Table of Contents Introduction to GlobeSurfer® III ....................8 Setup ............................... 9 2.1. Setting up WAN and LAN connections .................... 9 2.2. PC Network Configuration ........................ 9 GlobeSurfer® III Management Console ..................12 3.1. Accessing the GlobeSurfer® III Management Console ..............12 3.2.
1. Introduction to GlobeSurfer® III Within minutes, you can connect to your mobile network and use a wireless connection to the Internet through the mobile network. GlobeSurfer® III is compatible with GSM and 3G mobile networks and supports GPRS, EDGE, UMTS and HSDPA technologies.
2. Setup Connecting your computer or home network to the gateway is a simple procedure, varying slightly depending on your operating system. This chapter will help you to seamlessly integrate GlobeSurfer® III with your computer or home network. The Windows default network settings dictate that in most cases the setup procedure described below will be unnecessary.
Page 10
Windows XP • Access Network Connections from the Control Panel. • Right-click the Ethernet connection icon, and select Properties. • Under the General tab, select the Internet Protocol (TCP/IP) component, and press the Properties button. • The Internet Protocol (TCP/IP) properties window will be displayed. •...
Page 11
Linux • Login into the system as a super-user, by entering su at the prompt. • Type ifconfig to display the network devices and allocated IP addresses. • Type pump -i <dev>, where <dev> is the network device name. • Type ifconfig again to view the new allocated IP address. •...
3. GlobeSurfer® III Management Console The GlobeSurfer® III management console described here allows you to control various GlobeSurfer® III system parameters, using a user-friendly graphical interface. The management console includes a connection status screen, a quick setup screen, network configuration, security configuration, authentication with multiple-user support, connection monitoring and more.
3.3. Managing Tables Tables are used throughout the GlobeSurfer® III management console. They handle user-defined entries relating to elements such as network connections, local servers, restrictions and configurable parameters. The principles outlined in this section apply to all tables in the management console. In a typical table each row defines an entry in the table.
4. Home From this screen you can click on the tabs at the top left hand side to route to the following screens: • Overview - status of Internet Connection/Local Network/Storage/Printers/Services (see section 4.1) • Map View - pictorial overview of all components connected to GlobeSurfer® III (see section 4.2) •...
4.3. GlobeSurfer® III Installation Wizard The GlobeSurfer® III management console allows you to control various GlobeSurfer® III system parameters. The interface is accessed through a web browser: • Start a web browser on your PC. • Enter the address 192.168.1.1 to display the GlobeSurfer® III management console. When first logging on to the management console, the Login screen will appear.
4.3.1. Installation Wizard: Language Select the language and time zone you would like to use on the GlobeSurfer® III Management Console and Display. 4.3.2. Installation Wizard: Telephony Select the country for your telephone handset. This will adapt the telephone connector of GlobeSurfer®...
4.3.3. Installation Wizard: UMTS Check or change the following settings on the Installation screen to configure the UMTS connection: Access point name: enter the access point name as provided by your Internet Service Provider (ISP), or accept the name already set. UMTS connect method: •...
4.3.4. Installation Wizard: Wireless SSID: the Service Set Identifier: enter a name for your local wireless network (WLAN) (maximum 32 characters). Note: Setting the SSID to something unique will make it much easier to identify your own wireless network, especially if there are other wireless networks available in the nearby area. SSID broadcast: if you set the Enabled checkbox to broadcast, then other devices can detect and connect to your WLAN.
4.3.5. Installation Wizard: Wireless Encryption In order to prohibit unauthorized access to your GlobeSurfer® III, make sure to apply sufficient security and encryption on your wireless network. If WPA2 is supported by your wireless clients it is recommended to apply WPA2 encryption to your wireless network as it offers the highest level of security.
Note: WPA/WPA2 is recommended as it provides the higher level of security due to the longer key that changes automatically. You must configure your wireless PC clients to use the same encryption type and keys. Otherwise the devices will not understand each other. Enabling wireless encryption has no security effect on wired (Ethernet) connections.
Page 21
GlobeSurfer® III TECHNICAL REFERENCE MANUAL Page 21 of 184...
4.3.7. Installation Wizard: Finish The last page of the Installation Wizard shows all the settings made on previous pages. If they all look correct, press the Finish button to apply these settings. If you want to change any settings, use the Back button to navigate to the appropriate page and modify that setting.
5. Quick Setup You can use the Quick Setup screen to change the main settings needed to use GlobeSurfer® III: Web interface and display • Language: select the language for GlobeSurfer® III. The current language setting will be restored if you do not apply the settings. Telephony •...
Page 24
• In case of inactivity, disconnect after (minutes): The default is 10 minures. Set it to zero (0) if you want the UMTS to stay connected. The maximum is 1440 minutes (24 hours). Incoming traffic is treated as inactivity. Wireless The following settings are the most important for the local Wireless LAN: •...
6. Internet Connection The WAN Cellular connection connects GlobeSurfer® III to the Internet and other networks through GSM or UMTS mobile telecommunications standards. The WAN Cellular Properties screen displays a summary of the connection. From this screen you can click on the tabs at the top left hand side to route to the following detailed screens: •...
6.2. Settings The top part of the configuration window displays general communication parameters. It is not recommended to change the default values in this screen unless you are familiar with the networking concepts they represent. Since your gateway is configured to operate with the default values, no parameter modification is necessary.
6.3. Routing You can choose to setup your gateway to use static or dynamic routing. Dynamic routing automatically adjusts how packets travel on the network, whereas static routing specifies a fixed routing path to neighbouring destinations. You can configure the following routing settings: •...
Press the Apply button to apply changes and stay on this screen. Press the Cancel button to reject changes and go back to the previous screen. 6.4. Connection Watchdog When this feature is enabled and the Watchdog timeout duration is set, the GlobeSurfer will do periodic DNS queries to the DNS server to resolve pre-defined websites e.g.
To enable the SMS Control feature, check the SMS Control Center checkbox and define a valid phone number. The phone number has to be in international format with the country prefix preceded by a ‘+’. e.g. +32475123456 for Belgium where 32 is the country prefix of Belgium. Multiple phone numbers can be defined for this feature.
