yes option resp...
Страница 199: ...name Eval mobile caller 0 number mobile caller 0 enabled yes mobile caller 0 respond yes mobile roaming_template 0 roaming_template mobile roaming_template 0 roaming_sim 1 mobile roaming_template 0 firewall_zone wan mobile roaming_template 0 apn stream co uk mobile roaming_template 0 username default mobile roaming_template 0 password void mobile roaming_template 0 service umts mobile roaming_temp...
Страница 200: ...an config option enabled yes option preempt no option alt_mode no To see multiwan package via uci enter root VA_router uci show multiwan multiwan config multiwan multiwan config enabled yes multiwan config preempt no multiwan config alt_mode no 23 5 Automatic operator selection diagnostics via the web interface 23 5 1 Checking the status of the Multi WAN package When interfaces are auto created th...
Страница 201: ...__________________________________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 201 of 336 Figure 106 The interface overview page To check the status of the interface you are currently using in the top menu click Status The Interface Status page appears Scroll down to the bottom of the page to view Multi WAN Stats Figure 107 The status page multi WAN status section page ...
Страница 202: ...__________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 202 of 336 23 6 Automatic operator selection diagnostics via UCI To check interfaces created in the multi WAN package enter root VA_router cat var const_state multiwan Figure 108 Example of output from the command cat var const_stat multiwan To check interfaces created in the network package enter root VA_router cat va...
Страница 203: ...____________________________________________ _____________________________________________________________________________________________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 203 of 336 Figure 109 Example of output from the command cat var const_state network ...
Страница 204: ...___________________________________________________________________________________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 204 of 336 To check the status of the interface you are currently using enter root VA_router cat var const_state_ mobile Figure 110 Example of output from the command cat vat const_state_ mobile ...
Страница 205: ...ad the chapter Dynamic Multipoint Virtual Private Network DMVPN The number of IPSec tunnels supported by Virtual Access routers is not limited in any way by software the only hardware limitation is the amount of RAM installed on the device 24 1 Configuration package used Package Sections strongswan general connection secret 24 2 Configuring IPSec using the web interface To configure IPSec using th...
Страница 206: ...ith any new automatically keyed connection using an ID from a different IP address deemed to replace all old ones using that ID Participant IDs normally are unique so a new automatically keyed connection using the same ID is almost invariably intended to replace an old one 0 Disabled 1 Enabled replace Identical to Yes keep Rejects new IKE SA and keep the duplicate established earlier Web Cache CRL...
Страница 207: ...g with PSK authentication is less secure method than main mode and should be avoided 0 Disabled 1 Enabled Web Name UCI strongswan connection X name Opt name Specifies a name for the tunnel Web Autostart Action UCI strongswan connection X auto Opt auto Specifies when the tunnel is initiated start On start up route When traffic routes this way add Loads a connection without starting it ignore Ignore...
Страница 208: ...ublic IP address of the remote peer Web Local ID UCI strongswan connection X localid Opt localid Defines the local peer identifier Web Remote ID UCI strongswan connection X remoteid Opt remoteid Defines the remote peer identifier Web Local LAN IP Address UCI strongswan connection X locallan Opt locallan Defines the local IP of LAN Web Local LAN IP Address Mask UCI strongswan connection X locallanm...
Страница 209: ...remoteproto Restricts the connection to a single protocol on the remote side Web Remote Port UCI strongswan connection X remoteport Opt remoteport Restricts the connection to a single port on the remote side Web Authby UCI strongswan connection X authby Opt authby Defines how the two secure gateways should authenticate Note using aggressive mode along with PSK authentication is unsecure and should...
Страница 210: ...ec settings Figure 114 The IPSec connections settings Web Field UCI Package Option Description Web XAuth Identity UCI strongswan connection X xauth_identity Opt xauth_identity Defines Xauth ID Web IKE Algorithm UCI strongswan connection X ike Opt ike Specifies the IKE algorithm to use The format is encAlgo authAlgo DHGroup encAlgo 3des aes128 aes256 serpent twofish blowfish authAlgo md5 sha sha2 D...
Страница 211: ... and a WAN ADSL interface called dsl and wanted to use one of these interfaces for this IPSec connection you would use wan adsl Web IKE Life Time UCI strongswan connection X ikelifetime Opt ikelifetime Specifies how long the keyring channel of a connection ISAKMP or IKE SA should last before being renegotiated 3h Timespec 1d 3h 25m 10s Web Key Life UCI strongswan connection X keylife Opt keylife S...
Страница 212: ...ction X dpdtimeout Opt dpdtimeout Defines the timeout interval after which all connections to a peer are deleted in case of inactivity 150s Timespec 1d 2h 25m 10s Web n a UCI strongswan connection X inherit_child Opt inherit_child Defines whether the existing phase two IPSEC SA is maintained through IKE rekey for this tunnel This is normally set to match the behaviour on the IPSEC headend 0 Delete...
Страница 213: ...crettype Specifies the authentication mechanism to be used by the two peers Psk Preshared secret Pubkey Public key signatures Rsasig RSA digital signatures Ecdsasig Elliptic Curve DSA signatures Xauth Extended authentication Web Secret UCI strongswan secret X secret Opt secret Defines the secret Table 67 Information table for IPSec secrets settings 24 3 Configuring IPSec using UCI 24 3 1 Common se...
Страница 214: ...swan connection 0 auto start uci set strongswan connection 0 type tunnel uci set strongswan connection 0 remoteaddress 100 100 100 100 uci set strongswan connection 0 localid 192 168 209 1 uci set strongswan connection 0 remoteid 100 100 100 100 uci set strongswan connection 0 locallan 192 168 209 1 uci set strongswan connection 0 locallanmask 255 255 255 255 uci set strongswan connection 0 remote...
Страница 215: ... modp1024 option esp 3des md5 option waniface wan option dpdaction hold 24 3 3 Shunt connection If the remote LAN network is 0 0 0 0 0 then all traffic generated on the local LAN will be sent via the IPSec tunnel This includes the traffic destined to the router s IP address To avoid this situation you must include an additional config connection section Commands touch etc config strongswan uci add...
Страница 216: ... how the local end point of the tunnel proves its identity to the remote end point A sample secret section which could be used with the connection section in Connection Settings is shown below Commands to add a secret for psk auth touch etc config strongswan uci add strongswan secret uci set strongswan secret 0 enabled yes uci set strongswan secret 0 localaddress 192 168 209 1 uci set strongswan s...
