Page 1
USB Device Server myUTN-50a Dongleserver myUTN-80 myUTN-55 Dongleserver myUTN-800 myUTN-250 User Manual Windows...
Page 2
SEH Computertechnik GmbH has endeavored to ensure that the information in this documentation is correct. If you detect any inaccuracies please inform us at the address indicated above. SEH Computertechnik GmbH will not accept any liability for any error or omission.
The 'Dongleservers' (myUTN-80 and myUTN-800) are exclusively designed for the deployment of USB dongles. The software tool 'SEH UTN Manager' handles the access of the USB devices. The software is installed on all clients that are meant to access a USB device in the network. The SEH UTN Manager shows...
Page 7
User Manual. For further information; see: ’Documentation’ 8. Procedure and Basic After the SEH UTN Manager is started, the network will be scanned Functions for connected UTN servers. The network range to be scanned is freely definable.
'myUTN Control Center'. Online Help (SEH UTN Manager) The Online Help contains detailed information about how to use the software tool 'SEH UTN Manager'. Document Features This documentation has been designed as an electronic document for screen use. Many programs (e.g. Adobe® Reader®) offer a book-...
Page 9
General Information mark navigation feature that allows you to view the entire docu- ment structure. This document contains hyperlinks to the associated information units. If you want to print this documentation, we recommend using the printer setting 'Duplex' or 'Booklet'. Terminology Used in The explanation of technical terms used in this document is summa- this Document...
Page 10
General Information Symbols and A variety of symbols are used within this document. Their meaning is Conventions listed in the following table: Table 1: Conventions within the documentation Symbol / Convention Description A warning contains important information that must be heeded. Non-observance may lead to malfunctions.
8:00 a.m. to 3:15 p.m. (CET) +49 (0)521 94226-44 support@seh.de Current Services The following services can be found on the homepage of SEH Com- putertechnik GmbH http://www.seh-technology.com: • current firmware/software • current tools • current documentation • current product information •...
This will avoid potential misuse and prevent damages to people and devices. SEH Computertechnik GmbH will not accept any liability for per- sonal injuries, property damages and consequential damages result- ing from the non-observance of the mentioned safety regulations and warnings.
Guide'. 3. Make sure that an IP address is stored in the UTN server; see: 14 4. Install and start the software tool 'SEH UTN Manager' on your 21 Windows client; see: 5. Add the UTN servers that you want to use to the selection list;...
IP address in the UTN server. The UTN server’s assigned IP address can be determined and changed using the software tools 'SEH UTN Manager' and 'Inter- Con-NetTool'; see: 18. Different methods for the assignment of the IP address are described in the following.
Page 15
General Information ZeroConf If no IP address can be assigned via boot protocols, the UTN server assigns itself an IP address via ZeroConf. For this purpose, the UTN server picks an IP address at random from the address range (169.254.0.0/16) which is reserved for ZeroConf. You can use the domain name service of Bonjour for the name reso- lution of the IP address;...
Page 16
IPv4 address via the InterCon-NetTool, see: 37. SEH UTN Manager You can manually enter the desired IPv4 address and save it in the UTN server using the SEH UTN Manager. To configure an IPv4 address via the SEH UTN Manager, see: 36. myUTN Control Center You can manually enter the desired IP address and save it in the UTN server using the myUTN Control Center.
Page 17
General Information • To configure an IPv4 address via the myUTN Control Center, see: 36. • To configure an IPv6 address via the myUTN Control Center, see: 38. ARP/PING The assignment of the IP address to the hardware address can be done via the ARP table.
• ’Administration via myUTN Control Center’ 19 What Information Do You Need? • ’Administration via the SEH UTN Manager’ 21 • ’Administration via InterCon-NetTool’ 30 • ’Administration via E-Mail (only myUTN-80 and later)’ 32 myUTN User Manual Windows...
UTN server in the device list and select Actions – Launch Browser from the menu bar. • To start the myUTN Control Center via the SEH UTN Manager, mark the UTN server in the selection list and select UTN Server –...
Page 20
Administration Methods Fig. 2: myUTN Control Center - START Structure of the The available menu items are located in the navigation bar (top). myUTN Control After selecting a menu item (simple mouse click), the available sub- Center menu items are displayed at the left. After selecting a submenu item, the corresponding page with its content is displayed (at the right).
