Page 4
Cellular M2M Gateway 3.2.1.5 MAC Control ............................104 3.2.1.5.1 Configuration ..........................105 3.2.1.5.2 MAC Control Rule List ........................105 3.2.1.5.3 MAC Control Rule Configuration ....................106 3.2.1.6 Application Filters ..........................106 3.2.1.6.1 Configuration ..........................107 3.2.1.7 IPS ..............................107 3.2.1.8 Options ...............................108 3.2.2 QoS &...
Page 5
Cellular M2M Gateway 3.2.3.3.3 User Account List..........................132 3.2.3.3.4 User Account Configuration ......................132 3.2.3.3.5 L2TP Client ............................ 132 3.2.3.3.6 L2TP Client List & Status ........................ 132 3.2.3.3.7 L2TP Client Configuration ......................133 3.2.3.4 GRE ..............................134 3.2.3.4.1 GRE VPN Tunnel Scenario......................134 3.2.3.4.2 GRE Configuration .........................
Page 6
Cellular M2M Gateway Copyright The contents of this publication may not be reproduced in any part or as a whole, stored, transcribed in an information retrieval system, translated into any language, or transmitted in any form or by any means, mechanical, magnetic, electronic, optical, photocopying, manual, or otherwise, without the prior written permission.
Intranet, and all data are transmitted in a secure (256-bit AES encryption) link. To meet a variety of M2M application requirements, AMIT Cellular M2M Gateway products are based on modular design. A new functional module can replace current one to support new application in short time, such as for NFC or GPS applications.
Cellular M2M Gateway 1.2 Hardware Installation 1.2.1 WARNING Do not use the product in high humidity or high temperatures. Only use the power adapter that comes with the package. Using a different voltage rating power adaptor is dangerous and may damage the product. ...
Cellular M2M Gateway 1.2.3 Hardware Configuration Reset LED Indicators USB Port Button Cellular Auto MDI/MDIX RJ-45 Ports Console Cellular Antenna 4x FE LAN to connect local devices Port Antenna ※Reset Button The RESET button provides user with a quick and easy way to resort the default setting. Press the RESET button continuously for 6 seconds, and then release it.
Page 11
Cellular M2M Gateway 2.4G WiFi 2.4G WiFi Antenna Antenna Power Terminal Block IDG761-0P001 User Manual...
Cellular M2M Gateway 1.2.4 LED Indication LED Icon Indication LED Color Description Steady ON: Device is powered on by power Power Source 1 Green source 1 Power Source 2 Steady ON: Device is powered on by power Green source 2 Steady ON: Wireless radio is enabled WLAN (WiFi) Green...
Cellular M2M Gateway Chapter 2 Getting Started This chapter describes how to install and configure the hardware and how to use the setup wizard to configure the network with the web GUI of IDG761 series. 2.1 Hardware Installation 2.1.1 Mount the Unit The IDG761 series can be placed on a desktop, mounted on the wall, or mounted on a DIN-rail.
Cellular M2M Gateway 2.1.3 Connecting Power The IDG761 series can be powered by connecting a power source to the terminal block. It supports dual 9 to 48VDC power inputs . Following picture is the power terminal block pin assignments. Please check carefully and connect to the right power requirements and polarity.
Cellular M2M Gateway detect the transmission speed on the network and configure itself automatically. Connect the Ethernet cable to the RJ-45 ports of the device. Plug one end of an Ethernet cable into your computer’s network port and the other end into one of IDG761 series for LAN ports on the front panel.
Page 16
Cellular M2M Gateway A. Configure with the Network Setup Wizard Step 1 The network setup wizard will guide you to finish some basic settings, including login password, time zone, WAN interface, Ethernet LAN interface and WiFi LAN interface. Press “Next” to start the wizard. Step 2: Change Password Password Configuration: You can change the login password of Web UI here.
Page 17
Cellular M2M Gateway Step 4: WAN WAN Interface Configuration: Choose type of WAN connection. You can select Ethernet WAN if you want to connect to Internet through fixed line. Or select 3G/4G if you want to connect to Internet through 3G/4G network. A variety of WAN types are available for Ethernet WAN connection.
Page 18
Cellular M2M Gateway Press “Next” to continue. Step 4-4: Ethernet (PPTP) If choosing Ethernet->PPTP, you need to input required dial-up information that you get from ISP. This option is usually chosen when your ISP requests it. Press “Next” to continue. Step 4-5: Ethernet (L2TP) If choosing Ethernet->L2TP, you need to input required dial-up information that you...
Page 19
Cellular M2M Gateway Step 6: WiFi LAN WiFi Interface Configuration: Change the SSID, Channel Number, Authentication and Encryption Algorithm for first virtual AP of this gateway. You will see on your PC when doing wireless network scan. It’s strongly recommending you to add authentication and encryption in your wireless network to prevent any unknown WiFi clients and keep transferred data secured.
Page 20
Cellular M2M Gateway Step 2: VPN Type Select type of VPN connection you want to create. Here you can choose IPSec, PPTP, or L2TP. Press “Next” to continue. Step 2-1: IPSec If choosing IPSec, there are two options of tunnel scenario can be chosen. “Site to Site”...
Page 21
Cellular M2M Gateway Press “Next” to continue. If choosing PPTP Client, please input tunnel name, IP/FQDN of PPTP server, username/password, authentication, and MPPE options. Please make sure these settings are accepted by PPTP server. Otherwise, remote PPTP server will reject the connection. Press “Next”...
Cellular M2M Gateway If choosing L2TP Client, please input tunnel name, IP/FQDN of L2TP server, username/password, authentication, and MPPE options. Please make sure these settings are accepted by L2TP server. Otherwise, remote L2TP server will reject the connection. Press “Next” to continue. If choosing L2TP Server, please select options of authentication and MPPE.
Page 23
Cellular M2M Gateway A. Network Status In Network Status page, you can review lots information of network status, including a connection diagram, WAN IPv4 status, WAN IPv6 status, LAN status, and 3G/4G modem status. You can also check the device time at the bottom of this page. Connection Diagram 1.