Page 30
access to it through a network such as the Internet. The firewall can be activated per network connection. To enable the firewall on this network connection, select the Enabled checkbox. To learn more about your gateway's security features, please refer to section 8.2. Press the OK button to apply changes and go back to the previous screen.
7. Local Network This area provides an overview of and the ability to configure local network, storage and printer settings. From this screen you can click on the tabs at the top left hand side to route to the following detailed screens: •...
7.2. Device This screen displays a list of all the devices in the local network along with their status, and provides the ability to modify and delete each entry. For each device the following data is displayed: • Name • Number of computers connected •...
7.3.1. Overview This screen provides an overview of the wireless network. The following data is displayed: • Enable Wireless: click to checkbox to enable wireless functionality • Wireless Network (SSID): the SSID is the network name shared among all points in a wireless network.
7.3.2. Settings This screen enables you to enter more wireless settings. The following data is displayed: • SSID Broadcast: click on this checkbox to enable the SSID's broadcast. SSID broadcast is used in order to hide the name of the AP (SSID) from clients that should not be aware of its existence. •...
7.3.3. Advanced From this screen you can click on the tabs at the top left hand side to route to the following detailed screens: • General (see section 7.3.3.1) • Settings (see section 7.3.3.2) • Wireless (see section 7.3.3.3) • Advanced (see section 7.3.3.4) 7.3.3.1.
Page 36
7.3.3.3. Wireless Press the OK button to apply changes and go back to the previous screen. Press the Apply button to apply changes and stay on this screen. Press the Cancel button to reject changes and go back to the previous screen. 7.3.3.4.
7.4. Shared Storage/Disk Management This screen enables you to manage your system storage area, disks and RAID devices. The following data is displayed: • Enabled: click this checkbox to enable disk management • Status: this shows the status of disk management and how many disks are connected •...
Press the Apply button to apply changes and stay on this screen. Press the Cancel button to reject changes and go back to the previous screen. Press the Refresh button to refresh the screen. 7.4.1. RAID Properties This screen enables you to add a RAID device. The following data can be entered: •...
7.5. Shared Printers/Print Server GlobeSurfer® III includes a print server that allows printers attached to the device via the USB connection to be shared by all computers on the LAN. On this screen you can see information about your printer, as well as view a list of print jobs (when prints are in the queue).
8. Services 8.1. Overview This screen displays icons/hyperlinks for the various services available: • Firewall : this hyperlink routes to the Firewall Overview screen • File Server : this hyperlink routes to the File Server Overview screen • Print Server : this hyperlink routes to the Print Server Overview screen •...
Page 41
network devices. • The Overview screen allows you to choose the security level for the firewall (see section 1.1.1). • The Access Control screen can be used to restrict access from the local network to the Internet (see section 8.2.2). •...
8.2.1. Overview Use the Overview screen to configure the gateway’s basic security settings. The firewall regulates the flow of data between the home network and the Internet. Both incoming and outgoing data are inspected and then either accepted (allowed to pass through GlobeSurfer®...
Page 43
to this request, that determines whether a session can be established or not. You may choose from among three pre-defined security levels for GlobeSurfer® III: Minimum, Typical and Maximum. The table below summarizes the behaviour of GlobeSurfer® III for each of the three security levels.
make legitimate use of IP fragments. You will need to allow IP fragments to pass into the home network in order to make use of these select services.) Press the OK button to apply changes and go back to the Home screen. Press the Apply button to apply changes and stay on this screen.
Page 45
• Status: shows the status of the access control rule • Action: options for adding new entries or editing or deleting existing ones Click on New Entry - this routes to the Add Access Control Rule screen (see section 8.2.2.1) Click on the edit icon - this routes to the Edit Access Control Rule screen (see section 8.2.2.2) Press the OK button to apply changes and go back to the Home screen.
Page 46
IMAP – Messaging Server L2TP – Layer 2 Tuneling Protocol Ping – ICMP Echo Request POP3 – Incoming Mail SMTP – Outgoing Mail SNMP – Simple Network Management Protocol Telnet – Remote Connection TFTP – Trivial File Transfer Protocol Traceroute – Route Tracking Utility o Show All Services –...
Page 47
o Any o User Defined – this routes to the Edit Service screen (see section 8.2.2.5) o Show Basic Services – if this option is chosen a reduced list of options is displayed including: FTP - File Transfer HTTP – Web Server HTTPS –...
Page 48
Click on New Entry - this routes to the Edit Item screen (see section 8.2.2.4) Press the OK button to apply changes and go back to the previous screen. Press the Cancel button to reject changes and go back to the previous screen. 8.2.2.4.
Page 49
8.2.2.5. Edit Service This screen allows the editing of services. The following fields should be entered: • Service Name: type the name of the service Click on New Server Ports - this routes to the Edit Service Server Ports screen (see section 8.2.2.6) Press the OK button to apply changes and go back to the previous screen.
Page 50
• Range, then enter range values Destination Ports, then choose from the drop down list: • Any • Single, then enter port number • Range, then enter range values o UDP, then enter Source Ports, then choose from the drop down list: •...
Page 51
8.2.2.7. Edit Scheduler Rule This screen allows the editing of scheduler rules. The following fields should be entered: • Name: type the name of the scheduler ruled and click on New Time Segment Entry • Rule Activity settings: choose from the following radio buttons o Rule will be Active at the Scheduled Time o Rule will be Inactive at the Scheduled Time Click on New Time Segment Entry - this routes to the Edit Time Segment screen (see section...
Page 52
8.2.2.8. Edit Time Segment This screen allows the editing of time segments. The following fields should be entered: • Days of Week: check the days of the week when the rule should apply Click on New Hours Range Entry - this routes to the Edit Hour Range screen (see section 8.2.2.9) Press the OK button to apply changes and go back to the previous screen.
Press the OK button to apply changes and go back to the previous screen. Press the Cancel button to reject changes and go back to the previous screen. 8.2.3. Port Forwarding In its default state, GlobeSurfer® III blocks all external users from connecting to or communicating with your network.