Administration via the SEH UTN Manager Area of Application The software tool 'SEH UTN Manager' handles the access of the USB devices. The SEH UTN Manager shows the availability of all UTN servers and USB devices that exist in the network and establishes a connection between the client and the USB port of the UTN server to which the USB device is connected.
Page 22
UTN servers, simplified use of USB devices, and much more. The minimal version of the SEH UTN Manager can only be used via the command-line interface and UTN Actions. The minimal version can for example be used to •...
Page 23
Print-On-Demand can only be configured by users with administra- tive rights. Installation In order to use the SEH UTN Manager, the program must be installed on a computer with a Windows operating system. The installation file of the SEH UTN Manager can be found on the SEH Computer- technik GmbH homepage: http://www.seh-technology.com/services/downloads.html...
Page 24
Administration Methods Standard Installation The installation file is available as '*.exe' for Windows systems. The installation of the SEH UTN Manager is suitable for Windows System Requirements XP and later. The installation can only be carried out by users with administrative rights.
Page 25
Manager UTN Manager can be automatically installed on a large number of clients via login scripts. For more information, refer to the documentation of your operating system. The installation of the SEH UTN Managers is suitable for System Requirements Windows XP and later.
Page 26
Instructs the installation to be silent. There is no user interaction and the user cannot cancel the installation. Updates an existing SEH UTN Manager. (If no SEH UTN Manager is installed, it will be installed using the default installation settings.) Enables command line logging.
Page 27
. The icon is found on the desktop or the Windows start menu. (Start All Programs SEH Computertechnik GmbH SEH UTN Manager) Changing Versions If the minimal oder complete version of the SEH UTN Manager is already installed on your system and you want to change to the other version, you must first uninstall the existing version.
Page 28
• 'Granting Access to Locked USB Ports' 90 • 'Managing Selection Lists for Several Participants' 77 Detailed information on how to use the SEH UTN Manager can be found in the Online Help. To start the Online Help, select Help –...
Page 29
Administration Methods Functions in the SEH UTN Manager can be shown as inactive or not shown at all. This depends on • the embedded UTN server model • the type and location of the selection list • the user's rights on the client •...
Administration Methods Administration via InterCon-NetTool The InterCon-NetTool is a software that has been developed by SEH Computertechnik GmbH for the administration of SEH network devices (print server, TPG, ISD, UTN server, etc.). Depending on the network device you can configure various features via the Inter-...
Page 31
Administration Methods The settings of the InterCon-NetTool are saved in the 'NetTool.ini' file. This file is stored in the user folder of the user that is currently logged in. After the program start you will see the main dialog with the fol- Structure of the lowing elements.
Administration Methods Administration via E-Mail (only myUTN-80 and later) You can administer the UTN server via email and thus via any com- puter with Internet access. Functionalities An email allows you to • send UTN server status information • define UTN server parameters or •...
Page 33
Administration Methods The following commands are supported: Commands Option Description <command> get status Sends the status page of the UTN server. get parameters Sends the parameter list of the UTN server. set parameters Sends parameters to the UTN server. The syntax and values can be obtained from the parameter list, see: 121.
Page 34
Administration Methods Example 1 This email causes the UTN server to send the parameter list to the sender of the email. Email address of the UTN server as configured on the POP3 server. Command Fig. 5: Administration via Email - Example 1 Example 2 This email configures the parameter 'Description' on the UTN server.
IP addresses, see: 14. ’Configuring IPv4 Parameters via the myUTN Control Center’ What Do You Want 36 To Do? ’Configuring IPv4 Parameters via the SEH UTN Manager’ 36 ’Configuring IPv4 Parameters via InterCon-NetTool’ 37 myUTN User Manual Windows...
Page 36
Gateway Gateway address of the UTN server Configuring IPv4 Parameters via the SEH UTN Manager The SEH UTN Manager (complete version) is installed on the Requirements client; see: 21. The UTN server is shown in the selection list; see: 65.
Page 37
Network Settings Configuring IPv4 Parameters via InterCon-NetTool The InterCon-NetTool is installed on the client, see: 30. Requirements The network scan via Multicast has been enabled in the InterCon-NetTool. Proceed as follows: 1. Start the InterCon-NetTool. 2. Select the UTN server from the device list. The UTN server is displayed in the device list under the filter 'ZeroConf' with an IP address from the address range (169.254.0.0/16) which is reserved for ZeroConf.