Page 24
Cellular M2M Gateway WAN Interface IPv6 Network Status Display WAN type, IPv6 information, and connection status of multiple WAN interfaces in IPv6 networking. Press “Edit” button if you want to change settings. LAN Interface Status Display IPv4 and IPv6 information of local network. Press “Edit” button if you want to change settings.
Page 25
Cellular M2M Gateway Device Time Display current time information of device. B. WiFi Status WiFi Virtual AP List: In order to view the basic information of WiFi virtual APs, it will display operation band, virtual AP ID, WiFi activity, operation mode, SSID, channel, WiFi system, WiFi security approach and MAC address of all virtual APs on status page.
Page 26
Cellular M2M Gateway all client devices on status page. D. Firewall Status In Firewall Status page, you can review lots information of filter status, including Packet Filters, URL Blocking, Web Content Filters, MAC Control, Application Filters, IPS and other options of firewall. Packet Filters Display all detected contents of firing activated packet filter rules.
Page 27
Cellular M2M Gateway Display all activated rules of IPS. Options Display option settings of firewall. E. VPN Status In VPN Status page, you can review lots information of VPN status, including IPSec status, PPTP Server status, PPTP Client status, L2TP Server status and L2TP Client status. IPSec Status Display the status of all activated tunnels of IPSec.
Cellular M2M Gateway Chapter 3 Making Configurations Whenever you want to configure your network or this device, you can access the Configuration Menu by opening the web browser and typing in the IP Address of the device. The default IP Address is: 192.168.123.254. In the configuration section you may want to check the connection status of the device, to do Basic or Advanced Network setup or to check the system status.
Cellular M2M Gateway Note: You can see the first screen is located at Status >> Network Status after you logged in and the screen shows the Network Connection Status below. You can also check status of WiFi at WiFi Status page, connected clients at LAN Client List page, and other advanced function status at Firewall Status page and VPN Status page.
Cellular M2M Gateway 3.1.1 WAN Setup This device is equipped with three WAN Interfaces to support different WAN types of connection. You can configure one by one to get proper Internet connection setup. 3G/4G WAN: The gateway has one 3G/4G modem built-in, please plug in SIM card and follow UI setting to setup.
Cellular M2M Gateway 3.1.1.1 Physical Interface Click on the “Edit” button for each WAN interface and you can get the detail physical interface settings and then configure the settings as well. By default, the WAN-1 interface is forced to “Always-on” mode, and operates as the primary internet connection;...
Page 32
Cellular M2M Gateway (WAN-1), please choose “3G/4G” for configuring the embedded 3G/4G modem as primary WAN connection. Or you can select “USB 3G/4G” if you want to use attached 3G/LTE USB dongle as an Internet connection. Otherwise, you can choose “Ethernet” if you would like the RJ45 port to be the primary Internet connection.
Cellular M2M Gateway 3.1.1.2 Internet Setup There are three physical WAN interfaces that you can configure one by one to get proper Internet connection setup. They include the 3G/4G WAN, if the ISP is a mobile operator that can provide LTE, HSPA+, HSPA, WCDMA, EDGE, GPRS data services .
Page 34
Cellular M2M Gateway 1. WAN Type: Choose “3G/4G” from the drop list. 1. Preferred SIM Card: Choose “SIM-A”, “SIM-B”, “SIM-A First” or “SIM-B First” for 3G/4G connection. There are two SIM card slots on this gateway and with four kinds of SIM card usage scenarios, including "SIM-A", "SIM-B", “SIM-A First” and "SIM-B First“.
Page 35
Cellular M2M Gateway 1. Dial-up Profile: After you subscribe 3G/4G data service, your operator will provide some information for you to setup connection, such as APN, dialed number, account or password. If you know this information exactly, you can choose “Manual-configuration” option and type in that information by your own. Otherwise, you can select “Auto-detection”...
Page 36
Cellular M2M Gateway 2. MTU: MTU refers to Maximum Transmit Unit. Different WAN types of connection will have different value. You can leave it with 0 (Auto) if you are not sure about this setting. 3. NAT: By default, it is enabled. If you disable this option, there will be no NAT mechanism between LAN side and WAN side.
Cellular M2M Gateway 5. IGMP: Enable or disable multicast traffics from Internet. You may enable as auto mode or select by IGMP v1, IGMP v2, IGMP v3 or Auto. 3.1.1.2.2 Ethernet WAN Click on the “Edit” button for the Ethernet WAN interface and you can get the detail WAN settings and then configure the settings as well.
Page 38
Cellular M2M Gateway address of your PC to this field. Connection Control: Select your connection control scheme from the drop list: “Auto-reconnect (Always-on)”, “Dial-on-demand” or “Manually”. If selecting “Auto-reconnect (Always-on)”, this gateway will start to establish Internet connection automatically since it’s powered on. It’s recommended to choose this scheme if for mission critical applications to ensure Internet connection is available all the time.
Page 39
Cellular M2M Gateway Latency Threshold: Set acceptance of response time. This gateway will record this keep-alive check is failed if the response time of replied packet is longer than this setting. Fail Threshold: Times of failed checking. This WAN connection will be recognized as broken if the times of continuous failed keep-alive checking equals to this value.
Page 40
Cellular M2M Gateway mask, and gateway address which is provided by your ISP. Primary DNS/ Secondary DNS: Input the IP address of primary and secondary DNS server that is provided by your ISP. Secondary DNS can be ignored if only one DNS server is provided by your ISP. MTU: Most ISP offers MTU value to users.
Page 41
Cellular M2M Gateway auto mode or select by IGMP v1, IGMP v2, IGMP v3 or Auto. WAN IP Alias: In some cases, ISP will provide you another fixed IP address for management purpose. You can enter that IP address in this field. 3.1.1.2.2.3 PPP over Ethernet Select this option if your ISP requires you to use a PPPoE connection.
Page 42
Cellular M2M Gateway assigned to you. Please note the account and password is case sensitive. For security concern, the password you input won’t be displayed on web UI. Primary DNS/ Secondary DNS: In most cases, ISP will assign DNS server automatically after PPPoE connection is established.