Страница 217: ...oteaddress 100 100 100 100 uci set strongswan secret 1 secret xauth uci set strongswan secret 1 secrettype XAUTH uci commit This will create the following output config secret option enabled yes option idtype userfqdn option userfqdn testxauth option remoteaddress 100 100 100 100 option secret xauth option secrettype XAUTH 24 4 Configuring an IPSec template for DMVPN via the web interface To confi...
Страница 218: ...t uniqueids Defines whether a particular participant ID should be kept unique with any new automatically keyed connection using an ID from a different IP address deemed to replace all old ones using that ID Participant IDs normally are unique so a new automatically keyed connection using the same ID is almost invariably intended to replace an old one 0 Disabled 1 Enabled replace Identical to Yes k...
Страница 219: ...17 GW7304 Series User Manual Issue 1 9 Page 219 of 336 24 4 2 Configure connection settings Scroll down to view the connection settings section If you want to create a DMVPN you do not need to configure all settings as the DMVPN will automatically create them using the template Leave the following sections blank Remote GW Address Local ID Remote Id Local LAN IP Address Local LAN IP Address Mask Re...
Страница 220: ...______________________________________________________ _____________________________________________________________________________________________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 220 of 336 Figure 117 The connections settings section ...
Страница 221: ...ection X type Opt type Defines the type of IPSec connection tunnel Connection uses tunnel mode transport Connection uses transport mode pass Connection does not perform any IPSec processing drop Connection drops all the packets Web Remote GW Address UCI strongswan connection X remoteaddress Opt remoteaddress Sets the public IP address of the remote peer Leave blank for DMVPN Web Local ID UCI stron...
Страница 222: ... authby Defines how the two secure gateways should authenticate Note using aggressive mode along with PSK authentication is unsecure and should be avoided Pubkey For public key signatures Rsasig For RSA digital signatures ecdsasig For Elliptic Curve DSA signatures Psk Using a preshared key xauthrsasig Enables eXtended Authentication XAuth with addition to RSA signatures xauthpsk Using extended aut...
Страница 223: ... and a WAN ADSL interface called dsl and wanted to use one of these interfaces for this IPSec connection you would use wan adsl Web IKE Life Time UCI strongswan connection X ikelifetime Opt ikelifetime Specifies how long the keyring channel of a connection ISAKMP or IKE SA should last before being renegotiated 3h Timespec 1d 3h 25m 10s Web Key Life UCI strongswan connection X keylife Opt keylife S...
Страница 224: ...ent if no other traffic is received 30s Timespec 1d 2h 25m 10s Web DPD Timeout UCI strongswan connection X dpdtimeout Opt dpdtimeout Defines the timeout interval after which all connections to a peer are deleted in case of inactivity 150s Timespec 1d 2h 25m 10s Table 69 Information table for IPSec connections settings 24 4 3 Configure secrect settings Each tunnel requires settings to configure how...
Страница 225: ...tings 24 5 Configuring an IPSec template to use with DMVPN The following example shows how to configure an IPSec connection template to use with DMVPN Commands touch etc config strongswan uci set strongswan general general uci set strongswan general enabled yes uci set strongswan general strictcrlpolicy no uci set strongswan general uniqueids yes uci set strongswan general cachecrls yes uci set st...
Страница 226: ... uci set strongswan secret 0 secrettype psk uci set strongswan secret 0 secret secret This will create package strongswan config general general option enabled yes option strictcrlpolicy no option uniqueids yes option cachecrls yes option nattraversal yes config connection option enabled yes option name dmvpn option type transport option localproto gre option remoteproto gre option ike aes sha1 mo...
Страница 227: ... underscore for example dmvpn_213 233 148 2 24 7 IPSec diagnostics using UCI 24 7 1 IPSec configuration To view IPSec configuration via UCI enter root VA_router uci export strongswan To restart strongSwan enter root VA_router etc init d strongswan restart 24 7 2 IPSec status 24 7 3 To view IPSec status enter root VA_router ipsec statusall Security Associations 1 up 0 connecting dmvpn_89_101_154_15...
Страница 228: ...system is a chained processing filter where packets pass through various rules The first rule that matches is executed often leading to another rule chain until a packet hits either ACCEPT or DROP REJECT Accepted packets pass through the firewall Dropped packets are prohibited from passing Rejected packets are also prohibited but an ICMP message is returned to the source host A minimal firewall co...
Страница 229: ...efaults input Opt input Default policy for the INPUT chain Accept Accepted packets pass through the firewall Reject Rejected packets are blocked by the firewall and ICMP message is returned to the source host Drop Dropped packets are blocked by the firewall Web Output UCI firewall defaults output Opt output Default policy for the Output chain Accept Accepted packets pass through the firewall Rejec...
Страница 230: ...y by software the only hardware limitation is the amount of RAM installed on the device 25 2 2 1 Firewall zone general settings Figure 121 The firewall zone general settings Web Field UCI Package Option Description Web name UCI firewall zone label name Opt name Sets the unique zone name Maximum of 11 characters allowed Note the zone label is obtained by using the uci show firewall command and is o...
Страница 231: ...es Forward rules for a zone describe what happens to traffic passing between different interfaces within that zone Accept Accepted packets pass through the firewall Reject Rejected packets are blocked by the firewall and ICMP message is returned to the source host Drop Dropped packets are blocked by the firewall Web Masquerading UCI firewall zone label masq Opt masq Specifies whether outgoing zone...
Страница 232: ...ubnets are allowed Web Restrict Masquerading to given destination subnets UCI firewall zone label masq_dest Opt masq_dest Limits masquerading to the given destination subnets Negation is possible by prefixing the subnet with Multiple subnets are allowed Multiple IP addresses subnets should be separated by a space Example option masq_dest 1 1 1 1 2 2 2 0 24 Web Force connection tracking UCI firewal...
Страница 233: ...eb Field UCI Package Option Description Web Allow forward to destination zones UCI firewall forwarding label dest Opt dest Allows forward to other zones Enter the current zone as the source Enabling this option puts two entries into the firewall file destination and source UCI firewall forwarding label src Opt src Web Allow forward from source zones UCI firewall forwarding label dest Opt dest Allo...
Страница 234: ...starting from 0 Web Protocol UCI firewall redirect label proto Opt proto Defines layer 4 protocol to match incoming traffic tcp udp Match either TCP or UDP packets tcp Match TCP packets only udp Match UDP packets only Web Source UCI firewall redirect label src Opt src Specifies the traffic source zone It must refer to one of the defined zone names When using the web interface this is set to WAN in...