Network Settings How to Configure IPv6 Parameters You can integrate the UTN server into an IPv6 network. What are the IPv6 (Internet Protocol version 6) is the successor of the more com- Advantages of IPv6? monIPv4. Both protocols are standards for the network layer of the OSI model and regulate the addressing and routing of data packets via a network.
Page 39
Network Settings Which Types of IPv6 There are different types of IPv6 addresses. The prefixes of the IPv6 Addresses are addresses provide information about the IPv6 address types. available? • Unicast addresses can be routed globally. These addresses are unique and therefore unambiguous. A packet that is sent to a unicast address will only arrive to the interface that is assigned to this address.
Network Settings Parameters Description IPv6 address Defines a UTN server IPv6 unicast address assigned manually in the format n:n:n:n:n:n:n:n. Every 'n' represents the hexadecimal value of one of the eight 16 bit elements of the address. An IPv6 address may be entered or displayed using a shortened version when successive fields contain all zeros (0).
Network Settings Table 4: DNS Parameters Parameters Description Enables/disables the name resolution via a DNS server. Primary DNS server Defines the IP address of the primary DNS server. Secondary DNS server Defines the IP address of the secondary DNS server. The secondary DNS server is used if the first one is not available.
Network Settings Only for SNMPv3: The user accounts have been defined; see: Requirements 86. Proceed as follows: 1. Start the myUTN Control Center. 2. Select NETWORK – SNMP. 42 3. Configure the SNMP parameters; see: table 5 4. Click Save to confirm. ...
Page 43
Network Settings When checking the IP address assigned via ZeroConf (see: ’ZeroConf’ 15) the UTN server sends a query to the network. If the IP address has already been assigned elsewhere in the network, the UTN server will receive a message. The UTN server then sends another query with a different IP address.
Network Settings How to Configure POP3 and SMTP (only myUTN-80 and later) You must configure the protocols POP3 and SMTP on the UTN server so that the notification service (55) and the remote mainte- nance via email (32) will work. POP3 'POP3' (Post Office Protocol Version 3) is a transfer protocol that a client can use to fetch emails from a mail server.
Network Settings Table 7: POP3 Parameters Parameters Description POP3 Enables/disables the POP3 functionality. POP3 - Server name Defines the POP3 server via the IP address or the host name. The host name can only be used if a DNS server was configured beforehand.
Page 46
Network Settings Table 8: SMTP Parameters Parameters Description SMTP - Server name Defines the SMTP server via the IP address or the host name. The host name can only be used if a DNS server was configured beforehand. SMTP - Server port Defines the port number used by the UTN server to send emails to the SMTP server.
Network Settings How to Configure WLAN (myUTN-55 only) The UTN server 'myUTN-55' is a WLAN device and is operated wire- lessly in the network. What is WLAN? WLAN is a radio technology that allows you to establish wireless connections between network components. The WLAN technology is defined as a standard of the IEEE 802.11 family.
Page 48
Network Settings access point and the UTN server do not match. It is therefore recom- mended to use hexadecimal WEP keys. WPA/WPA2 In contrast to WEP, WPA (Wi-Fi Protected Access) offers enhanced mechanisms for exchanging keys. The exchange key is only used at the beginning of a session.
Page 49
Network Settings Table 9: WLAN Parameters Parameters Description Mode Defines the communication mode. The communication Communication mode) mode defines the network structure in which the UTN server will be installed. Two modes are available: - In the 'Ad-Hoc' mode, the UTN server communicates directly with another WLAN client (peer-to-peer).
Page 50
Network Settings Parameters Description Encryption method see: ’WLAN Security’ 47 Authentication method see: ’How to Use Authentication Methods’ 101 myUTN User Manual Windows...
Device Settings 4 Device Settings You can configure the device time, the UTN port, the notification service, etc. on the UTN server. This chap- ter describes these device settings. • ’How to Determine a Description’ 51 What Information Do You Need? •...
Device Settings The data is saved. To assign names to USB ports, see: 54. How to Assign an Identifier Shown in the Display Panel (myUTN-800 only) The Dongleserver myUTN-800 can be mounted in a 19" server rack. In order to identify a certain myUTN-800 if several are mounted in a rack, an identifier is shown in the display panel on the front side of the Dongleserver.
Device Settings How to Configure the Device Time You can control the device time of the UTN server via a time server (SNTP server) in the network. A timeserver is a computer networking device that reads the actual time from a reference clock and distrib- utes this information to its clients.