Page 43
Cellular M2M Gateway increase when WAN bandwidth is fully occupied. To avoid keep-alive feature work abnormally, enable this option will stop sending keep-alive packets when there are continuous incoming and outgoing data packets passing through WAN connection. Check Interval: Indicate how often to send keep-alive packet. Check Timeout: Set allowance of time period to receive response of keep-alive packet.
Page 44
Cellular M2M Gateway WAN Type: Choose “PPTP” from the drop list. IP Mode: Please check the IP mode your ISP assigned, and select “Static IP Address” or “Dynamic IP Address” accordingly. If you select “Static IP Address” option, you have to specify additional “WAN IP Address”, “WAN Subnet Mask”, and “WAN Gateway”...
Page 45
Cellular M2M Gateway selecting “Auto-reconnect (Always-on)”, this gateway will start to establish Internet connection automatically since it’s powered on. It’s recommended to choose this scheme if for mission critical applications to ensure Internet connection is available all the time. If choosing “Dial-on-demand”, this gateway won’t start to establish Internet connection until local data is going to be sent to WAN side.
Page 46
Cellular M2M Gateway period, this gateway will record this keep alive is failed. Latency Threshold: Set acceptance of response time. This gateway will record this keep-alive check is failed if the response time of replied packet is longer than this setting. Fail Threshold: Times of failed checking.
Page 47
Cellular M2M Gateway WAN Type: Choose “L2TP” from the drop list. IP Mode: Please check the IP mode your ISP assigned, and select “Static IP Address” or “Dynamic IP Address” accordingly. If you select “Static IP Address” option, you have to specify additional “IP Address”, “Subnet Mask”, and “WAN Gateway IP”...
Page 48
Cellular M2M Gateway connection is available all the time. If choosing “Dial-on-demand”, this gateway won’t start to establish Internet connection until local data is going to be sent to WAN side. After that, this gateway will disconnect WAN connection if idle time reaches value of Maximum Idle Time. If choosing “Manually”, this gateway won’t start to establish WAN connection until you press “Connect”...
Cellular M2M Gateway longer than this setting. Fail Threshold: Times of failed checking. This WAN connection will be recognized as broken if the times of continuous failed keep-alive checking equals to this value. Target1/Target2: Set host that is used for keep alive checking. It can be DNS1, DNS2, default Gateway, or other host that you need to input IP address manually.
Page 50
Cellular M2M Gateway By Priority If you choose the “By Priority” strategy, you have to further specify the outbound traffic percentage for each WAN interface. The load balancing mechanism will follow these settings to allocate proper traffics for each WAN to access the internet. By User Policy If you choose the “By User Policy”...
Cellular M2M Gateway 1. Source IP Address: Enter the expected Source IP Address for the load balance policy. It can be “Any”, “Subnet”, “IP Range”, or “Single IP”. Just choose one type of the source IP address, and specify its value as well. If you don’t want to specify a certain source IP address for this policy, just leave it as “Any”.
Cellular M2M Gateway 3.1.2.1 Ethernet LAN Please follow the following instructions to do IPv4 Ethernet LAN Setup. IP Mode: LAN IP address of this gateway needs to be set manually. LAN IP Address: The local IP address of this device. The computer on your network must use the LAN IP address of this device as their Default Gateway.
Cellular M2M Gateway 3.1.2.2 VLAN This section provides a brief description of VLANs and explains how to create and modify virtual LANs which are more commonly known as VLANs. A VLAN is a logical network under a certain switch or router device to group lots of client hosts with a specific VLAN ID.
Page 54
Cellular M2M Gateway Port-Based VLAN Tagging for Differentiated Services Port-based VLAN function can group Ethernet ports, Port-1 ~ Port-4, and WiFi Virtual Access Points, VAP-1 ~ VAP-8, together for differentiated services like Internet surfing, multimedia enjoyment, VoIP talking, and so on. Two operation modes, NAT and Bridge, can be applied to each VLAN group.
Page 55
Cellular M2M Gateway Tag-based VLAN Tagging for Location-free Departments Tag-based VLAN function can group Ethernet ports, Port-1 ~ Port-4, and WiFi Virtual Access Points, VAP-1 ~ VAP-8, together with different VLAN tags for deploying department subnets in Intranet. All packet flows can carry with different VLAN tags even at the same physical port for Intranet.
Page 56
Cellular M2M Gateway switch to separate the VLAN trunk to different groups based on VLAN ID. Following is an example. In SMB or a company, administrator schemes out 3 segments, Lobby & Restaurant, Lab & Meeting Rooms and Office. In a Security VPN Gateway, administrator can configure Lobby &...
Cellular M2M Gateway Inter VLAN Group Routing: In Port-based tagging, administrator can specify member hosts of one VLAN group to be able to communicate with the ones of another VLAN group or not. This is a communication pair, and one VLAN group can join many communication pairs. But communication pair has not the transitive property.
Page 58
Cellular M2M Gateway By default, all the 4 LAN ports and 8 virtual APs belong to one VLAN, and this VLAN is a NAT type network, all the local device IP addresses are allocated by DHCP server 1. If you want to divide them into different VLANs, click on the “Edit” button related to each port.
Cellular M2M Gateway Above configuration example supports 3 access policies. The first one is Internet Access Policy that includes Port-1, Port-2, VAP-1 ~ VAP-4. All client hosts via these interfaces can access the Internet. The second policy is Intranet access Policy that includes Port-3 and VAP-5~ VAP-8.
Cellular M2M Gateway By default, all the LAN ports and virtual APs belong to one VLAN, and this VLAN ID is forced to “1”. It is a special tag based VLAN for device to operated, there is no tag required for this default VLAN ID. If you want to configure your own tag-based VLANs, click on the “Edit”...
Cellular M2M Gateway 3.1.3.1 WiFi Configuration This device is equipped with IEEE802.11b/g/n 2Tx2R wireless radio, you have to configure 2.4G Hz operation band’s wireless settings and then activate your WLAN. There are several wireless operation modes provided by this device. They are: “AP Router Mode”, “WDS Hybrid Mode”, and “WDS Only Mode”.