Страница 235: ...p port for the redirect traffic Web Enable UCI firewall redirect label enabled Opt enabled Specifies if this redirect should be enabled or disabled 0 Disabled 1 Enabled Table 75 Information table for firewall port forward settings The defined redirects can be sorted into a specific order to be applied More specific rules should be placed first After the redirect is created and saved to make change...
Страница 236: ...all redirect label reflection Opt reflection Enable or disable NAT reflection for this redirect 0 reflection disabled 1 reflection enabled Web Extra arguments UCI firewall redirect label extra Opt extra Passes extra arguments to IP tables This is useful to specify additional match options like m policy dir in for IPSec The arguments are entered as text strings Table 76 Information table for port f...
Страница 237: ...s This option is only valid when ICMP is selected as the protocol ICMP types can be listed as either type names or type numbers Note for a full list of valid ICMP type names see the ICMP Options table below Web Source zone UCI firewall rule label src Opt src Specifies the traffic source zone must refer to one of the defined zone names For typical port forwards this is usually WAN Web Source MAC ad...
Страница 238: ...ffix Example 3 hour Web n a UCI firewall rule label limit_burst Opt limit_burst Sets maximum initial number of packets to match This number gets recharged by one every time the limit specified above is not reached up to this number Web n a UCI firewall rule label recent Opt recent Sets number of allowed connections within specified time This command takes two values e g recent 2 120 will allow 2 c...
Страница 239: ...e icmp esp ah sctp or all or it can be a numeric value representing one of these protocols or a different one A protocol name from etc protocols is also allowed The number 0 is equivalent to all Dest Specifies the traffic destination zone must refer to one of the defined zone names If specified the rule applies to forwarded traffic else it is treated as input rule dest_ip Match incoming traffic di...
Страница 240: ...d ACCEPT Note this command is only required if there is no defaults section 25 3 2 Firewall zone settings To set up a firewall zone enter uci add firewall zone uci set firewall zone 1 name lan uci set firewall zone 1 input ACCEPT uci set firewall zone 1 output ACCEPT uci set firewall zone 1 forward ACCEPT uci set firewall zone 1 network lan1 wifi_client uci set firewall zone 1 family any uci set f...
Страница 241: ... set firewall redirect 1 dest_port 2005 uci set firewall redirect 1 enabled 1 25 3 5 Firewall traffic rules To set traffic rules enter uci add firewall rule uci set firewall rule 1 enabled 1 uci set firewall rule 1 name Allow_ICMP uci set firewall rule 1 family any uci set firewall rule 1 proto ICMP uci set firewall rule 1 icmp_type any uci set firewall rule 1 src wan uci set firewall rule 1 src_m...
Страница 242: ...0 ba3 64 option target ACCEPT Similarly the following rule is automatically treated as IPv4 only config rule option src wan option dest_ip 88 77 66 55 option target REJECT Rules without IP addresses are automatically added to iptables and ip6tables unless overridden by the family option Redirect rules port forwards are always IPv4 since there is no IPv6 DNAT support at present 25 5 Implications of...
Страница 243: ...ion tracking By default the firewall will disable connection tracking for a zone if no masquerading is enabled This is achieved by generating NOTRACK firewall rules matching all traffic passing via interfaces referenced by the firewall zone The purpose of NOTRACK is to speed up routing and save memory by circumventing resource intensive connection tracking in cases where it is not needed You can c...
Страница 244: ...anner because it is not using default port 22 config redirect option name ssh option src wan option proto tcpudp option src_dport 5555 option dest_ip 192 168 1 100 option dest_port 22 option target DNAT option dest lan 25 7 3 Source NAT SNAT Source NAT changes an outgoing packet destined for the system so that is looks as though the system is the source of the packet Define source NAT for UDP and ...
Страница 245: ...estination port forwarding This usage is similar to SNAT but as the destination IP address is not changed machines on the destination network need to be aware that they ll receive and answer requests from a public IP address that is not necessarily theirs Port forwarding in this fashion is typically used for load balancing config redirect option src wan option src_dport 80 option dest lan option d...
Страница 246: ...a forward rule rejecting traffic from LAN to WAN on the ports 1000 1100 config rule option src lan option dest wan option dest_port 1000 1100 option proto tcpudp option target REJECT 25 7 9 Denial of service protection rule The example below shows a sample configuration of SSH DoS attack where if more than two SSH connections are attempted within 120 seconds every further connection will be droppe...
Страница 247: ...addr 10 1 28 122 option netmask 255 255 0 0 option ifname eth1 eth3 12 option ipv4_rp_filter 1 25 7 11 Simple DMZ rule The following rule redirects all WAN ports for all protocols to the internal host 192 168 1 2 config redirect option src wan option proto all option dest_ip 192 168 1 2 25 7 12 Transparent proxy rule external The following rule redirects all outgoing HTTP traffic from LAN through ...
Страница 248: ...e below redirects all outgoing HTTP traffic from LAN through a proxy server listening at port 3128 on the router itself config redirect option src lan option proto tcp option src_dport 80 option dest_port 3128 25 7 14 IPSec passthrough This example enables proper forwarding of IPSec traffic through the WAN AH protocol config rule option src wan option dest lan option proto ah option target ACCEPT ...
Страница 249: ...l management After a configuration change to rebuild firewall rules enter root VA_router etc init d firewall restart Executing the following command will flush all rules and set the policies to ACCEPT on all standard chains root VA_router etc init d firewall stop To manually start the firewall enter root VA_router etc init d firewall start To permanently disable the firewall enter root VA_router e...
Страница 250: ..._____________________ _____________________________________________________________________________________________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 250 of 336 To direct the output to a file for later inspection enter root VA_router FW_TRACE 1 fw reload 2 tmp iptables lo ...
Страница 251: ...or_memory monitor_process pass system trapreceiver usm_user view The SNMP application has several configuration sections System and Agent Configures the SNMP agent Com2Sec Maps SNMP community names into an arbitrary security name Group Assigns community names and SNMP protocols to groups View and Access Creates views and sub views of the whole available SNMP tree and grants specific access to thos...
Страница 252: ...dress es and port s on which the agent should listen udp tcp port address Web Enable Authentication Traps UCI snmpd agent 0 authtrapenabled Opt authtrapenabled Enables or disables SNMP authentication trap 0 Disabled 1 Enabled Note this is the SNMP poll authentication trap to be set when there is a community mismatch Web Enable Link State Notification UCI snmpd agent 0 link_updown_notify Opt link_u...
Страница 253: ...estrictions Web Community UCI snmpd com2sec x community Opt community Specifies the community string being presented in the request Table 81 Information table for Com2Sec settings 26 2 3 Group settings Group settings assign community names and SNMP protocols to groups Figure 130 The group settings section Web Field UCI Package Option Description Web Group UCI snmpd group x group Opt group Specifie...