Page 54
Additionally, port forwarding enables you to redirect traffic to a different port instead of the one to which it was designated. Let’s say, that you have a Web server running on your PC on port 8080 and you want to grant access to this server to anyone who accesses GlobeSurfer® III via HTTP.
Page 55
8.2.3.1. Add Port Forwarding Rule This screen allows the entry of new port forwarding rules. The following fields should be entered: • Local Host: IP address or the host name of the computer that will provide the service - the “server”. (Note that only one LAN computer can be assigned to provide a specific service or application): options available are: o User Defined –...
8.2.3.2. Edit Item This screen allows the editing of network object types. The following fields should be entered: • Network Object Type: choose from the drop down list: o IP Address, then enter IP address o Host Name, then enter Host Name Press the OK button to apply changes and go back to the previous screen.
Page 57
• You are not concerned with security and wish to expose one computer to all services without restriction. Warning: A DMZ host is not protected by the firewall and may be vulnerable to attack. Designating a DMZ host may also put other computers in the home network at risk. When designating a DMZ host, you must consider the security implications and protect it if necessary.
8.2.5. Port Triggering Port triggering can be used for dynamic port forwarding configuration. By setting port triggering rules, you can allow inbound traffic to arrive at a specific LAN host, using ports different than those used for the outbound traffic. This is called port triggering since the outbound traffic triggers to which ports inbound traffic is directed.
Page 59
o Show Basic Services – if this option is chosen a reduced list of options is displayed o Show All Services – a more comprehensive list services is displayed including L2TP – Layer 2 Tuneling Protocol TFTP – Trivial File Transfer Protocol AIM Talk DialPad.com RealAudio on Port 7070...
Page 60
This screen allows the editing of port triggering rules. The following fields should be entered: • Service Name: type the name of the service Click on New Trigger Ports - this routes to the Edit Service Server Ports screen (see section 8.2.2.6) Click on New Opened Ports - this routes to the Edit Service Opened Ports screen (see section 8.2.5.2)
• Range, then enter range values Destination Ports, then choose from the drop down list: • Any • Single, then enter port number • Range, then enter range values • Same as Initiating Ports o ICMP, then enter ICMP Message by choosing from the drop down list: •...
Page 62
accessed from computers in the home network. Moreover, restrictions can be applied to a comprehensive and automatically updated table of sites to which access is not recommended. This screen offers the facility to restrict access from the LAN to websites. Entries can be added, edited or deleted.
Page 63
8.2.6.1. Restricted Website This screen allows the entry of websites to be restricted. The following fields should be entered: • Restricted Website: enter the website address (IP address or URL) that you would like to make inaccessible from your home network (all web pages within the site will also be blocked and if the website address has multiple IP addresses, GlobeSurfer®...
be found and blocked by GlobeSurfer® III. 8.2.7. The NAT (Network Address Translation) screen allows you to hide the computers in your network so they cannot be found or directly accessed from outside your network. This screen offers the facility to translate network addresses. Entries can be added, edited or deleted.
Page 65
Press the Apply button to apply changes and stay on this screen. Press the Cancel button to reject changes and go back to the Home screen. Press the Resolve Now button to check the screen. Press the Refresh button to refresh the screen. 8.2.7.1.
Page 66
8.2.7.2. Add NAT/NAPT Rule This screen allows the entry of new NAT (Network Address Translation) /NAPT rules. The following fields should be entered: • Matching o Source Address: choose from the drop down list: User Defined – this routes to the Edit Network Object screen (see section 8.2.2.3) A specific address o Destination Address: choose from the drop down list:...
Page 67
• Ping – ICMP Echo Request • POP3 – Incoming Mail • SMTP – Outgoing Mail • SNMP – Simple Network Management Protocol • Telnet – Remote Connection • TFTP – Trivial File Transfer Protocol • Traceroute – Route Tracking Utility Show All Services –...
8.2.8. Connections This screen shows all connections currently active. The following fields are displayed: • Active Connections: number of active connections • Approximate Max. Connections: maximum number of possible connections (approximate) For each active connection the following fields are displayed: •...
8.2.9. Advanced Filtering Advanced filtering is designed to allow comprehensive control over the firewall's behaviour. You can define specific input and output rules, control the order of logically similar sets of rules and make a distinction between rules that apply to WAN and LAN devices. The screen is divided into three sections, one for Input Rule Sets, one for Output Rule Sets and one for ALG (Application Level Gateway) Rule Sets.
Page 70
• Input Rule Sets for configuring inbound traffic o Rule ID: the rule identifier o Source Address: source address of the packets sent to or received from the network object o Destination Address: destination address of the packets sent to or received from the network object –...
Page 71
Press the OK button to apply changes and go back to the Home screen. Press the Apply button to apply changes and stay on this screen. Press the Cancel button to reject changes and go back to the Home screen. Press the Resolve Now button to check the screen.
Page 72
section 8.2.2.3) A specific address o Protocol: traffic protocol: choose from the drop down list: User Defined – this routes to the Edit Service screen (see section 8.2.2.5) Show Basic Services – if this option is chosen a reduced list of options is displayed including: •...
Page 73
o Always – access is always controlled o User defined – this routes to the Edit Scheduler Rule screen (see section 8.2.2.7) Press the OK button to apply changes and go back to the Advanced Filtering screen. Press the Cancel button to reject changes and go back to the Advanced Filtering screen. 8.2.9.2.
Page 74
A specific address o Protocol: traffic protocol: choose from the drop down list: User Defined – this routes to the Edit Service screen (see section 8.2.2.5) Show Basic Services – if this option is chosen a reduced list of options is displayed including: •...
8.2.10. The Security Log displays a list of firewall-related events, including attempts to establish inbound and outbound connections, attempts to authenticate through an administrative interface (Web-based management or Telnet terminal), firewall configuration and system start- The following fields are displayed: •...