Page 62
Cellular M2M Gateway This mode allows you to get your wired and wireless devices connected with NAT. In this mode, this gateway is working as a WiFi AP, but also a WiFi hotspot. It means local WiFi clients can associate to it, and go to Internet. With its NAT mechanism, all of wireless clients don’t need to get public IP addresses from ISP.
Page 63
Cellular M2M Gateway wireless network. You can select VAP-1 ~ VAP-8 and configure each wireless network if it is required. 5. Time Schedule: The wireless radio can be turn on according to the schedule rule you specified. By default, the wireless radio is always turned on when the wireless module is enabled.
Page 64
Cellular M2M Gateway In this mode, you can only choose “None” or “WEP” in the encryption field. Shared Shared key authentication relies on the fact that both stations taking part in the authentication process have the same "shared" key or passphrase. The shared key is manually set on both the client station and the AP/router.
Cellular M2M Gateway and this router. This key value must be consistent with the key value in the RADIUS server. The available encryption modes are “TKIP”, “AES”, or “TKIP/AES”. WPA-PSK/WPA2-PSK If some of wireless clients can only support WPA-PSK, but most of them can support WPA2-PSK.
Page 66
Cellular M2M Gateway 1. Wireless Module: Enable the wireless function. 2. Wireless Operation Mode: Choose “WDS Only Mode” from the drop list. 3. Lazy Mode: This device support the Lazy Mode to automatically learn the MAC address of WDS peers, you don’t have to input other peer AP's MAC address. However, not all the APs can be set to enable the Lazy mode simultaneously;...
Page 67
Cellular M2M Gateway of when a failure may occur is if the client's MAC address is explicitly excluded in the AP/router configuration. In this mode you can enable 802.1x feature if you have another RADIUS server for user authentication. You need to input IP address, port and shared key of RADIUS server here.
Cellular M2M Gateway 8. Remote AP MAC 1 ~ Remote AP MAC 4: If you do not enable the Lazy mode, you have to enter the wireless MAC address for each WDS peer one by one. Afterwards, click on “Save” to store your settings or click “Undo” to give up the changes.
Page 69
Cellular M2M Gateway 1. Wireless Module: Enable the wireless function. 2. Wireless Operation Mode: Choose “WDS Hybrid Mode” from the drop list. 3. Lazy Mode: This device support the Lazy Mode to automatically learn the MAC address of WDS peers, you don’t have to input other peer AP's MAC address. However, not all the APs can be set to enable the Lazy Mode simultaneously;...
Page 70
Cellular M2M Gateway Open Open system authentication simply consists of two communications. The first is an authentication request by the client that contains the station ID (typically the MAC address). This is followed by an authentication response from the AP/router (WiFi gateway) containing a success or failure message.
Cellular M2M Gateway 12. Remote AP MAC 1 ~ Remote AP MAC 4: If you do not enable the Lazy mode, you have to enter the wireless MAC address for each WDS peer one by one. Afterwards, click on “Save” to store your settings or click “Undo” to give up the changes.
Cellular M2M Gateway “Enrollee”. In most cases, for an AP router or AP, it should be in “Registrar” mode, so that other wireless clients in “Enrollee” mode can connect to the discovered “Registrar”. Briefly specking, “Enrollee” is the initiator of WPS connection. Registrar Mode Enrollee Mode 4.
Cellular M2M Gateway 3.1.3.3 Advanced Configuration This device provides advanced wireless configuration for professional user to optimize the wireless performance under the specific installation environment. 1. Operation Band: Select the WiFi operation band that you want to configure. But the device supports only 2.4G single WiFi band. 2.
Page 74
Cellular M2M Gateway AP/router. The main purpose of beacon packet is let wireless clients know this AP (SSID) when doing wireless network scan. 4. DTIM interval: A DTIM is a countdown informing clients of the next window for listening to broadcast and multicast messages. When the wireless router has buffered broadcast or multicast messages for associated clients, it sends the next DTIM with a DTIM Interval value.
Cellular M2M Gateway 10. RF Bandwidth: Select Auto, HT20 or HT40 to define the RF bandwidth for a channel. By default, it is Auto for the device. 11. Transmit Power: Normally the wireless transmission power operates at 100% out power specification of this device. You can lower down the power ratio to prevent transmissions from reaching beyond your corporate/home office or designated wireless area.
Cellular M2M Gateway network renumbering and router announcements when changing Internet connectivity providers. This gateway supports various types of IPv6 connection (Static IPv6 / DHCPv6 / PPPoE / 6 to 4 / IPv6 in IPv4 tunnel). Please ask your ISP of what type of IPv6 is supported before you proceed with IPv6 setup.
Page 77
Cellular M2M Gateway 1. IPv6 address: Enter the IPv6 address here; IPv6 addresses have a size of 128 bits. Therefore, IPv6 has a vastly enlarged address space compared to IPv4. An example of an IPv6 address is “2001:0db8:85a3:0000:0000:8a2e:0370:7334” 2. Subnet Prefix Length: Enter the Prefix length of the Subnet Mask here; the prefix-length in IPv6 is the equivalent of the subnet mask in IPv4.
Cellular M2M Gateway 1. Auto-configuration: Disable or enable this auto configuration setting. 2. Auto-configuration Type: You may set stateless or stateful (Dynamic IPv6). 3. Router Advertisement Lifetime: You can set the time for the period that the router send (broadcast) its router advertisement. Each router periodically multicasts a Router Advertisement from each of its multicast interfaces, announcing the IP address of that interface.
Page 79
Cellular M2M Gateway list of ports that want to receive the data, instead of being flooded to all ports in a VLAN. This list is constructed by snooping IPv6 multicast control packets. If necessary in your environment, please enable this feature. WAN Connection Options 1.
Cellular M2M Gateway 3.1.4.3 PPPoEv6 When “PPPoEv6” is selected for the WAN Connection Type, you need to do the following settings: PPPoEv6 WAN Type Configuration 1. Account: enter the Username that you got from your ISP 2. Password: enter the Password that you got from your ISP 3.