This UTN port or the UTN SSL port must not be blocked by a firewall. If required, you can change the port number on the UTN server. In order that the SEH UTN Managers installed on the clients Requirements receive the current port number, the 'SNMPv1' parameter must be activated;...
Purpose devices cannot be connected to the network. Deactivated USB ports cannot be seen in the SEH UTN Manager. This function also allows you to turn a USB device off and on again without having to manually remove or reconnect it. USB devices that are in an undefined state, can be restarted by interrupting and re-establishing the power supply of the USB port.
Page 56
Device Settings • The event notification informs you about a specific event on the UTN server via email or SNMP trap. The event can be: The restart of the UTN server. The connection/disconnection of a USB device to/from the UTN server. The activation/deactivation of a USB port.
Device Settings Configuring event notifications via email SMTP parameters have been configured on the UTN server, see: Requirements 44. A DNS server has been configured on the UTN server, see: 40. For the notification service you can specify up to two email recipi- ents and the message types.
Device Settings • only one power supply works • SD card errors (read and write errors, no SD card) Errors are displayed in codes. The meaning of the codes you will find in chapter ’Information Shown in the Display Panel (myUTN-800 only)’...
Page 59
Device Settings • only one network connection is established These optional acoustic signals ideally complement the error mes- sages in the display panel 57. Proceed as follows: 1. Start the myUTN Control Center. 2. Select Device – Notification. 3. In the Acoustic signal area, tick the options with the desired message types.
Device Settings 4.10 How to Use the UTN Server in VLAN environ- ments (only myUTN-80 and later) The UTN server supports the use of VLAN (Virtual Local Area Net- works). It is useful to divide a physical network into VLANs for per- formance and security reasons.
Page 61
Device Settings Entering IPv4 Management VLANs Proceed as follows: 1. Start the myUTN Control Center. 2. Select NETWORK – IPv4 VLAN. 3. Configure the IPv4 management VLAN parameters; see: table 11 62 4. Click Save to confirm. The settings are saved. Table 10: IPv4 management VLAN parameters Parameters Description...
Page 62
Device Settings 4. Click Save to confirm. The settings are saved. Table 11: IPv4 client VLAN parameters Parameters Description VLAN Enables/disables the forwarding of IPv4 client VLAN data. IP Address IP address of the UTN server within the IPv4 client VLAN.
The software tool SEH UTN Manager handles the access of the USB devices. This chapter will show you how to embed USB devices in the SEH UTN Manager and how to establish connections between the client and the USB port including the connected USB device.
’Defining Search Parameters’ 64 What Do You Want To Do? ’Scanning the Network’ 64 Defining Search Parameters The SEH UTN Manager (complete version) is installed on the Requirements client; see: 21. Proceed as follows: 1. Start the SEH UTN Manager.
The UTN servers found during the network scan will be displayed in the 'network list'. To use the connected USB devices, they must be assigned to the 'selection list' in the SEH UTN Manager together with the UTN server. The SEH UTN Manager (complete version) is installed on the Requirements client;...
The SEH UTN Manager (complete version) is installed on the Requirements client; see: 21. The USB port is shown in the selection list; see: 65. All provisions (driver installation, etc.) necessary to operate the USB device locally (i.e.
Page 67
1. Start the SEH UTN Manager. 2. Select the port from the selection list. 3. Select Port – Activate from the menu bar. The connection will be established. Fig. 11: SEH UTN Manager - Activating the Device myUTN User Manual Windows...
USB device is no longer needed. This allows other network participants to access the USB port and the connected USB device. Usually the connection is cut by the user via the SEH UTN Manager. The administrator can also cut the connection via the myUTN Con- trol Center.
The user can then terminate the connection to the USB port. When the USB port is shared, the connection between the USB port and your client will be established automatically. The SEH UTN Manager (complete version) is installed on the Requirements client; see: 21.
• activated upon the operating system startup and terminated when the system shuts down • automatically reestablished when the system restarts. The SEH UTN Manager (complete version) is installed on the Requirements client; see: 21. The USB port is shown in the selection list; see: 65.
Page 71
Auto-Disconnect allows a large number of network participants to access a small amount of USB ports including the connected USB devices and avoids idle times. The SEH UTN Manager (complete version) is installed on the Requirements client; see: 21.