Page 76
The following are the available event types that can be recorded in the firewall log: Firewall internal - an accompanying explanation from the firewall internal mechanism will be added in case this event-type is recorded. Firewall status changed - the firewall changed status from up to down or the other way around, as specified in the event type description.
Page 77
PPP Discover - a PPP discover packet has been accepted. PPP Session - a PPP session packet has been accepted. 802.1Q - a 802.1Q (VLAN) packet has been accepted. Outbound Auth1X - an outbound Auth1X packet has been accepted. IP Version 6 - an IPv6 packet has been accepted. GlobeSurfer®...
Page 78
NAT Error: No free NAT IP - a message notifying that there is no free NAT IP, therefore NAT has failed. NAT Error: Conflict Mapping already exists - a message notifying that there is a conflict since the NAT mapping already exists, therefore NAT has failed. Malformed packet: Failed parsing - a packet has been blocked because it is malformed.
Page 79
• Blocked Events o All Blocked Connection Attempts - write a log message for each blocked attempt to establish an inbound connection to the home network or vice versa. You can enable logging of blocked packets of specific types by disabling this option, and enabling some of the more specific options below it.
8.3. VPN/Internet Protocol Security (IPSec) This screen allows the entry of Internet Protocol Security (IPSec) data. The following fields should be entered: • Block Unauthorised IP o Enabled: click this checkbox to block unauthorized attempts, and then enter o Maximum Number of Authentication Failures: number allowed before blocking o Block Period: time in seconds •...
8.3.1. Internet Protocol Security (IPSec) Settings This screen displays the IPSec public key and allows it to be recreated. Press the Recreate Key button to recreate the IPSec public key. Press the Close button to go back to the VPN/Internet Protocol Security (IPSec) screen. Press the Refresh button to refresh the screen.
Page 82
This screen allows the customization of the IPSec log, by allowing the user to choose what data is recorded. It is important to note the enabling many of these options may reduce GlobeSurfer® III’s performance. The following checkboxes can be clicked: •...
9. System This area enables the user to configure system settings and perform maintenance functions. From this screen you can click on the tabs at the top left hand side to route to the following detailed screens: • Overview - system overview including version, release date, platform, load average (see section 9.1) •...
9.2. System Settings Access GlobeSurfer® III's system settings by clicking the Settings tab in the System area. From this screen you can click on the tabs at the top right hand side to route to the following detailed screens: • Overview (see section 9.2.1) •...
Page 85
• Session Lifetime: controls the session lifetime (seconds) for logins to the management console. When the time has expired the login screen will appear again. Management Application Ports: this section allows you to configure the following management application ports: • Primary HTTP Management Port •...
Page 86
• Information Persistent Security Log: select this checkbox to keep the security log. • Outgoing Mail Server: • Server: enter the hostname of your outgoing (SMTP) server. • From Email Address: each email requires a from address and some outgoing servers refuse to forward email without a valid from address for anti-spam considerations.
Press the OK button to apply changes and go back to the Home screen. Press the Apply button to apply changes and stay on this screen. Press the Cancel button to reject changes and go back to the Home screen. 9.2.2.
Page 88
timeserver address by clicking the New Entry link at the bottom of the section. • Press the Sync Now button to synchronise the time. • Status: shows the date and time when the time was last updated. • Click on the edit icon in the Time Server table to modify an entry, or click on the New Entry hyperlink or the add icon to add an entry.
9.2.2.2. Clock Set To access the Clock Set screen, click the Clock Set button on Date and Time screen in the System area. To set the clock enter the following: • Local Date: choose the current month, day and year from the drop down lists. •...
• User Name: the name the remote user will use to access your local network • Permissions: the remote user’s privileges on your local network • Action: add, modify or delete For each group the following data is displayed: • Name •...
Page 91
General: • Full Name: the remote user’s full name • User Name: the name the remote user will use to access your local network • New Password: type a new password for the remote user. If you do not want to assign a password to the remote user leave this field empty.
9.3.2. Group Settings To access the Group Settings screen, click the New Group hyperlink from the Users screen in the System area. To configure group settings enter the following: General: • Name: group name • Description: group description Group Members: •...
Page 93
This section describes the different network connections available with GlobeSurfer® III in their order of appearance in the Network Connections screen, as well as the connection types that you can create using the Connection Wizard. GlobeSurfer® III's default network connections are: •...
• Layer 2 Tunneling Protocol over Internet Protocol Security • Layer 2 Tunneling Protocol Server • Internet Protocol Security • Internet Protocol Security Server • Internet Protocol over Internet Protocol • General Routing Encapsulation 9.4.1. Connection Wizard The logical network connections can be easily created using the Connection Wizard. This wizard is consists of a series of web-based management screens, intuitively structured to gather all the information needed to create a logical connection.
Page 95
VPN Client or Point-To-Point: selecting this option will take you to the VPN Client or Point-To-Point screen. From here you can choose one of the following protocols to connect to a remote VPN server: • Point-to-Point Tunneling Protocol Virtual Private Network (PPTP VPN): enable the secure transfer of data to another location over the Internet, using name/password authentication •...
Page 96
From here you can choose one of the following VPN protocols to allow a remote host to connect to GlobeSurfer® III: • Point-to-Point Tunneling Protocol Server (PPTP Server): enable Virtual Private Network (VPN) connections to your home network from other locations •...
encryption and digital certificates and user name/password authentication • Layer 2 Tunneling Protocol Server (L2TP Server): enable Virtual Private Network (VPN) connections to your home network from other locations • Internet Protocol Security (IPSec): enable secure transfer of data to another location over the Internet, using private and public keys for encryption and digital certificates or shared secret for authentication •...
Page 98
LAN devices formerly constituting the bridge as DHCP clients, with the exact DHCP client configuration. To configure an existing bridge or create a new one, perform the following steps: • Click the New Connection hyperlink in the Network Connections screen. The Connection Wizard screen will appear.
Page 99
Important notes: • The same connections cannot be shared by two bridges. • A bridge cannot be bridged. • Bridged connections will lose their IP settings. Click Next. The Connection Summary screen will appear, corresponding to your changes. Check the Edit the Newly Created Connection check box if you wish to be routed to the new connection's configuration screen after clicking Finish.