Cellular M2M Gateway 1. Auto-configuration: Disable or enable this auto configuration setting. 2. Auto-configuration type: You may set stateless or stateful (Dynamic IPv6). 3. Router Advertisement Lifetime: You can set the time for the period that the router send (broadcast) its router advertisement. Each router periodically multicasts a Router Advertisement from each of its multicast interfaces, announcing the IP address of that interface.
Cellular M2M Gateway secondary DNS address. 3. MLD Snooping: MLD snooping, IPv6 multicast data is selectively forwarded to a list of ports that want to receive the data, instead of being flooded to all ports in a VLAN. This list is constructed by snooping IPv6 multicast control packets. If necessary in your environment, please enable this feature.
Page 83
Cellular M2M Gateway When “6 in 4” is selected for the WAN Connection Type, you need to do the following settings: 6in4 WAN Type Configuration 1. Remote / Local IPv4 and IPv6 Address: you may add remote / local IPv4 address and local IPv6 address, then set DNS address manually for Primary DNS address and secondary DNS address.
Cellular M2M Gateway 2. Auto-configuration Type: You may set stateless or stateful (Dynamic IPv6). 3. Router Advertisement Lifetime: You can set the time for the period that the router send (broadcast) its router advertisement. Each router periodically multicasts a Router Advertisement from each of its multicast interfaces, announcing the IP address of that interface.
Cellular M2M Gateway LAN Configuration 1. Global Address: Please enter IPv6 global address for LAN interface. 2. Link-Local Address: To show the IPv6 Link-Local address of LAN interface. Address Auto-configuration 1. Auto-configuration: Disable or enable this auto configuration setting. 2. Auto-configuration type: You may set stateless or stateful (Dynamic IPv6). 3.
Cellular M2M Gateway 3.1.5.1 Configuration 1. NAT Loopback: Allow you to access the WAN IP address from inside your local network. This is useful when you run a server inside your network. For an example, if you set a mail server at LAN side, your local devices can access this mail server through gateway’s WAN IP address.
Cellular M2M Gateway please refer to System->Scheduling. For example, if you have an FTP server (Service port 21) at 192.168.123.1, a Web server1 (Service port 80) at 192.168.123.2, a Web server2 (Service Port 8080 and Private port 80) at 192.168.123.3, and a VPN server at 192.168.123.6, then you need to specify the following virtual server mapping table Public Port Server IP...
Cellular M2M Gateway Enable: Check this item to enable the Virtual Computer feature. 3.1.5.2.3 Special AP & ALG NAT feature can protect Intranet from outside attacks, but sometimes also blocks some applications, such as SIP VoIP. In this situation, the NAT gateway needs to do special process (ALG) for each application.
Cellular M2M Gateway enabled. Rule: Check this item to enable the Special AP rule. 3.1.5.3 DMZ DMZ (DeMilitarized Zone) Host is a host without the protection of firewall. It allows a computer to be exposed to unrestricted 2-way communication for Internet games, Video conferencing, Internet telephony and other special applications.
Cellular M2M Gateway 3.1.6.1 Static Routing For static routing, you can specify up to 32 routing rules. The routing rules allow you to determine which physical interface addresses are utilized for outgoing IP data grams. You can enter the destination IP address, Subnet Mask, Gateway, and Metric for each routing rule, and then enable or disable the rule by checking or un-checking the Enable checkbox.
Page 91
Cellular M2M Gateway BGP for you to establish routing table automatically. The feature of dynamic routing will be very useful when there are lots of subnets in your network. Generally speaking, RIP is suitable for small network. OSPF is more suitable for medium network. BGP is more used for big network infrastructure.
Cellular M2M Gateway 3. BGP: Border Gateway Protocol (BGP) is the protocol backing the core routing decisions on the Internet. It maintains a table of IP networks or 'prefixes' which designate network reach-ability among autonomous systems (AS). It is described as a path vector protocol.
Cellular M2M Gateway contains information about the topology of the network immediately around it. This page displays the routing table maintained by this device. It is generated according to your network configuration. 3.1.7 Client/Server/Proxy 3.1.7.1 Dynamic DNS How does user access your server if your WAN IP address changes all the time? One way is to register a new domain name, and maintain your own DNS server.
Cellular M2M Gateway Host Name: Register a domain name to the DDNS provider. The fully domain name is concatenated with hostname (you specify) and a suffix(DDNS provider specifies). Username/E-mail: Input username or E-mail based on the DDNS provider you registered. Password/Key: Input password or key based on the DDNS provider you select.
Page 95
Cellular M2M Gateway this gateway, so there are maximum 253 clients allowed in LAN network. Hereafter are the available options for subnet mask. 4. IP Pool Starting / Ending Address: Whenever there is a request, the DHCP server will automatically allocate an unused IP address from the IP address pool to the requesting computer.
Page 96
Cellular M2M Gateway assign IP address to local computers, but local computers will go to Internet through another gateway. Press “Clients List …” button at the bottom of one DHCP server configuration page and the list of DHCP clients will be shown consequently. Select some client records by checking the “Select”...
Cellular M2M Gateway 3.2 Advanced Network This device also supports many advanced network features, such as Firewall, QoS & Bandwidth Management, VPN Security, Redundancy and System Management. You can finish those configurations in this section. 3.2.1 Firewall The firewall functions include Packet Filters, URL Blocking, Web Content Filters, MAC Control, Application Filters, IPS and some firewall options.
Cellular M2M Gateway 3.2.1.2 Packet Filters Packet Filters function can let you define both outbound filter and inbound filter rules by specifying the source IP and destination IP in a rule. It enables you to control what packets are allowed or blocked to pass the router. Outbound filters are applied to all outbound packets.
Cellular M2M Gateway Filter List. Besides, unnecessary rules can be removed by checking the “Select” box for those rules and then clicking on the “Delete” command button at the Packet Filter List caption. 3.2.1.2.3 Packet Filter Rule Configuration It supports the adding of one new rule or the editing of one existed rule. There are some parameters need to be specified in one packet filter rule.