Страница 254: ...snmpd view x viewname Opt viewname Specifies an arbitrary view name Typically it describes what the view shows Web Type UCI snmpd view x type Opt type Specifies whether the view lists oids that are included in the view or lists oids to be excluded from the view in which case all other oids are visible apart from those ones listed included excluded Web OID UCI snmpd view x oid Opt oid OID to be inc...
Страница 255: ...n number being used in the request any v1 v2c and usm are supported v1 SNMP v1 v2v SNMP v2 usm SNMP v3 any Any SNMP version Web Level UCI snmpd access x level Opt level Specifies the security level For SNMP v1 and SNMP v2c level must be noauth noauth auth priv Web Prefix UCI snmpd access x prefix Opt prefix Prefix specifies how context above should be matched against the context of the incoming pd...
Страница 256: ... use in trap messages for this host Table 85 Information table for trap receiver settings 26 2 7 Inform receiver Inform receiver settings define a notification receiver that should be sent SNMPv2c INFORM notifications Figure 134 The inform receiver settings page Web Field UCI Package Option Description Web Host UCI snmpd informreceiver x host Opt host Host address Can be either an IP address or an...
Страница 257: ...Name Backup Access 4 config agent option agentaddress UDP 161 option authtrapenabled 1 option link_updown_notify 1 Another sample agent configuration shown below causes the agent to listen on UDP port 161 TCP port 161 and UDP port 9161 on only the interface associated with the localhost address config agent option agentaddress UDP 161 tcp 161 9161 localhost 26 3 3 com2sec settings The following sa...
Страница 258: ...om2sec public option secname ro option source default option community public config com2sec private option secname rw option source localhost option community private 26 3 4 Group settings The following example specifies that a request from the security name ro using snmp v1 v2c or USM User Based Security Model for SNM P v3 are all mapped to the public group Similarly requests from the security n...
Страница 259: ...ccess read all snmpd grp_1_access write none snmpd grp_1_access notify none snmpd grp_1_access group public snmpd grp_2_v1 group snmpd grp_2_v1 version v1 snmpd grp_2_v1 group public snmpd grp_2_v1 secname ro snmpd grp_2_v2c group snmpd grp_2_v2c version v2c snmpd grp_2_v2c group public snmpd grp_2_v2c secname ro snmpd grp_2_usm group snmpd grp_2_usm version usm snmpd grp_2_usm group public snmpd ...
Страница 260: ...ttings using package options config group public_v1 option group public option version v1 option secname ro config group public_v2c option group public option version v2c option secname ro config group public_usm option group public option version usm option secname ro config group private_v1 option group private option version v1 option secname rw config group private_v2c option group private opt...
Страница 261: ...snmpd mib2 viewname mib2 snmpd mib2 type included snmpd mib2 oid iso org dod Internet mgmt mib 2 26 3 5 2 View settings using package options config view all option viewname all option type included option oid 1 config view mib2 option viewname mib2 option type included option oid iso org dod Internet mgmt mib 2 26 3 6 Access settings The following example shows the public group being granted read...
Страница 262: ...ix exact option read all option write all option notify all 26 3 7 SNMP traps settings 26 3 7 1 SNMP trap using UCI snmpd trapreceiver 0 trapreceiver snmpd trapreceiver 0 host 1 1 1 1 161 snmpd trapreceiver 0 version v1 snmpd trapreceiver 0 community public SNMP trap using package options for SNMPv1 or v2c trap receivers config trapreceiver option host IPADDR PORT option version v1 v2c option comm...
Страница 263: ...er should the Master become unavailable This process allows the virtual router IP address es on the LAN to be used as the default first hop router by end hosts The advantage gained from using VRRP is a higher availability default path without requiring configuration of dynamic routing or router discovery protocols on every end host Two or more routers forming the redundancy cluster are configured ...
Страница 264: ... the VRRP cluster is to operate For example lan The interface name is taken from the package network Web Track Interfaces UCI vrrp g1 track_iface Opt track_iface Sets one or more WAN interfaces that VRRP should monitor If a monitored interface goes down on the Master VRRP router it goes into Fault state and the Backup VRRP router becomes the Master Web IPSec connection UCI vrrp g1 ipsec_connection...
Страница 265: ...ethod This field may be left blank if no authentication is required Web Virtual IP UCI vrrp g1 virtual_ipaddr Opt virtual_ipaddr Sets the virtual IP address and mask in prefix format For example 11 1 1 99 24 All co operating VRRP routers serving the same LAN must be configured with the same virtual IP address Web GARP UCI vrrp g1 garp_delay_sec Opt garp_delay_sec Sets the Gratuitous ARP message se...
Страница 266: ... Series User Manual Issue 1 9 Page 266 of 336 Or enter uci show vrrp vrrp main vrrp vrrp main enabled yes vrrp g1 vrrp_group vrrp g1 enabled yes vrrp g1 interface lan1 vrrp g1 track_iface lan vrrp g1 init_state BACKUP vrrp g1 router_id 1 vrrp g1 priority 115 vrrp g1 advert_int_sec 2 vrrp g1 password secret vrrp g1 virtual_ipaddr 10 1 10 150 16 vrrp g1 garp_delay_sec 5 vrrp g1 ipsec_connection Test...
Страница 267: ...IPSec configuration to the physical interface This reduces the number of lines of configuration required for a VPN development For example for a 1000 site deployment DMVPN reduces the configuration effort at the hub from 3900 lines to 13 Adding new peers spokes to the VPN requires no changes at the hub Better scalability of the network Dynamic IP addresses can be used at the peers site Spokes can ...
Страница 268: ...N interface ADSL 3G and initiate main mode IPSec in transport mode to the hub After an IPSec tunnel is established spokes register their NHRP membership with the hub GRE tunnels come up Hub caches the GRE tunnel and real IP addresses of each spoke When spoke1 wants to talk to spoke2 it sends an NHRP resolution request to the hub The hub checks its cache table and forwards that request to spoke2 Sp...
Страница 269: ...th the source of the packet Hub sends an NHRP registration reply with a NAT extension to spoke1 The NAT extension informs spoke1 that it is behind the NAT ed device Spoke1 registers its pre and post NAT address When spoke1 wants to talk to spoke2 it sends an NHRP resolution request to the hub Hub checks its cache table and forwards that request to spoke2 Spoke2 caches spoke1 s GRE pre and post NAT...