Page 100
9.4.2.1. General From the Network Connections screen, if you click on a LAN Bridge connection, you will be routed to the LAN Bridge Properties screen. From this screen you can click on the tabs at the top left hand side to route to the following detailed screens: •...
Page 101
9.4.2.2. Settings The top part of the configuration window displays general communication parameters. It is not recommended to change the default values in this screen unless you are familiar with the networking concepts they represent. Since your gateway is configured to operate with the default values, no parameter modification is necessary.
Page 102
recommended size is 1492. You should leave this value in the 1200 to 1500 range. Internet Protocol - please note that according to the selection you make in the Internet Protocol drop down list, the screen will refresh and display relevant configuration settings. •...
Page 103
• New IP Address hyperlink: this will appear on the screen if DHCP Relay has been chosen. Press the OK button to apply changes and go back to the previous screen. Press the Apply button to apply changes and stay on this screen. Press the Cancel button to reject changes and go back to the previous screen.
Page 104
neighboring destinations. Device Metric The device metric is a value used by the gateway to determine whether one route is superior to another, considering parameters such as bandwidth, delay, and more. Default Route Select this check box to define this device as the default route. Multicast - IGMP Proxy Internal IGMP proxy enables the system to issue IGMP host messages on behalf of hosts that the system discovered through standard IGMP interfaces.
9.4.2.5. Advanced Your gateway's firewall helps protect your computer by preventing unauthorized users from gaining access to it through a network such as the Internet. The firewall can be activated per network connection. To enable the firewall on this network connection, select the Enabled check box. You can add alias names (additional IP addresses) to the gateway by clicking the New IP Address link.
Page 106
9.4.3.1. General 9.4.3.2. Settings The top part of the configuration window displays general communication parameters. It is recommended not to change the default values in this screen unless you are familiar with the networking concepts they represent. Since your gateway is configured to operate with the default values, no parameter modification is necessary.
select the best MTU for your Internet connection, select Automatic (default setting). 9.4.3.3. Advanced Your gateway's firewall helps protect your computer by preventing unauthorized users from gaining access to it through a network such as the Internet. The firewall can be activated per network connection.
Page 108
9.4.4.1. General 9.4.4.2. Settings The top part of the configuration window displays general communication parameters. It is recommended not to change the default values in this screen unless you are familiar with the networking concepts they represent. Since your gateway is configured to operate with the default values, no parameter modification is necessary.
Page 109
9.4.4.3. Wireless The wireless access point settings are: SSID The SSID is the network name shared among all points in a wireless network. The SSID must be identical for all points in the wireless network. It is case-sensitive and must not exceed 32 characters (use any of the characters on the keyboard). Make sure this setting is the same for all points in your wireless network.
Page 110
Protection Mode decreases performance. Leave this feature disabled unless you encounter severe communication difficulties between the gateway and Wireless-G products. CTS Protection Type CTS Protection Type defines if the CTS Protection Mode defined above should use CTS only or both RTS/CTS. Beacon Interval A beacon is a packet broadcast by GlobeSurfer®...
Page 111
Encryption Algorithm The encryption algorithm used for WPA2 is the Advanced Encryption Standard (AES). Group Key Update Interval Defines the time interval in seconds for updating a group key. • WPA and WPA2 Mixed Mode – a mixed data encryption mode. Authentication Method Select the authentication method you would like to use.
Page 112
1 In the Network Authentication combo box, select “Shared”. 2 In the Data Encryption combo box, select “WEP”. 3 Enter your encryption key in both the Network key and the Confirm network key fields. • Non-802.1x WEP - a data encryption method utilizing a statically-defined key for wireless clients that do not use 802.1x for authentication but WEP for encryption.
Page 113
Obtain Address Automatically Select Obtain Address Automatically if you require that this connection will try to obtain its IP address from a DHCP server. Use the Following IP Address The LAN connection is usually configured using a permanent (static) IP address.
1 Specify the IP address of the DHCP server. 2 Click OK to save the settings. • Disabled Select Disabled from the combo-box if you would like to statically assign IP addresses to your network computers. You can choose to setup your gateway to use static or dynamic routing. Dynamic routing automatically adjusts how packets travel on the network, whereas static routing specifies a fixed routing path to neighboring destinations.
Page 115
the GSM and UMTS mobile telecommunications standards. The WAN Cellular Properties screen displays a summary of the connection properties. 9.4.5.1. General 9.4.5.2. Settings GlobeSurfer® III TECHNICAL REFERENCE MANUAL Page 115 of 184...
Page 116
The top part of the configuration window displays general communication parameters. It is recommended not to change the default values in this screen unless you are familiar with the networking concepts they represent. Since your gateway is configured to operate with the default values, no parameter modification is necessary.
Page 117
9.4.5.3. Routing You can choose to setup your gateway to use static or dynamic routing. Dynamic routing automatically adjusts how packets travel on the network, whereas static routing specifies a fixed routing path to neighboring destinations. Routing Mode When Advanced routing is selected, select one of the following Routing modes: Route Use route mode if you want your GlobeSurfer®...
Routing Table Allows you to add or modify routes when this device is active. Use the 'New Route' button to add a route or edit existing routes. 9.4.5.4. Advanced Your gateway's firewall helps protect your computer by preventing unauthorized users from gaining access to it through a network such as the Internet.
Page 119
screen. After the connection is established, its status will change to Connected: GlobeSurfer® III TECHNICAL REFERENCE MANUAL Page 119 of 184...
Page 120
An icon will appear in the notification area, announcing the successful initiation of the wireless connection. You can now use GlobeSurfer® III's wireless network from the configured PC. However, so can any other user with a wireless PC, which happens to be in your network's radio range. Such a user has access to any disk shares available in your network.
9.5. Monitor Access GlobeSurfer® III's monitoring settings by clicking the Monitor tab in the System area. From this screen you can click on the tabs at the top right hand side to route to the following detailed screens: • Network (see section 9.5.1) •...
