Introduction Services Services > QoS > Basic Registration & Login Services > QoS > Advanced Services > PCI DSS Home Services > Mako Guardian Anatomy of the Left Main Menu Services > Mako Failover Status Icons Services > Dynamic DNS 'Click' Convention Configure > Location Anatomy of the Header Bar Configure >...
Page 4
Should Someone Else Be Reading This? What's wrong with this IP address: 202.12.324.4? Page 4 of 45 Central Management System...
This manual will complement your chosen Mako appliance, also known as the Customer Premise Equipment (CPE). Your CPE is managed remotely by Mako via a web server, using your standard Internet connection and the Central Management System (CMS). The CMS uses a web browser for personal configuration and reporting.
1.0.2 Manual Conventions Main Tab > Sub-tab > ... > ... > Function. For navigation, we use this format: This is shorthand, asking you to click on the first level menu level and click on successive levels until you find the appropriate page.
Registration & Login When your account is set up, the CMS emails you your accounts details, along with a link to log you into your network. The CMS has been tested against several versions of the popular browser software products. It's likely that, due to different browser products, versions and settings, your view of the interface may vary slightly from the ones illustrated in this guide.
Page 8
2.0.2 Login n Click the link, or open your Web browser and navigate to your Mako Management CMS. n Click the Customer Login button, top right of the window. If you're operating in a PCI environment you will need to provide the reCAPTCHA login details.
Home The Home window is the starting point for administration and monitoring of your CPEs and users. Anatomy of the Left Main Menu n Reveal triangles ( ) show more options are within that menu. Dark triangles indicate collapsed options, coloured triangles indicate revealed options.
Anatomy of the Header Bar The header gives you an immediate overview of your account, access history and general info. The top line gives you the user access details, time and company you're operating under for this session. Also here is: "Head Office"...
Selection The Selection menu allows you to select an individual CPE in your network and interrogate it. Large sections of the CMS are inoperable if you don't have an appliance selected. Let's get a list of CPEs to choose from. Search Selection > ...
The Report section is covered in a different manual. In your use of the Mako CMS, you'll find other ways to select a CPE. Always remember: The CPE you are working with is listed in the Header bar of each page.
Page 13
Be aware that re-configuring these functions can disable critical operations of your Mako appliance — care should be taken to ensure that configuration changes do not compromise your office network security or its access to the Internet. If a configuration option is missing, this will be highlighted by ...
This should be provided by your reseller and rarely needs to change. When installing new CPEs on the network, this hostname stays the same. Mako WAN IP: With an Ethernet model configuration, this IP address is the external address allocated to the CPE.
Page 15
Configure DNS: Check to change your DNS addresses. Primary DNS Server: Enter the address of your primary DNS server. Secondary DNS Server: Enter the address of your secondary DNS server. 5.1.5 Billing Settings The following options concern your billing cycle and monthly traffic thresholds. This facility is not available where your ISP Connection Plan does not impose a traffic- charging threshold.
Page 16
Failover is a network 'safety net' . If your main network connection (PPTP, Ethernet, etc) is interrupted, cellular-capable Mako systems are able to switch to a cellular network for continued operation. Naturally, this option is only available if you're using cellular-capable CPEs. If cellular failover is required, ensure that the CPE has an active SIM card inserted into the slot and is within your provider's coverage area.
Page 17
5.3.1 Extraordinary Usage Alerts Over time, the Mako System builds a profile for the usual traffic patterns of your Internet connection. Extraordinary usage is outside the norm for your CPE's internet connection. You can set threshold alerts to trigger when the volume of extraordinary traffic is attained.
Page 18
5.3.4 Environmental Alerts Your CPE monitors its temperature, which can be affected by an external heating or cooling source. Alert when temperature over: Set your upper level operating temperature. Fan speed alert: High-capacity models contain an internal fan. Check if internal cooling fans require monitoring.
Page 19
The default is Deny and should only be enabled for troubleshooting. Mako Ethernet IP address: The selected LAN port must be given a fixed IP address on your network. This is set to a default value (of 192.168.1.254 for your first network, 192.168.2.254 for your second, etc.).
IP allocation. The IP range will be limited by the defined subnet mask. The range is also dependent on the defined Mako Ethernet IP address, if entered incorrectly or the wrong range is used, this will create an error alert.