Страница 270: ...nterface The DMVPN section contains fields required to configure the parameters relative to the DMVPN Hub These are used for DMVPN tunnels such as GRE tunnels GRE tunnel remote IP DMVPN Hub IP and password 28 5 1 DMVPN general settings In the top menu select Network DMVPN The DMVPN page appears There are two sections General and DMVPN Hub Settings Figure 138 The DMVPN general section Web Field UCI...
Страница 271: ...terface on the hub For example if the mask is 255 255 0 0 the length will be 16 Web DMVPN Hub IP Address UCI dmvpn interface X nhs_ip Opt nhs_ip Configures the physical IP address for the DMVPN hub Web NHRP Authentication UCI dmvpn interface X cisco_auth Opt cisco_auth Enables authentication on NHRP The password will be applied in plaintext to the outgoing NHRP packets Maximum length is 8 characte...
Страница 272: ...c connections page In the Name column the syntax contains the IPSec name defined in package dmvpn and the remote IP address of the hub or the spoke separated by an underscore for example dmvpn_213 233 148 2 To check the status of DMVPN in the top menu click Status DMVPN Figure 141 The NBMA peers page To check DMVPN status enter opennhrpctl show Status ok Interface gre GRE Type local Protocol Addre...
Страница 273: ...n with local route local_addr Local destination IP or off NBMA subnet Protocol Address Tunnel IP address NBMA Address Pre NAT IP address if NBMA NAT OA Address is present or real address if NAT is not present NBMA NAT OA Address Post NAT IP address This field is present when Address is translated in the network Flags up Can send all packets registration ok unique Peer is unique used Peer is kernel...
Страница 274: ...e 1 9 Page 274 of 336 You can check DMVPN status using UCI commands opennhrpctl show Status ok Interface gre GRE Type local Protocol Address 11 11 11 7 32 Alias Address 11 11 11 3 Flags up Interface gre GRE Type local Protocol Address 11 11 11 3 32 Flags up Interface gre GRE Type cached Protocol Address 11 11 11 2 32 NBMA Address 178 237 115 129 NBMA NAT OA Address 172 20 38 129 Flags used up Expi...
Страница 275: ... Opt enabled Enables Terminal on the router 0 Disabled 1 Enabled Web not available UCI terminal console device Opt device String value point at the tty device in dev folder None Defalut string Device name e g ttySC0 to use serial port 0 Web not available UCI terminal console speed Opt speed Set the speed of serial connection 115200 Defalut range Supported port speed Web not available UCI terminal ...
Страница 276: ...rminal config terminal ttySC0 option enabled 0 option device ttySC0 option speed 115200 option type vt100 option flowcontrol 1 29 5 Terminal diagnostics 29 5 1 Checking Terminal entry in inittab To check if Terminal configuration is running enter the following and confirm the line referring to the device name is present and looks similar to the last line below root VA_router cat etc inittab sysini...
Страница 277: ...ne for each serial port depending on the device Each Terminal Server session has an IP endpoint and an associated specific serial port You can configure the IP endpoint of each Terminal Server session to be a TCP server each session is listening on a unique port TCP client Terminal Server makes a TCP connection to external TCP server UDP endpoint Terminal Server forwards data between a UDP stream ...
Страница 278: ...able Enables detailed debug logging 0 Disabled 1 Enabled Web Syslog severity UCI tservd main log_severity Opt log_severity Determines the syslog level Events up to this priority will be logged 0 Emergency 1 Alert 2 Critical 3 Error 4 Warning 5 Notice 6 Informational 7 Debug Web Log RX TX UCI tservd main debug_rx_tx_enable Opt debug_rx_tx_enable Enables logging data transfers 0 Disabled 1 Enabled T...
Страница 279: ...work 256 256 bytes Range 0 2048 Web Network Forwarding Timeout ms UCI tservd port 0 fwd_timeout Opt fwd_timeout Forwarding timeout in milliseconds serial to network 30 30 ms Range 0 10000 Web Network Forwarding Timer Mode UCI tservd port 0 fwd_timer_mode Opt fwd_timer_mode Forwarding timer mode serial to network Idle Timer is re started on each received data Aging Timer started on the first Rx Web...
Страница 280: ...l When either side TCP socket closes the main terminal server client re connects to the normal IP destination and the server proxy returns to listening for another connection from the far end 0 Disabled 1 Enabled Web Disable Remote Client s Local Echo Telnet option UCI tservd port 0 disable_echo Opt disable_echo Set to 1 to send IAC WILL ECHO Telnet option to remote client forcing it to disable lo...
Страница 281: ...___________________________________________ _____________________________________________________________________________________________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 281 of 336 Figure 144 The serial section fields portmode RS232 and usb serial disabled ...
Страница 282: ... port 0 parity Opt parity Serial device parity 0 None 1 Even 2 Odd 3 Space Web Stop Bits UCI tservd port 0 stops Opt stops Serial device number of stop bits 1 Range 1 2 Web Flow Control UCI tservd port 0 fc_mode Opt fc_mode Serial flow control mode 0 None 1 RTS CTS 2 XON XOFF Web RS485 Termination UCI tservd port 0 rs485_line_termination Opt rs485_line_termination Enables or disable RS485 terminat...
Страница 283: ... echo suppression timeout in milliseconds 20 Range Web n a UCI tservd port 0 v23_tx_rampdown Opt v23_tx_rampdown Defines the time in milliseconds it takes the V23 transmitter to rampdown carrier from peak to zero 30 Range Web n a UCI tservd port 0 v23_tx_maxfill Opt v23_tx_maxfill Defines the maximum transmit queue fill level in bytes 127 Range 0 255 Web Atmel USB serial card UCI tservd port 0 is_...
Страница 284: ...ge Inverted clock data transmitted on rising edge Only displayed if Atmel USB serial card is enabled 0 Normal 1 Invert Web RX MSBF UCI tservd port 0 sync_rx_msbf Opt sync_rx_msbf Defines whether most significant bit is received first Only displayed if Atmel USB serial card is enabled 0 Receive least significant bit first 1 Receive most significant bit first Web TX MSBF UCI tservd port 0 sync_tx_ms...
Страница 285: ...le Defines the value of idle character decimal to transmit in case of tranmit underrun In HDLC mode this configures inter frame fill 0 Tranmit 0 in HDLC mode 126 Transmit flags in HDLC mode 255 Tranmit 1 in HDLC mode Range 0 255 Web n a UCI tservd port 0 v23_inband_carrier_sign alling Opt v23_inband_carrier_signalling Enables signalling of carrier by sending special characters 0 Disabled 1 Enabled...