Click on the LAN Wireless 802.1g Access Point hyperlink to be routed to the LAN Wireless 802.11g Access Point Properties screen in the Network Connections tab in the System area (see section 9.4.4) Click on the WAN Cellular hyperlink to be routed to the WAN Cellular Properties screen in the Network Connections tab in the System area (see section 9.4.5) Click on the IP Address Distribution hyperlink to be routed to the IP Address Distribution screen in the Network Connections tab in the Services (see section 8.6.2)
Press the Refresh button to refresh the screen manually. 9.5.3. System Log To access the System Log screen, click the Log tab at the top right hand side of the Monitor screen in the System area. This screen displays the system log. Filters on the log are displayed and can be added, modified and deleted.
Press the Close button to go to the Home screen. Press the Clear Log button to delete all the log entries. Press the Download log button to save the log to an Excel spreadsheet. Press the Refresh button to update the data. 9.6.
Page 125
• Gateway: the IP address of the GlobeSurfer® III. • Netmask: the network mask is used in conjunction with the destination to determine when a route is used. • Metric: a measurement of the preference of a route. Typically, the lowest metric is the most preferred route.
Page 126
server, it will add a routing entry for the IP address of the reply through the device from which it arrived. This means that future packets from this IP address will be routed through the device from which the reply arrived. Select the checkbox to enable domain routing. Press the OK button to apply changes and go back to the previous screen.
9.6.2. BGP and OSPF To access the BGP and OSPF screen, click the BGP and OSPF tab at the top right hand side of the Routing screen in the System area. The following data can be modified: • Border Gateway Protocol (BGP): select this checkbox to enable BGP, then enter: •...
9.6.3. PPPoE Relay To access the PPPoE screen, click the PPPoE tab at the top right hand side of the Routing screen in the System area. The following data can be modified: • Point-to-Point Protocol over Ethernet (PPPoE): select this checkbox to enable PPPoE. This is a specification for connecting users on an Ethernet network to the Internet by using a broadband connection (typically through a DSL modem).
The following data can be modified: • Allow Other Network Users to Control GlobeSurfer® III’s Network Features: select this checkbox to enable the UPnP feature. This will enable you to define UPnP services on any LAN host. • Enable Automatic Cleanup of Old Unused UPnP Services: select this checkbox to enable automatic cleanup of invalid rules.
Page 130
SNMP enables network management systems to remotely configure and monitor GlobeSurfer® III. Your Internet service provider (ISP) may use SNMP in order to identify and resolve technical problems. Your ISP should provide technical information regarding the properties of GlobeSurfer® III’s SNMP agent. The following SNMP parameters can be modified, as provided by your Internet service provider: •...
9.7.3. Remote Administration To access the Remote Administration screen, click the Remote Administration tab at the top right hand side of the Management screen in the System area. It is possible to access and control GlobeSurfer® III not only from within the home network, but also from the Internet.
Page 132
The following data can be modified: • Allow Incoming WAN Access to Web-Management: used to obtain access to the Web-based Management and gain access to all system settings and parameters (using a browser). Both secure (HTTPS) and non-secure (HTTP) access is available. Select the checkboxes required: •...
Press the OK button to apply changes and go back to the previous screen. Press the Apply button to apply changes and stay on this screen. Press the Cancel button to reject changes and go back to the previous screen. 9.8.
Click on the Upgrade hyperlink in the top right hand corner to upgrade. This routes you to the Firmware upgrade screen in the Maintenance tab in the System area (see section 9.8.5). Press the Close button to go back to the Home screen. 9.8.2.
Press Browse to locate the configuration file. Press the OK button to begin the configuration file uploading process. Press the Cancel button to reject changes and go to the Home screen. 9.8.3. Reboot To access the Reboot screen, click the Reboot tab at the top right hand side of the Maintenance screen in the System area.
You may sometimes wish to restore GlobeSurfer® III’s factory default settings This may happen, for example, when you wish to build a new network from the beginning, or when you cannot recall changes made to the network and wish to go back to the default configuration. Note: All web-based management settings and parameters, not only those in the Advanced section, will be restored to their default values.
have previously downloaded from the Internet or received on CD. Note: You can only use files with an rmt extension when performing the firmware upgrade procedure. Enter the path of the software image file, or press the Browse button to browse for the firmware upgrade file on your PC.
number of packets transmitted and received, round-trip time and success status. The following data can be modified: • Ping (ICMP Echo): this can be used to diagnose network connectivity: • Destination: enter the IP address or URL to be tested •...
Page 139
The Protocols feature incorporates a list of preset and user-defined applications and common port settings. You can use protocols in various security features such as Access Control and Port Forwarding. You may add new protocols to support new applications or edit existing ones according to your needs. For each protocol the following data is displayed: •...
Page 140
Enter the following data: • Service Name: name of the service • Service Description: description of the service For each server port the following data is displayed: • Protocol • Server Ports • Action: add, modify or delete For each opened port the following data is displayed: •...
Page 141
You may choose any of the protocols available in the drop down list, or add a new one by selecting Other. When selecting a protocol from the drop down list, the screen will refresh, presenting the appropriate fields to enter for that protocol. Select a protocol and enter the relevant information. The following fields should be entered: •...
Page 142
• Redirect for Host • Echo Request • Other • GRE • ESP • AH • Other, then enter Protocol Number Press the OK button to apply changes and go back to the previous screen. Press the Cancel button to reject changes and go back to the previous screen. You may choose any of the protocols available in the drop down list, or add a new one by selecting Other.
Destination Ports, then choose from the drop down list: • Any • Single, then enter port number • Range, then enter range values • Same as Initiating Ports • ICMP, then enter ICMP Message by choosing from the drop down list: •...
Page 144
MAC address, IP address and host name. Defining such a group can assist when configuring system rules. For example, network objects can be used when configuring GlobeSurfer® III's security filtering settings such as IP address filtering, host name filtering or MAC address filtering. You can use network objects in order to apply security rules based on host names instead of IP addresses.
Page 145
You may choose any of the object types available in the drop down list. When selecting an object type from the drop down list, the screen will refresh, presenting the appropriate fields to enter for that object type. Select an object type and enter the relevant information. The source address should be entered in one of the following: •...