VLAN Trunk can only be assigned to one LAN port. Regular LANs with a VLAN ID set only have the VLAN ID tagged when going through the VLAN Trunk. That is, they are untagged on their normal ports. DHCP Attributes: If DHCP has been enabled for this LAN port.
Page 22
Ports and routing options are different from model to model. The following one is designed to operate as a 1-4 port switch with up to 4 separate networks. In this CPE the 4-port switch configuration is the default. VLAN Setup Configure >...
Page 23
5.8.1 Basic Wireless LAN Configuration Setting up a Wireless LAN is similar to setting up a physical LAN. Some options may or may not be available to your CPE depending on make, permissions or pre- configured function. Some options aren't explained, as they're covered in the glossary. Wireless Network Name (SSID): The name of the Wireless LAN.
Plug the CPE into the network port and power it up. The Mako system will automatically identify this device and allocate the next available IP address to it. In the Name column it will be referred to as "allocated by system."...
Page 25
Internet. You can call out, but they can't call in. This means that users on your Mako-protected networks can send and receive their email, browse the World Wide Web, and access all other Internet-based services, while the firewall ensures that none of their PCs are visible to the Internet.
Page 26
The default setting is to Deny any communication between them. The Intranet Firewall rules allow or deny traffic between 2 or more Mako-protected networks. On the Intranet page, both Inbound and Outbound traffic are considered the same.
Page 27
If your ISP provides you with multiple public IP addresses you may specify a public IP address that the inbound rule refers to. This is useful if you want to have multiple rules to the same port on different internal PCs. If your ISP doesn't provide you with multiple public IP addresses you will not see the Target IP address drop-down.
Page 28
The optional Comments field can be used to label or describe the rule. Here, one of the rules operating on the firewall is shown as having been created on the Inbound Rules > Advanced page. 5.13.6 VPN Specifics Before you can add rules to a Virtual Private Network firewall, you must create the VPN in the separate VPN Section.
Page 29
Manage Access VPN > ... > If you have 2 or more CPEs, use this window to set up VPNs between each pair of Mako-protected networks. The CPEs have to be online and operating and configured with a WAN address.
Page 30
Send Invitation VPN > ... > Invitation > If you wish to have a Mako to Mako VPN between your CPE and a Mako that belongs to another company, you can do so with Mako VPN Invitations. To create a VPN between a CPE you administer and one you cannot, you need to know the email address of the other Mako's administrator.
Page 31
If the security of this network isn't as important to you, you can leave this field blank. Add, or Add and Create VPN when finished. If you click Add and Create VPN this will take you back to the Mako to Mako VPN page, and you can continue setting up the VPN.
Any user recorded in the subsequent Add User section can have their network access enabled and disabled as appropriate. We recommend that users are permitted access only while they need to use the office network. At other times, their access should be disabled. 6.6.1 Enable, Disable or Edit VPN Users icon (disabled) to enable a VPN user.
Page 33
Voice over IP traffic, by ensuring there is always bandwidth reserved for it, and that it has priority over less demanding services such as web browsing. The Mako default setting is recommended for most users. This setting allocates bandwidth reservations to the most common Internet applications and traffic types.
Ethernet interface for communication between the 2 devices. If you have Failover enabled, refer to the Mako Failover manual for details on using this add on. This can be found under the Help/Docs > Documentation page once logged into the CMS.
Page 35
Your reseller neither endorses nor guarantees the services provided by either of these parties. We provide the Dynamic DNS service as a convenience to the users of its products. Location Configure > The Location section allows you to update and view the non-technical details of your CPE. n Click Edit.
Page 36
Email Settings Configure > Access > The Email Settings page lets you choose which users receive email reports from the Mako System. n Select your report type. n Click on the icon to allow or deny this report respectively.
Page 37
Management The management section focuses on managing pre-existing or pre-configured Makos, users, companies, VPNs and systems, rather than setting up systems. Once set, your network administrators will manage the network through these pages. Home Management > The Management section is for administering User and Company information. By default, your own User and Company are selected and shown in the header section.
Page 38
Licences Management > Company > Manage [Your Company] > Resellers and high-level administrators create time-based permissions for users of a Mako system. This gives your system an ability to maintain current security checks. This page creates reports for the Company or users under the company's Mako system.