Страница 286: ...bled 951 Range 1 65535 Web Remote IP 1 UCI tservd port 0 remote_ip1 Opt remote_ip1 Destination peer IP 1 address 0 0 0 0 Range IPv4 address Web Remote IP 2 UCI tservd port 0 remote_ip2 Opt remote_ip2 Destination peer IP 2 address Only displayed if Transport Mode is TCP 0 0 0 0 Range IPv4 address Web Enable TCP Keepalives UCI tservd port 0 tcp_keepalives_enabl ed Opt tcp_keepalives_enabled Enable o...
Страница 287: ...liseconds to start reconnecting after setting DTR low 5000 5 seconds Range 0 10000 Web UDP Keepalive Interval UCI tservd port 0 udpKaIntervalMs Opt udpKaIntervalMs Defines time in milliseconds to send UDP keepalives empty UDP packets when no data to send Only displayed if transport mode is UDP 0 Disabled Range 0 65535 Web UDP Keepalive Count UCI tservd port 0 udpKaCount Opt udpKaCount Defines the ...
Страница 288: ...n remote_ip1 0 0 0 0 option remote_ip2 0 0 0 0 30 6 Terminal Server diagnostics The tservd process has to be running otherwise diagnostics options for terminal server will not be available 30 6 1 Checking Terminal Server process To check if Terminal Server is running enter root VA_router ps grep tservd 1264 root 1032 S tservd 1769 root 1496 S grep tservd If Terminal Server is running it will be sh...
Страница 289: ...v disgnostics Command syntax tserv show stats show statistics tserv clear stats clear statistics tserv show serial show serial interface status tserv send serial0 data send data to serial port 0 tserv start capture N N port number 0 to 3 start capturing rx serial data tserv print capture N N port number 0 to 3 print captured rx serial data tserv show serial txlog hex Port length Port port cfg inde...
Страница 290: ...______________________________________________________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 290 of 336 tserv show userial version show USB serial card firmware version tserv show userial cpld status show USB serial card CPLD programming status tserv upgrade userial initiate upgrade of the USB serial card tserv quit terminate termserv process ...
Страница 291: ...e web interface To create GRE interfaces through the web interface in the top menu select Network Interfaces There are three sections in the Interfaces page Section Description Interface Overview Shows existing interfaces and their status You can create new and edit existing interfaces here Port Map In this section you can map device ports to Ethernet interfaces Ports are marked with capital lette...
Страница 292: ...HCP Client Address and netmask are assigned by DHCP Unmanaged Unspecified IPv6 in IPv4 RFC4213 Used with tunnel brokers IPv6 over IPv4 Stateless IPv6 over IPv4 transport GRE Generic Routing Encapsulation protocol IOT L2TP Layer 2 Tunnelling Protocol PPP Point to Point protocol PPPoE PPP over Ethernet PPPoATM PPP over ATM LTE UMTS GPRS EV DO CDMA UMTS or GPRS connection using an AT style 3G modem W...
Страница 293: ...guration general setup Figure 147 The GRE common configuration page Web Field UCI Package Option Description Web Protocol of the new interface UCI network if name proto Opt proto Shows the protocol the interface will operate on GRE should be currently selected Web Tunnel IP Address UCI network if name ipaddr Opt ipaddr Configures local IP address of the GRE interface Web Mask Length UCI network if...
Страница 294: ...to be linked with the GRE tunnel interface optional Web Remote IP address UCI network if name remote_ip Opt remote_ip For point to point tunnels specifies Remote IP address Web TTL UCI network if name ttl Opt ttl Sets Time To Live value on the interface 128 Range Web Tunnel key UCI network if name key Opt key Sets GRE tunnel ID key optional Usually an integer Web MTU UCI network if name mtu Opt mt...
Страница 295: ...nabled Table 98 Information table for GRE advanced settings 31 2 3 GRE connection firewall settings Use this section to select the firewall zone you want to assign to this interface Select unspecified to remove the interface from the associated zone or fill out the create field to define a new zone and attach the interface to it Figure 149 GRE firewall settings Click Save and Apply This will save ...
Страница 296: ...VA_router uci show network network tunnel1 interface network tunnel1 proto gre network tunnel1 monitored 0 network tunnel1 ipaddr 172 255 255 2 network tunnel1 mask_length 24 network tunnel1 local_interface wan network tunnel1 remote_ip 172 255 255 100 network tunnel1 ttl 128 network tunnel1 key 1234 network tunnel1 mtu 1472 network tunnel1 auto 1 31 5 GRE configuration using package options root ...
Страница 297: ... 68 66 54 Bcast 10 68 66 55 Mask 255 255 255 252 inet6 addr fe80 21e 10ff fe1f 0 64 Scope Link UP BROADCAST RUNNING MULTICAST MTU 1500 Metric 1 RX packets 81 errors 0 dropped 0 overruns 0 frame 0 TX packets 127 errors 0 dropped 0 overruns 0 carrier 0 collisions 0 txqueuelen 1000 RX bytes 8308 8 1 KiB TX bytes 12693 12 3 KiB gre Tunnel1 Link encap UNSPEC HWaddr 0A 44 42 36 DB B0 00 48 00 00 00 00 0...
Страница 298: ... addr fe80 5efe a44 4236 64 Scope Link UP RUNNING MULTICAST MTU 1472 Metric 1 RX packets 7 errors 0 dropped 0 overruns 0 frame 0 TX packets 7 errors 0 dropped 0 overruns 0 carrier 0 collisions 0 txqueuelen 0 RX bytes 912 912 0 B TX bytes 8GRE route status To show the current GRE route status enter root VA_router route n Kernel IP routing table Destination Gateway Genmask Flags Metric Ref Use Iface...
Страница 299: ...y group of receivers that expresses an interest in receiving a particular data stream The receivers the designated multicast group are interested in receiving a data stream from the source They indicate this by sending an Internet Group Management Protocol IGMP host report to their closest router in the network The routers are then responsible for delivering the data from the source to the receive...
Страница 300: ...or PIM global settings 32 3 2 Interfaces configuration Figure 151 The interfaces configuration section Web Field UCI Package Option Description Web Enabled UCI pimd interface x enabled Opt enabled Enables multicast management of the given interface by the PIM application 0 Disabled 1 Enabled Web Interface UCI pimd interface x interface Opt interface Selects the interface to apply PIM settings to W...
Страница 301: ...nfig pimd To view the configuration file enter uci export pimd root VA_router etc config1 uci export pimd package pimd config routing pimd option enabled yes config interface option enabled yes option interface lan option ssm yes option igmp yes config interface option enabled yes option interface wan option ssm yes option igmp no Alternatively enter uci show pimd root VA_router etc config1 uci sh...