9.9.3. Scheduler Rules To access the Scheduler Rules screen, click the Scheduler Rules tab at the top right hand side of the Objects and Rules screen in the System area. Scheduler rules are used for limiting the activation of settings, such as firewall rules, to specific time periods, specified in days of the week, and hours.
Page 147
Enter the following data: • Name: name for the rule • Rule Activity settings: choose from the following radio buttons to specify if the rule will be active/inactive during the designated time period: • Rule will be Active at the Scheduled Time •...
Click on the New Hours Range hyperlink or the add icon to add an entry. You will be routed to the Edit Hour Range screen (see below). Press the OK button to apply changes and go back to the previous screen. Press the Cancel button to reject changes and go back to the previous screen.
Page 149
GlobeSurfer® III makes use of public-key cryptography to encrypt and authenticate keys for the encryption of Wireless and VPN data communication, the Web Based Management (WBM) utility, and secured telnet. 9.9.4.2. Digital Certificates When working with public-key cryptography, you should be careful and make sure that you are using the correct person’s public key.
Page 150
Organization and Country.) • The certificate’s validity period: the certificate’s start date/time and expiration date/time - indicates when the certificate will expire. • The unique name of the certificate issuer: the unique name of the entity that signed the certificate. This is normally a CA. Using the certificate implies trusting the entity that signed this certificate.
Page 151
taped to it. It has your name and some information about you on it, plus the signature of the person who issued it to you. Click the Certificates tab in the top right hand corner of the Objects and Rules screen in the System area.
Page 152
After a short while, press the Refresh button, until the Save Certificate Request screen appears. Click the Save Certificate Request button and save the request to a file. Click the Close button. The main GlobeSurfer® III’s Local screen will reappear, listing your certificate as Unsigned.
Page 153
You can click the Save icon under the Action column, and then Open in the dialogue box to view the Certificate window (Windows only) box to save the certificate to a file. You can also click the Edit icon under the Action column to view the Certificate Details screen. GlobeSurfer®...
Page 154
9.9.4.5. Creating a Self-Signed Certificate A default self-signed certificate is included in GlobeSurfer® III, in order to enable certificate demanding services such as HTTPS. Note that if deleted, this certificate is restored when GlobeSurfer® III's Restore Factory Settings operation is run (see section 9.8.4). To create a self-signed certificate, click the Certificates tab in the top right hand corner of the Objects and Rules screen in the System area.
Page 155
Enter the following certification request parameters: • Certificate Name • Subject • Organization • State • Country Click the Generate button. A screen will appear stating that the certification request is being generated. After a short while, press the Refresh button, until the Certificate Details screen appears. GlobeSurfer®...
Page 156
Click the OK. The main GlobeSurfer® III’s Local screen will reappear, displaying the certificate name and issuer. 9.9.4.6. Loading a PKCS#12 Format Certificate You can also load certificates in PKCS#12 format (usually stored in .p12 files) to GlobeSurfer® III’s certificate store. You must first obtain the .p12 file, containing the private and public keys and optional CA certificates.
Page 157
Click the Upload Certificate link. The Load GlobeSurfer® III’s Local Certificate screen will appear. Use the Browse button to browse to the .p12 file. If the private key is encrypted using a password, type it in the password entry (otherwise leave the entry empty) and press Load to load the certificate. The GlobeSurfer®...
10. Shortcuts This page displays icon shortcuts in alphabetical order for many of the GlobeSurfer® III functions to enable quick and easy access to all areas. Click on the shortcut you require, and you will be routed immediately to the correct page. Shortcuts available are: •...
Page 159
• Diagnostics • File Server • Firewall • Firmware Upgrade • IP Address Distribution • IPSec • L2TP Server • Network Connections • Network Monitor • Network Objects • PPPoE Relay • PPTP Server • Personal Domain Name (Dynamic DNS) •...
11. Telephone GlobeSurfer® III is equipped with a telephony connector and can replace a regular fixed line service (POTS). In order to setup fixed line telephony to make phone calls through GlobeSurfer® III, connect GlobeSurfer® III to the first telephony plug. Note that you should configure your country in the GlobeSurfer®...
11.3. Outgoing calls The Outgoing calls screen shows calls, with Caller ID, that have been initiated from your telephones using GlobeSurfer® III including a time stamp and duration of the event. By clicking Clear Log you will erase the history of outgoing calls. 11.4.
• International Dialing Code: enter the prefix for the country • Dialling timeout (seconds): type in the number of seconds to set the delay between pressing a dial- key on phone and when the call is placed • Use # to end dialling: clicking this checkbox allows you to press the # key instead of waiting for the timeout •...
• All calls: the following options apply to all calls: o Activate: clicking this button will forward all calls to the number provided o Deactivate: clicking this button will stop the forwarding of all calls o Clear number: clicking this button will delete the number provided o Number: enter the phone number to forward all calls to o Status: displays the status of all call forwarding as Activated or Deactivated •...
Use the Call Waiting screen to make the following settings: • Call Waiting: displays the status of the call waiting functionality as Activated or Deactivated • Activate: clicking this button will activate call waiting • Deactivate: clicking this button will deactivate call waiting Press the Refresh button to refresh the screen.
required but it can be stored in the GlobeSurfer® III after the first use so that you don’t have to enter it more than once. These settings can be changed but note that you should disconnect before doing any changes to the SIM setup. From this screen you can click on the tabs at the top right hand side to route to the following detailed screens: •...
11.8.2. SIM PIN enable Use the SIM PIN enable screen to make the following changes: • PIN code: enter the PIN code you wish to use • PIN enabled: clicking this checkbox enables the PIN on your SIM card – to disable the PIN, de-select the checkbox Press the OK button to apply changes and go back to the previous screen.
GlobeSurfer® III+ TECHNICAL REFERENCE MANUAL In case the GlobeSurfer® III is locked to a specific ISP, it can be unlocked with a code that you should be able to get from your ISP. Normally there are certain conditions that must be fulfilled to be able to unlock the device.