Page 39
Information: An overview of a user's current settings. Access Control: Password and governance controls over the user. You cannot change your own Access level, only the Users you have created. You may only grant other users access equal to or less than your own access. Change Password: Takes you to the Change Password page.
Page 40
Help > This page contains downloadable PDF documentation and product literature on nearly every aspect of the Mako System. Are You The Office Fire Hazard? In all country's flexible cable wiring codes, what color is NOT permitted for 'live' mains power?
If the password is exposed to a third party, your computer network is insecure and at risk. n You must follow the Forgot Password? link on the Mako CMS to create a new password for your account. A temporary access code is issued to your email address to confirm your request. You must contact your reseller if you have changed email addresses.
ISP Plan Request Select an ISP: Choose an ISP that you want modified from this list. Add an ISP Plan: Select a pre-existing plan from the drop down menu to base this new plan on, or click the New button and enter a new plan name in the Plan Name field.
The Unique Central Management System The Mako CMS is accessed via a secure website that users log into to manage their network(s). A user's login gives them access to all their CPEs around the world, providing a central place from which to manage their complete network.
You can link 2 Mako-protected networks together using the CMS in seconds, using only 3 mouse-clicks! Linking 3 or more Mako-protected networks is just as easy. The CMS allows this to happen without static IP Addresses. In the same way you can also allow specified users remote access to your Mako-protected networks with the Remote VPN feature –...
Page 45
You can be assured that your Mako appliance will continue to be current as long as it has a current licence. Diagnostics A 1.1 Mako Diagnostics gives support personnel the ability to remotely resolve network and connectivity issues without the need for onsite visits or technically literate users.
Glossary ADSL Asymmetric Digital Subscriber Line. A group of technologies used to transmit high speed (broadband) data across a non-digital telephone circuit, with the channel capacity towards the subscriber being several times greater than that from the subscriber. Typical bandwidths are in megabits per second. Browser A software application that displays HTML formatted text and facilitates access to websites.
Page 47
To sign up to one of these services, follow the instructions and documentation on the provider's website. You'll receive a username and password from your Dynamic DNS provider. Enter these in the appropriate section on the SecureME Networks Dynamic DNS screen. Once entered, each time your CPE changes its public IP address, it will update your Dynamic DNS provider.
Page 48
the information appear as though it originated from a trusted source. To resolve this problem, source routing is disabled by your firewall. File Transfer Protocol. This is a service for bulk data transfer over the Internet. Gateway A gateway is a network point that acts as an entrance to another network. On the Internet, a node or stopping point can be either a gateway node or a host (end-point) node.
belonging to a computer within its immediate neighbourhood or domain. That gateway then forwards the packet directly to the computer whose address is specified. IP Address In the most widely installed level of the Internet Protocol today (IPv4), an IP address is a 32-bit number that identifies each host on the Internet.
Page 50
Router A communications device connected between 2 (or more) different networks, which maps (routes/ directs) traffic between the IP addresses on each network. Service Services comprise 3 elements—a pair of communicating software applications; the definition of the data structures which the applications exchange; and the definition of the protocols by which the applications exchange data structures.
Page 51
A virtual private network (VPN) is a network that uses a public telecommunication infrastructure, such as the Internet, to provide remote offices or individual users with secure access to their network. A virtual private network can be contrasted with an expensive system of owned or leased lines that can only be used by one company.
Software ID Software version number, this is often useful to helpdesk staff. Failover Status Shows whether the failover is active or not. Last Mako Server The last time your CPE communicated with the CMS. Contacted Page 52 of 54 Central Management System...
Page 53
Last User Change The last user modification to your CPE's configuration. Firewall Status Shows whether the firewall is loaded or not. Mako Guardian Status Shows whether the Content Filter is active or not. Temperature Displays the internal temperature of the CPE.
Connectivity information The text for the connectivity information is colour coded, green for active (on) and red for disabled/ disconnected (off ). This applies to the ADSL, PPP and LAN information. ADSL Status If it is red then this indicates that the ADSL circuit is faulty or that the CPE is still booting.
(the “Warranty Period”). This warranty extends only to end-user and will not extend to, nor may it be assigned to, any subsequent user, Purchaser or user of a MAKO NETWORKS LTD.
Page 56
Support support@makonetworks.com Web site www.makonetworks.com...
Need help?
Do you have a question about the 6500 and is the answer not in the manual?
Questions and answers