Page 72
(printer or multifunction printer) and the client will be automati- cally created as soon as a print job is received. After completion of the print job, the connection will be automatically disabled. The SEH UTN Manager (complete version) is installed on the Requirements client; see: 21.
Page 73
Working with the SEH UTN Manager 7. Select Port – Deactivate from the menu bar. The connection will be deactivated. Print-On-Demand is set up. myUTN User Manual Windows...
Page 74
USB port after the closing of the application and additional options. Finally, the complete UTN Action will be created automatically by the SEH UTN Manager and saved by the user. The SEH UTN Manager (complete version) is installed on the Requirements client;...
Page 75
Working with the SEH UTN Manager 3. Select Port – Create UTN Action from the menu bar. The dialog Create UTN Action will be started. 4. Follow the instructions of the Wizard. A UTN Action will be created. The UTN Action can be run by double-clicking the file.
What Do You Want To Do? ’Configuring Messages’ 76 Displaying Status Information The SEH UTN Manager (complete version) is installed on the Requirements client; see: 21. The USB port is shown in the selection list; see: 65.
How to Manage Selection Lists for Several Participants What are Selection The selection list is a central element of the SEH UTN Manager. It Lists? displays all embedded UTN servers as well as the connected USB devices and shows their status. These USB devices can be connected to the client via the port connection and can then be used.
Page 78
Working with the SEH UTN Manager Global Selection List Fig. 13: Global Selection List Properties of the global selection list: • All users of a client use the same selection list. • The users can only access the devices listed in the selection list.
Page 79
’Providing Users with a Predefined Selection List’ 80 ’Protecting the user-specific selection list’ 81 Providing the Global Selection List to All Users The SEH UTN Manager (complete version) is installed on the Requirements client; see: 21. You are logged on to the system as administrator.
Page 80
The setting will be saved. All users of a client use the same selection list. Providing User-Specific Selection Lists The SEH UTN Manager (complete version) is installed on the Requirements client; see: 21. You are logged on to the system as administrator.
Page 81
Protecting the user-specific selection list When using predefined user-specific selection lists we recommend protecting the selection list against modifications by the user. The selection list of a user is stored as 'SEH UTN Manager.ini' file in the following location: %APPDATA%\SEH Computertechnik GmbH\SEH UTN Manager.ini (See: ’User-Specific Selection List’...
Security 6 Security A number of security mechanisms are available to ensure optimum security for the UTN server. This chap- ter describes how to make use of these security mech- anisms. The following security mechanisms can be configured and activated according to your demands: What Information •...
Security How to Define the Encryption Strength for SSL/TLS Connections The following connections to and from the UTN server can be encrypted via SSL/TLS: • Email: POP3 (44) • Email: SMTP (44) • Web access to the myUTN Control Center: HTTPS (85) •...
Page 84
Security Establishing When establishing a secure connection, the protocol to be used and Connections a list of supported cipher suites is sent to the communicating party. A cipher suite is agreed upon that will be used later on. The stron- gest cipher suite that is supported by both parties will be used by default.
Security connection type for the web access to the myUTN Control Center. As current browsers do not support cipher suites of 'Low', a con- nection can then not be established. 5. Click Save to confirm. The setting will be saved. Detailed information about the individual SSL/TLS connection status (e.g.
Security 4. Click Save to confirm. The setting will be saved. How to Control the Access to the myUTN Control Center (User Accounts) You can limit the access to the myUTN Control Center. This is done with the help of user accounts. User Accounts There a two types of user accounts for which a name and password have to be defined.
Security 2. Select SECURITY – Device access. 3. Define the two user accounts. To do this, in the area User accounts enter a User name and Password respectively. (You can show the typing if you want to make sure that there are no typing errors in the password.) 4.
Page 88
Security • The use of wildcards (*) allows you to define subnetworks. Test Mode The 'test mode' allows you to check the configured access protec- tion. If the test mode is activated, access protection remains active until the UTN server is rebooted. After restarting, the protection is no longer effective.
Neither the USB port nor the connected USB device will be displayed in the SEH UTN Manager. This means that a user will not be able to make changes to the port or to establish a connection between the client and the USB port.
Page 90
In order for a user to gain access to a USB device that is protected by means of the USB port key control, an appropriate key must be entered on the client via the SEH UTN Manager. Proceed as follows: 1.