Страница 302: ...__________________________________________ _____________________________________________________________________________________________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 302 of 336 pimd interface 1 ssm yes pimd interface 1 igmp no To change any of the above values use uci set command ...
Страница 303: ...three types of object Forwardings Rules that define what kind of events should be generated For example you might want an event to be created when an IPSec tunnel comes up or down Targets Define the targets to send the event to The event may be sent to a target via a syslog message a snmp trap or email Connection testers Define methods to test the target is reachable IP connectivity to a server an...
Страница 304: ...s the methods to test a connection that are currently supported Type Description link Checks if the interface used to reach the target is up ping Pings the target And then assumes there is connectivity during a configurable amount of time Table 102 Event system supported connection tester methods 33 6 Configuring the event system using the web interface Configuring the event system using the web i...
Страница 305: ... be stored before being processed Default file is tmp event_buffer tmp event_buffer Range UCI va_eventd main event_queue_size Opt event_queue_size Maximum size of the event queue in bytes Default value is 128k 128K 128 kilobytes Range Table 103 Information table for event settings main section 33 7 2 Va_eventd forwarding Forwardings are section rules that define what kind of events should be gener...
Страница 306: ...tion enabled 1 option className ethernet option eventName LinkUp option severity warning critical option target syslog1 33 7 5 Forwarding table options UCI Package Option Description UCI va_eventd forwarding label enabled Opt enabled Enables or disables event generation 0 Disabled 1 Enabled UCI va_eventd forwarding label className Opt className Only generate events with the given className Availab...
Страница 307: ...on Table 104 Information table for event system forwarding rules 33 7 6 Va_eventd connection testers There are two types of connection testers ping connection tester and link connection tester Multiple connection testers can be defined and each forwarding section can be given a label for identification For example To define a connection tester label of Tester1 using package options enter config co...
Страница 308: ...ster label enabled Opt enabled Enable this connection tester 0 Disabled 1 Enabled UCI va_eventd conn_tester label type Opt type Set to ping for a ping connection tester ping Ping connection tester link Link connection tester UCI va_eventd conn_tester label ping_dest_addr Opt ping_dest_addr IP Address to ping UCI va_eventd conn_tester label ping_source Opt ping_source Source IP Address of the pings...
Страница 309: ...tion tester 0 Disabled 1 Enabled UCI va_eventd conn_tester label type Opt type Set to link for a link connection tester ping Ping connection tester link Link connection tester UCI va_eventd conn_tester label link_iface Opt link_iface Interface name to check Table 106 Information table for link connection tester settings 33 7 7 Supported targets There are four possible targets Syslog target Email t...
Страница 310: ...tion enabled 1 option type syslog option tcp_syslog 0 option target_addr 192 168 0 1 514 option conn_tester pinger option snmp_version 3 33 7 7 4 Syslog target table options UCI Package Option Description UCI va_eventd target label name Opt name Name of the target This is to be used in the forwarding section UCI va_eventd target label enabled Opt enabled Enable this target 0 Disabled 1 Enabled UCI...
Страница 311: ...l target using UCI va_eventd target 0 target va_eventd target 0 name email1 va_eventd target 0 enabled 1 va_eventd target 0 type email va_eventd target 0 smtp_addr smtp site com 587 va_eventd target 0 smtp_user john_smith site com va_eventd target 0 smtp_password secret word va_eventd target 0 use_tls 0 va_eventd target 0 tls_starttls 0 va_eventd target 0 tls_forcessl3 0 va_eventd target 0 timeout...
Страница 312: ...get syslog Syslog target email Email target snmptrap SNMP target exec Exec target UCI va_eventd target label smpt_addr Opt smtp_addr IP address or FQDNand port of the SMTP server to use Format x x x x port or fqdn port UCI va_eventd target label smtp_user Opt smtp_user Username for smtp authentication UCI va_eventd target label smtp_password Opt smtp_password Password for smtp authentication UCI v...
Страница 313: ...arget using UCI va_eventd target 0 target va_eventd target 0 name snmp1 va_eventd target 0 enabled 1 va_eventd target 0 type snmptrap va_eventd target 0 target_addr 192 168 0 1 va_eventd target 0 agent_addr 192 168 0 4 va_eventd target 0 conn_tester pinger SNMP target using package options config target option name snmp1 option enabled 1 option type snmptrap option community public option target_a...
Страница 314: ...en an exec target receives an event it executes a shell command 33 7 8 4 Exec target using UCI va_eventd target 0 target va_eventd target 0 name logit va_eventd target 0 enabled 1 va_eventd target 0 type exec va_eventd target 0 cmd_template logger t eventer eventName 33 7 8 5 Exec target using package options config target option name logit option enabled 1 option type exec option cmd_template log...
Страница 315: ...ad value internal 2 EventdConfigWarn warning p1 p2 p3 has bad value internal 3 EventdConfigUnknown informat p1 p2 field p3 is no internal 4 EventdSystemErr error p1 p2 p3 p4 p5 internal 5 EventdSystemWarn error p1 p2 p3 p4 p5 internal 6 EventdUpAndRunning informat internal 7 EventdStopped warning p1 mobile 1 SIMin notice SIM card p1 inserted mobile 2 SIMout notice SIM card p1 removed mobile 3 Link...
Страница 316: ... warning Telnet login attempt bad passwo auth 7 BadUserLuCI warning LuCI login attempt bad username auth 8 BadPasswordLuCI warning LuCI login attempt bad password auth 9 LoginSSH notice SSH login user p2 from p3 auth 10 LogoffSSH notice SSH logoff user p1 due to auth 11 LoginConsole notice Console login user p1 on p2 auth 12 LogoffConsole notice Console logoff on p1 auth 13 LoginTelnet notice Teln...
Страница 317: ...2 disconnected wifi 4 WiFiStationDetached notice WiFi station p2 disconnected wifi 5 WiFiStationAttachFailed notice WiFi station p2 failed to con wifi 5 WiFiStationAttachFailed notice WiFi station p2 failed to con ppp 1 LinkUp informat PPP for interface p2 protoco ppp 2 LinkDown informat PPP for interface p2 protoco ppp 3 ConnEstablished informat PPP connection for interface p adsl 1 LinkUp notice...
Страница 318: ...orward the l2tp event CannotFindTunnel with a severity between debug and critical to a syslog server Forward all mobile events with a severity between notice and critical to a SNMP trap manager Execute logger t eventer eventName when an Ethernet event occurs Forward all auth events via email Connection to the SNMP and syslog server is checked by sending pings Connection to the smtp server is verif...