Cellular M2M Gateway implies all ports are used. You also can choose one well-known service instead so that the chosen service will provide its destination port and protocol number for the rule. The supported well-known services include: 7. Protocol: Specify which packet protocol is to be filtered. It can be TCP, UDP, or Both.
Cellular M2M Gateway 3.2.1.3.1 Configuration 1. URL Blocking: Check the enable box if you want to activate URL Blocking function. 2. Black List / White List: Select one of the two filtering policies for the defined rules in URL Blocking Rule List. ...
Cellular M2M Gateway 3.2.1.3.3 URL Blocking Rule Configuration It supports the adding of one new rule or the editing of one existed rule. There are some parameters need to be specified in one URL blocking rule. They are Rule Name, URL / Domain Name / Keyword, Destination Port, Time Schedule and finally, the rule enable.
Cellular M2M Gateway script types, like Java Applet, Java Scripts, cookies and Active X. 3.2.1.4.1 Configuration 1. Web Content Filters: Check the Enable box if you want to enable Web Content Filters function. 2. Popular File Extension List: Check which extension types, Cookie, Java, ActiveX, are to be blocked.
Cellular M2M Gateway 3.2.1.4.3 Web Content Filter Configuration It supports the adding of one new rule or the editing of one existed rule. There are some parameters need to be specified in one Web Content Filter rule. They are Rule Name, User-defined File Extension List, Time Schedule and finally, the rule enable.
Cellular M2M Gateway 3.2.1.5.1 Configuration 1. MAC Control: Check the “Enable” box to activate the MAC Control function. All of the settings in this page will take effect only when “Enable” is checked. 2. Black List / White List: Select one of the two filtering policies for the defined rules.
Cellular M2M Gateway “Select” box for those rules and then clicking on the “Delete” command button at the MAC Control Rule List caption. 3.2.1.5.3 MAC Control Rule Configuration It supports the adding of one new rule or the editing of one existed rule. There are some parameters need to be specified in one MAC Control rule.
Cellular M2M Gateway 3.2.1.6.1 Configuration 1. Application Filters: Check the “Enable” box to activate the Application Filters function. All of the settings in this page will take effect only when “Enable” is checked. 2. Log Alert: Enable the log alerting so that system will record Application Filter events when filtering rules are fired.
Cellular M2M Gateway 3.2.1.8 Options 1. Stealth Mode: Enable this feature, this device will not respond to port scans from the WAN so that makes it less susceptible to discovery and attacks on the Internet. 2. SPI: When this feature is enabled, the router will record the outgoing packet information pass through the router like IP address, port address, ACK, SEQ number and so on.
It is indeed required that an access gateway satisfies the requirements of latency-critical applications, minimum access right guarantee, fair bandwidth usage for same subscribed condition and flexible bandwidth management. AMIT Security Gateway provides a Rule-based QoS to carry out the requirements.
Cellular M2M Gateway 3.2.2.1 Configuration QoS on Multiple WAN Interfaces QoS on all WAN interfaces satisfies the requirements of latency-critical applications, minimum access right guarantee, fair bandwidth usage for same subscribed condition and flexible bandwidth management in a more flexible approach.
Cellular M2M Gateway 1. WAN Interface: Select the WAN interface to configure. 2. Bandwidth of Upstream: The maximum bandwidth of uplink in Mbps. 3. Bandwidth of Downstream: The maximum bandwidth of downlink in Mbps. 4. Total Connection Sessions: Input the maximum number of connection sessions for the WAN interface.
Cellular M2M Gateway connection sessions, priority queues and DiffServ Code Point (DSCP). Control function that acts on target objects for specific services of packet flow is based on these resources. For bandwidth resource, control functions include guaranteeing bandwidth and limiting bandwidth. For priority queue resource, control function is setting priority.
Cellular M2M Gateway 1. Add: After you enabled the rule-based QoS function, you can click on the “Add” button to create a new QoS rule. 2. Delete: After you selected some QoS rules by checking the “Select” box for each rule, you can click on the “Delete”...
Page 114
Cellular M2M Gateway You need to choose a correct one according to your device’s specification. When “TOS” is selected for Service, TOS value must be chosen from a list of 4 options. For example: When “User-defined Services” is selected, two more parameters, Protocol Number and Service Port Range, must be defined.
Page 115
Cellular M2M Gateway 5. Control Function: It depends on the chosen resource. For “Bandwidth” resource, the control function is “Set MINR & MAXR”. For “Connection Sessions”, the control function is “Set Session Limitation”. For “Priority Queues”, it is “Set Priority”. However, for “DiffServ Code Points”, it is “DSCP Marking”...
Page 116
Cellular M2M Gateway Interface: Select “All WANs”. Group: Select “IP” and enter IP range: 192.168.75.10 ~ 40. Service: Select “DSCP” with DiffServ CodePoint is CS4. Resource: Select “DiffServ Code Points”. Control Function: Select “DSCP Marking” with “AF Class 2(High Drop)”. ...
Cellular M2M Gateway 3.2.3 VPN Setup A virtual private network (VPN) extends a private network across a public network, such as the Internet. It enables a computer to send and receive data across shared or public networks as if it were directly connected to the private network, while benefitting from the functionality, security and management policies of the private network.
Page 118
Cellular M2M Gateway a static IP address or a FQDN can initiate the establishing of an IPSec VPN tunnel. Two peers of the tunnel have their own Intranets and the secure tunnel serves for data communication between these two subnets of hosts. ...
Cellular M2M Gateway done in a secure way through local Business Security Gateway. 3.2.3.1.2 IPSec Configuration IPSec: You could trigger the function of IPSec VPN if you check “Enable” box. NetBIOS over IPSec: If you would like two Intranets behind two Business Security Gateways to receive the NetBIOS packets from Network Neighborhood, you have to check “Enable”...
Cellular M2M Gateway Add: You can add one new IPSec tunnel with Site to Site scenario by clicking the “Add” button. Delete: Delete selected tunnels by checking the “Select” box at the end of each tunnel list and then clicking the “Delete” button. Refresh: To refresh the Tunnel List &...