GlobeSurfer® III+ TECHNICAL REFERENCE MANUAL 12.1. SMS Create Creating and sending SMS text messages: • Select the SMS Create tab. • Type your message text in the SMS message field. • The Characters left field shows how much space is left. •...
GlobeSurfer® III+ TECHNICAL REFERENCE MANUAL 12.2. Inbox Handling SMS text messages in the Inbox: • Select the Inbox tab to display the messages, with unread message in bold. • Click the SMS that you want to read. The message text is shown. •...
GlobeSurfer® III+ TECHNICAL REFERENCE MANUAL 12.3. Outbox After a SMS text message has been sent from your GlobeSurfer® III it will be stored temporarily in the Outbox folder until it is sent. 12.4. Sent After a SMS text message has been sent from your GlobeSurfer® III it will be stored in the Sent folder. From here it is possible to open any sent message and choose to delete, forward or save it to the archive (see section 12.7).
GlobeSurfer® III+ TECHNICAL REFERENCE MANUAL 12.6. Templates From the SMS create tab it is possible to choose to save a text message as a template instead of sending it directly. When a message is saved as a template, it can be loaded from the Templates folder. This is convenient when SMS messages are often sent to the same recipient or with similar content.
GlobeSurfer® III+ TECHNICAL REFERENCE MANUAL 12.9. Settings On the Settings tab it is possible to define the SMSC number which is the number to the Short Message Service Centre that will be used for sending SMS messages from your GlobeSurfer® III unit. This number is usually already filled in by default, but if necessary you can use the Settings tab to change it.
GlobeSurfer® III+ TECHNICAL REFERENCE MANUAL 2 List of Acronyms ALG Application-Level Gateway API Application Programming Interface CPE Customer Premise Equipment DHCP Dynamic Host Configuration Protocol DMZ Demilitarized Zone DNS Domain Name System DOCSIS Data Over Cable Service Interface Specification DSL Digital Subscriber Line FTP File Transfer Protocol HomePNA Home Phoneline Network Alliance HTTP HyperText Transport Protocol...
Page 174
GlobeSurfer® III+ TECHNICAL REFERENCE MANUAL PDA Personal Digital Assistant POP3 Post Office Protocol 3 POTS Plain Old Telephony Service PPP Point-to-Point Protocol PPTP Point-to-Point Tunnelling Protocol RG Residential Gateway RIP Routing Information Protocol SNMP Simple Network Management Protocol SPI Stateful Packet Inspection TCP Transmission Control Protocol TFTP Trivial File Transfer Protocol UDP User Datagram Protocol...
GlobeSurfer® III+ TECHNICAL REFERENCE MANUAL 3 Glossary 100Base-T Also known as Fast Ethernet, an Ethernet cable standard with a data transfer rate of up to 100 Mbps. 10Base-T An older Ethernet cable standard with a data transfer rate of up to 10 Mbps. 802.11, 802.11b A family of IEEE (Institute of Electrical and Electronics Engineers) defined specifications for wireless networks.
Page 176
GlobeSurfer® III+ TECHNICAL REFERENCE MANUAL infrastructure, and DSL modems, which rely on telephone lines operating at DSL speeds. Broadcast Broadcasting sends a message to everyone on the network whereas multicasting sends a message to a select list of recipients. Bus A set of hardware lines used for data transfer among the components of a computer system. A bus essentially allows different parts of the system to share data.
Page 177
GlobeSurfer® III+ TECHNICAL REFERENCE MANUAL DMZ Acronym for ‘demilitarized zone’. A collection of devices and subnets placed between a private network and the Internet to help protect the private network from unauthorized Internet users. DNS Acronym for ‘Domain Name System’. A data query service chiefly used on the Internet for translating host names into Internet addresses.
Page 178
GlobeSurfer® III+ TECHNICAL REFERENCE MANUAL Ethernet A networking standard that uses cables to provide network access. Ethernet is the most widely-installed technology to connect computers together. Ethernet cable A type of cable that facilitates network communications. An Ethernet cable comes in a couple of flavors.
Page 179
GlobeSurfer® III+ TECHNICAL REFERENCE MANUAL Hub A device that has multiple ports and that serves as a central connection point for communication lines from all devices on a network. When data arrives at one port, it is copied to the other ports. IEEE Acronym for ‘Institute of Electrical and Electronics Engineers’.
Page 180
GlobeSurfer® III+ TECHNICAL REFERENCE MANUAL LAN Acronym for ‘local area network’. A group of computers and other devices dispersed over a relatively limited area (for example, a building) and connected by a communications link that enables any device to interact with any other on the network. MAC address Abbreviation for ‘media access control’...
Page 181
GlobeSurfer® III+ TECHNICAL REFERENCE MANUAL PAP Password Authentication Protocol, the most basic form of authentication, in which a user’s name and password are transmitted over a network and compared to a table of name-password pairs. Typically, the passwords stored in the table are encrypted. The Basic Authentication feature built into the HTTP protocol uses PAP.
Page 182
GlobeSurfer® III+ TECHNICAL REFERENCE MANUAL Profile A computer-based record that contains an individual network’s software settings and identification information. Protocol A set of rules that computers use to communicate with each other over a network. Resource Any type of hardware (such as a modem or printer) or software (such as an application, file, or game) that users can share on a network.
Page 183
GlobeSurfer® III+ TECHNICAL REFERENCE MANUAL building, or on the same local area network (LAN). Having an organization’s network divided into sub- nets allows it to be connected to the Internet with a single shared network address. Similar in form to an IP address and typically provided by an ISP.
Page 184
GlobeSurfer® III+ TECHNICAL REFERENCE MANUAL WAN Acronym for ‘wide area network’. A geographically widespread network that might include many linked local area networks. Wi-Fi A term commonly used to mean the wireless 802.11b standard. Wireless Refers to technology that connects computers without the use of wires and cables. Wireless devices use radio transmission to connect computers on a network to one another.
Need help?
Do you have a question about the GlobeSurfer III and is the answer not in the manual?
Questions and answers