Страница 319: ...config forwarding option enabled yes option className auth option target email config conn_tester option name mon_server option enabled 1 option type ping option ping_dest_addr 192 168 100 254 option ping_source eth0 option ping_success_duration_sec 10 config conn_tester option name smtp_server option enabled 1 option type link option link_iface eth0 config target option name syslog option enabled...
Страница 320: ...yes option tls_starttls no option tls_forcessl3 no option timeout_sec 10 option from y example com option to z example com option subject_template severityName eventName option body_template eventName class subclass happened option conn_tester smtp_server config target option name snmp option enabled yes option type snmptrap option community public option target_addr 192 168 100 254 option agent_a...
Страница 321: ...ackets received transmitted and the difference between them Packet loss average max and min Signal strength average max and min Online time Temperature average max and min The SLA Report Manager can build reports from a list of selected routers presenting a range of statistics over extended periods of time Note as well as configuring Monitor for SLA you must configure each router To configure the ...
Страница 322: ...llowing options TFTP HTTP HTTPS Enter in the relevant Server Address and the TFTP Server Port number to match Figure 153 The device settings fields 34 4 Viewing graphs When the router has started to send SLA statistics to the Monitoring platform default graphs are displayed on the SLA Reporting screen To view the graphs for one specific network interface select the relevant interface from the drop...
Страница 323: ..._______________________________________________________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 323 of 336 Figure 155 Graphs showing per hour data To view raw data click each graph to produce the following information Figure 156 Raw data information from each graph To change the range of the graph click zoom Figure 157 Altered range of graph information ...
Страница 324: ...If the scroll bar represents less than a period of one day you can also specify the start and end times to display on the graphs When you have selected a range with the scroll bar click Go to get statistics for that period Figure 158 Graph showing specified start and end times The following graphs can be displayed Packets received transmitted and the difference between them Packet loss average max...
Страница 325: ...ings interface Click Statistics A drop down menu appears The menu has the following options Create Report Edit Report Remove Report Statistics Settings 34 5 1 Create a report Select Create Report Enter the relevant parameters Report name Frequency of report Assigned devices SLA Report Elements The selected frequency of report determines how often SLA reports will be generated by the Monitor3 Repor...
Страница 326: ...____ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 326 of 336 To assign devices to the report click Change Figure 161 Assign devices to a report After clicking Change the select devices page appears this allows you to select which devices are to be members of the report Figure 162 Sample from the select devices page Click Continue and then add SLA report elements Figure 163 Add repo...
Страница 327: ...ror Count Average Signal Strength Average Error Count Max Signal Strength Max Error Count Min Signal Strength Min Bytes Transmitted Bytes Received Bytes Transmitted over Received Online time Temperature Min Temperature Max Temperature Average Select a graph name and then select a relevant range from the following options Year Month Week Day Click Add and when you have selected all graphs click Sav...
Страница 328: ...ery week and so on 34 5 2 2 Default SLA element settings The Default SLA Element settings control range and graphs Range Sets what the default range will be when a new user is created Graph Selects whteher each report element is displayed as a graph or in tabular data form The view of SLA data is customisable per user These default values set how graphs appear when you use SLA for the first time Y...
Страница 329: ...P version 3 Table 111 Information table for reporting device commands The table below shows options that are relevant only if you have selected SNMP version 3 Web Field UCI Package Option Description UCI monitor main snmp_uname Opt snmp_uname Specifies uname Blank Default value String UCI monitor main snmp_auth_pass Opt snmp_auth_pass snmpv3 authentication password UCI monitor main snmp_auth_proto...
Страница 330: ...n 2c monitor v3 keepalive monitor v3 enable yes monitor v3 interval_min 1 monitor v3 monitor_ip 172 16 250 100 monitor v3 dev_reference TEST monitor v3 snmp_version 3 monitor v3 snmp_uname TEST monitor v3 snmp_auth_pass vasecret monitor v3 snmp_auth_proto MD5 monitor v3 snmp_priv_pass vasecret monitor v3 snmp_priv_proto DES root VA_router uci export monitor package monitor config keepalive main op...
Страница 331: ...______________________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 331 of 336 list monitor_ip 172 16 250 100 option dev_reference TEST option snmp_version 3 option snmp_uname TEST option snmp_auth_pass vasecret option snmp_auth_proto MD5 option snmp_priv_pass vasecret option snmp_priv_proto DES config interface_stats stats option enabled yes option bin_period 1m option bin...
Страница 332: ...ask of uploading statistics to Monitor 2 The Virtual Access router monitors UDP keepalive packets It creates and stores statistics in bins These statistics are uploaded every hour to the Monitor server Figure 166 The SLA function This section describes how to configure SLA on a router For information on how to configure Monitor for SLA reporting read the previous section Configuring SLA on Monitor...
Страница 333: ...ce UCI slad main interface Opt interface Specifies the interface on which traffic should be monitored Web Destination Host IP Address UCI slad main_destination_host_ip_address Opt destination_host_ip_address Specifies the destination IP address for the keepalive packets that are originated on the LAN Web Destination UDP port UCI slad main destination_udp_ip_address Opt destination_udp_ip_address S...
Страница 334: ...rt slad or uci show slad uci export slad package slad config slad main option enable yes option roundtrip_timeout_msec 5000 option interface lan option destination_host_ip_address 10 1 1 2 option destination_udp_port 53 option bin_restart_period_msec 3600000 option max_bin_count 73 uci show slad slad main slad slad main enable yes slad main roundtrip_timeout_msec 5000 slad main interface lan slad ...
Страница 335: ...newest N Shows the newest valid bin range YYYYMMDDHH YYYYMMDDHH Shows all bins that match specified time range Type the command sla current To show current statistics enter root VA_router sla current Bin valid no Start time 01 01 1970 03 34 00 End time n a Pkts In 1 Pkts Out 1 Bytes In 15 Bytes Out 15 Pkts OK 1 Pkts Fail 0 Last Round Trip 1 ms Min Last Trip 1 ms Max Round Trip 1 ms Avg Round Trip ...
Страница 336: ..._______________________________________________________________________ Virtual Access 2017 GW7304 Series User Manual Issue 1 9 Page 336 of 336 Bytes Out 90 Pkts OK 6 Pkts Fail 0 Last Round Trip 0 ms Min Last Trip 1 ms Max Round Trip 1 ms Avg Round Trip 1 ms Min GSM signal quality 63 dBm Max GSM signal quality 63 dBm Avg GSM signal quality 63 dBm Availability 100 00 ...