Cellular M2M Gateway there is no traffic within the VPN tunnel. If the device can't get ICMP response from remote host anymore, it will terminate the VPN tunnel automatically. 3.2.3.1.5 Local & Remote Configuration Local subnet: The subnet of LAN site of local Business Security Gateway. It can be a host, a partial subnet, or the whole subnet of LAN site of local gateway.
Cellular M2M Gateway IPSec phase. The pre-shared key must be the same for both VPN tunnel initiator and responder. When “Manually” key management is adopted, the Pre-shared is not necessary. Local ID: The Type and the Value of the local Business Security Gateway must be the same as that of the Remote ID of the remote VPN peer.
Cellular M2M Gateway Name” and “Password” for valid user to initiate that tunnel. Dead Peer Detection: This feature will detect if remote VPN peer still exists. Delay indicates the interval between detections, and Timeout indicates the timeout of detected to be dead. Phase 1 Key Life Time: The value of life time represents the life time of the key which is dedicated at Phase 1 between both end gateways.
Cellular M2M Gateway There are 4 IPSec proposals can be defined by you and used in IPSec phase of negotiation between two VPN peers. Encryption: There are six algorithms can be selected: DES, 3DES, AES-auto, AES-128, AES-192, and AES-256. Authentication: There are five algorithms can be selected: None, MD5, SHA1, SHA2-256 and SHA2-512.
Cellular M2M Gateway also set in hex formatted. 3.2.3.2 PPTP The Point-to-Point Tunneling Protocol (PPTP) is a method for implementing virtual private networks. PPTP uses a control channel over TCP and a GRE tunnel operating to encapsulate PPP packets. The PPTP specification does not describe encryption or authentication features and relies on the Point-to-Point Protocol being tunneled to implement security functionality.
Cellular M2M Gateway The Business Security Gateway can behave as a PPTP server and a PPTP client at the same time. PPTP: Check the “Enable” box to activate PPTP client and server functions. Client/Server: Choose Server or Client to configure corresponding role of PPTP VPN tunnels for the Business Security Gateway beneath the choosing screen 3.2.3.2.2 PPTP Server Configuration The Business Security Gateway can behave as a PPTP server, and it allows remote...
Cellular M2M Gateway Server Virtual IP: It is the virtual IP address of PPTP server used in PPTP tunneling. This IP address should be different from the gateway one and members of LAN subnet of Business Security Gateway. IP Pool Starting Address: This device will assign an IP address for each remote PPTP client.
Cellular M2M Gateway Add or edit one user account will activate the “User Account Configuration” screen. User Name: Enter the user name of user account. Password: Enter the password of user account. Account: Check the “Enable” box to validate the user account. Save: To save the user account configuration.
Page 129
Cellular M2M Gateway PPTP Client Name: The name of this tunnel. Operation Mode: Default is “Always on” and other options depend on product models. Peer IP/Domain: The IP address or Domain name of remote PPTP server. User Name: The user name which can be validated by remote PPTP server. Password: The password which can be validated by remote PPTP server.
Cellular M2M Gateway authentication methods. 10. NAT before Tunneling: Check the “Enable” box to let hosts in the Intranet of Business Security Gateway can go to access Internet via remote PPTP server. By default, it is enabled. However, if you want the remote PPTP Server to monitor the Intranet of local Business Security Gateway, the option can’t be enabled.
Cellular M2M Gateway 1. L2TP Server: Enable or disable L2TP server function. 2. L2TP over IPSec: L2TP over IPSec VPNs allow you to transport data over the Internet, while still maintaining a high level of security to protect data. Enter a Pre-shared key that system will use it in IPSec tunneling.
Cellular M2M Gateway dialing in L2TP clients by clicking on the “Disconnect” button. 3.2.3.3.3 User Account List You can input up to 10 different user accounts for dialing in L2TP server. Add: You can add one new user account by clicking on the “Add” button. Delete: Delete selected user accounts by checking the “Select”...
Cellular M2M Gateway You can add new up to 22 different L2TP client tunnels by clicking on the “Add” button, and modify each tunnel configuration by clicking on the corresponding “Edit” button at the end of each existed tunnel. Add: You can add one new L2TP client tunnel by clicking on the “Add” button. Delete: Delete selected tunnels by checking the “Select”...
Cellular M2M Gateway Intranet of Business Security Gateway goes over this L2TP tunnel if these packets don’t match the Peer Subnet of other L2TP tunnels. There is only one L2TP tunnel to own the “Default Gateway” property. However, when “Peer Subnet”...
Cellular M2M Gateway 3.2.3.4.2 GRE Configuration GRE Tunnel: Check the “Enable” box to activate the GRE tunnel function. 3.2.3.4.3 GRE Tunnel Definitions Add: You can add one new GRE tunnel by clicking on the “Add” button. Delete: Delete selected tunnels by checking the “Select” box at the end of each tunnel list and then clicking on the “Delete”...
Cellular M2M Gateway Tunnel: Enable or disable this GRE tunnel. Tunnel Name: The name of this GRE tunnel. Tunnel IP: The gateway IP address of Business Security Gateway. Peer IP: Enter the IP address of remote peer that you want to connect. Key: Enter the password to establish GRE tunnel with remote host.
Page 137
Cellular M2M Gateway The protocol achieves this by creation of virtual routers, which are an abstract representation of multiple routers, i.e. master and backup routers, acting as a group. The default gateway of a participating host is assigned to the virtual router instead of a physical router.
Cellular M2M Gateway 3.2.5 System Management This device supports many system management protocols, such as TR-069, SNMP, Telnet with CLI and UPnP. You can finish those configurations in this sub-section. 3.2.5.1 TR-069 TR-069 (Technical Report 069) is a Broadband Forum technical specification entitled CPE WAN Management Protocol (CWMP).
Page 139
IF-MIB, IP-MIB, TCP-MIB, UDP-MIB SMIv1 and SMIv2 SNMPv2-TM and SNMPv2-MIB AMIB (AMIT Private MIB) 1. Enable SNMP: You can check “Local(LAN)”, “Remote(WAN)” or both to enable SNMP function. If “Local(LAN)” is checked, this device will respond to the request from LAN.
Cellular M2M Gateway from WAN. 2. WAN Access IP Address: If you want to limit the remote SNMP access to specific computer, please enter the PC`s IP address. The default value is 0.0.0.0, and it means that any internet connected computer can get some information of the device with SNMP protocol.
Cellular M2M Gateway port mapping protocol and is supported by some NAT routers. It is a common communication protocol of automatically configuring port forwarding. Applications using peer-to-peer networks, multiplayer gaming, and remote assistance programs need a way to communicate through home and business gateways. Without IGD one has to manually configure the gateway to allow traffic through, a process which is error prone and time consuming.
Cellular M2M Gateway 3.3.1 Mobile Application 3.3.1.1 SMS You can compose new SMS message and check received SMS message on this gateway. 1. Physical Interface: Indicate which 3G/LTE modem is used for SMS feature. 2. SMS: Indicate which SIM card is used for SMS feature. 3.
Page 143
Cellular M2M Gateway 1. From Phone Number: Indicate phone number of sender. 2. Alert Approach: Decide the way to forward message. You can forward this message to another phone number, or to a mail address, or to a syslog server. 3.
Cellular M2M Gateway Read New SMS Message You can read, delete, reply, and forward messages in this inbox section. 1. Refresh: You can press “Refresh” button to renew SMS lists. 2. Delete, Reply, Forward Messages: After reading message, you can check the checkbox on the right of each message to delete, reply, or forward this message.
Cellular M2M Gateway You can compose a USSD message, and sends it to the service provider, where it is received by a computer dedicated to USSD. The answer from this computer is sent back to this device, but it is usually with a very basic presentation. 1.
Cellular M2M Gateway 1. Physical Interface: Indicate which 3G/LTE modem is used for network scan. And SIM Status indicates which SIM card is used to Network Scan. 2. Network Type: Set network type of network scan. You can choose “2G Only”, “3G Only”, “LTE Only”, or “Auto”.
Page 147
Cellular M2M Gateway Management Settings 1. Remote Management via SMS: Check this to enable this function. 2. Delete SMS for Remote Management: This device will delete received SMS message that is for remote management purpose if enabling this option. This option can prevent storage space of SIM card from being occupied continuously.
Page 148
Cellular M2M Gateway 4. Reconnect: Enable it, and you can send command “reconnect” to disconnect WAN connection, and start WAN connection again immediately. 5. Reboot: Enable it, and you can send command “reboot” to restart router. **All management commands are not case sensitive** Notification Settings 1.
Cellular M2M Gateway 3.4 System In the System section you can see system related information and system logs, use system tools for system update and do some network tests. Besides, you can also define some time scheduling rules here to be applied at various applications in the device system.
Cellular M2M Gateway click “Undo” to give up the changes. 1. Old Password: Input the old password of administrator. 2. New Password: Input the new password of administrator for future logging in. Certainly, once the password is changed successfully, system will ask you login again with new password.
Cellular M2M Gateway 1. Web Log: You can select the log types to be collected in the web log area. There are “System”, “Attacks”, “Drop”, and “Debug” types for you to select. 2. Email Alert: This device can also export system logs via sending emails to specific recipients.
Page 152
Cellular M2M Gateway System Time There are three approaches to setup the system time. Before the process, some basic information must be filled by clicking on the “Configure” command button. Basic information includes following items: 1. Time Zone: Select a time zone where this device locates. 2.
Page 153
Cellular M2M Gateway “Sync with my PC”. Click on the button to let system synchronizes its date and time to the ones of the configuration PC. FW Upgrade If new firmware is available, you can upgrade router firmware through the WEB GUI here.
Page 154
Cellular M2M Gateway Tracert Test Traceroute is a network diagnostic tool for displaying the route (path) and measuring transit delays of packets across an IP network. Traceroute proceeds unless all (three) sent packets are lost more than twice, then the connection is lost and the route cannot be evaluated.
Cellular M2M Gateway Reset to Default You can reset this device to factory default settings by clicking the “Reset” button. Wake on LAN Wake on LAN (WOL) is an Ethernet networking standard that allows a computer to be turned on or awakened by a network message. You can specify the MAC address of the computer, in your LAN network, to be remotely turned on by clicking on the “Wake up”...
Page 156
Cellular M2M Gateway Time). In a schedule rule, it collects 8 time periods to organize it. You also can specify the rule is to define the enable timing (“Inactive except the selected days and hours below”) or disable timing (“Active except the selected days and hours below”).
Cellular M2M Gateway Appendix A. Licensing Information This product includes copyrighted third-party software licensed under the terms of the GNU General Public License. Please refer to the GNU General Public License below to check the detailed terms of this license. Availability of source code Please visit our web site or contact us to obtain more information.
Page 158
Cellular M2M Gateway GNU GENERAL PUBLIC LICENSE Version 2, June 1991 Copyright (C) 1989, 1991 Free Software Foundation, Inc. 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed. Preamble The licenses for most software are designed to take away your freedom to share and change it.
Page 159
Cellular M2M Gateway the Program). Whether that is true depends on what the Program does. 1. You may copy and distribute verbatim copies of the Program's source code as you receive it, in any medium, provided that you conspicuously and appropriately publish on each copy an appropriate copyright notice and disclaimer of warranty;...
Page 160
Cellular M2M Gateway If distribution of executable or object code is made by offering access to copy from a designated place, then offering equivalent access to copy the source code from the same place counts as distribution of the source code, even though third parties are not compelled to copy the source along with the object code.
Page 161
Cellular M2M Gateway Foundation, write to the Free Software Foundation; we sometimes make exceptions for this. Our decision will be guided by the two goals of preserving the free status of all derivatives of our free software and of promoting the sharing and reuse of software generally. NO WARRANTY 11.
Need help?
Do you have a question about the IDG761AM-0P001 and is the answer not in the manual?
Questions and answers