Page 91
Security Specifying the Device Assignment on the USB Port To prevent manipulations by switching the USB devices on the UTN server, you can permanently assign USB devices to the USB ports. Proceed as follows: 1. Start the myUTN Control Center. 2.
Security How to Block USB Device Types USB devices are grouped into classes according to their function. For example, input devices such as keyboards belong to the group 'Human Interface Device' (HID). USB devices may present themselves as HID class USB devices but actually are used for abuse (known as 'BadUSB').
Security How to Use Certificates Correctly The UTN server has its own certificate management. This section explains how certificates are used and when the use of certificates is recommended. What are Certificates can be used in TCP/IP-based networks to encrypt data Certificates? and to authenticate communication partners.
Page 94
Security • CA certificates are certificates that have been issued for a certi- fication authority (CA). They are used for verifying certificates that have been issued by the respective certification authority. • S/MIME certificates (*.pem file) are used to sign and encrypt the emails that are sent by the UTN server.
Page 95
Security ’Displaying Certificates’ 95 What Do You Want To Do? ’Creating a Self-Signed Certificate’ 95 ’Creating a Certificate Request for a Requested Certificate’ 97 ’Installing the Requested Certificate in the UTN Server’ 97 ’Installing the PKCS#12 Certificate in the UTN Server’ 98 ...
Page 96
Security 5. Click Create/Install. The certificate will be created and installed. This may take a few minutes. Table 13: Parameters for the Creation of Certificates Parameters Description Common name Is used to clearly identify the certificate. It is advisable to use the IP address or the host name of the UTN server to allow a clear assignment of the certificate to the UTN server.
Page 97
Security Creating a Certificate Request for a Requested Certificate As preparation for using a certificate which is issued by a certifica- tion authority for the UTN server, a certificate request can be cre- ated in the UTN server. The request must be sent to the certification authority which creates an certificate on the basis of this request.
Page 98
Security 4. Click Browse. 5. Specify the requested certificate. 6. Click Install. The requested certificate will be installed in the UTN server. Installing the PKCS#12 Certificate in the UTN Server Certificates with the PKCS#12 format are used to save private keys and their respective certificates and to protect them by means of a password.
Page 99
Security Proceed as follows: 1. Start the myUTN Control Center. 2. Select SECURITY – Certificates. 3. Click S/MIME certificate. 4. Click Browse. 5. Specify the S/MIME certificate. 6. Click Install. The S/MIME certificate is saved in the UTN server. Installing the CA Certificate in the UTN Server In order to check the identity of the communicating parties of the UTN server, it is necessary to validate their certificates.
Page 100
Security Deleting Certificates Do not delete the certificate (CA/self-signed/PKCS#12) if only HTTPS is defined as the permitted connection type for the web access to the myUTN Control Center. If the corresponding certifi- cate is deleted, the myUTN Control Center can no longer be reached.
Security How to Use Authentication Methods By means of an authentication, a network can be protected against unauthorized access. The UTN server can participate in various authentication procedures. This section describes which procedures are supported and how these procedures are configured on the UTN server.
Page 102
Security Configuring EAP-MD5 Benefits and EAP-MD5 validates the identity of devices or users before they gain Purpose access to network resources. You can configure the UTN server for the EAP-MD5 network authentication. This ensures that the UTN server gets access to protected networks. Mode of Operation EAP-MD5 describes a user-based authentication method via a RADIUS server.
Page 103
Security validate the certificate. After the mutual authentication was suc- cessful, the access to the network will be freed. Since each device needs a certificate, a PKI (Public Key Infrastruc- ture) must be available. User passwords are not necessary. If you want to use the EAP-TLS authentication, you must observe the instructions below in the indicated order.
Page 104
Security tion. This ensures that the UTN server gets access to protected net- works. Mode of Operation EAP-TTLS consists of two phases: • In phase 1, a TLS-encrypted channel between the UTN server and the RADIUS server will be established. Only the RADIUS server authenticates itself using a certificate that was signed by a CA.
Page 105
Security Configuring PEAP Benefits and PEAP (Protected Extensible Authentication Protocol) validates the Purpose identity of devices or users before they gain access to network resources. You can configure the UTN server for the PEAP network authentication. This ensures that the UTN server gets access to pro- tected networks.
Page 106
Security 7. Click Save & Restart to confirm. The settings are saved. Configuring EAP-FAST Benefits and EAP-FAST (Flexible Authentication via Secure Tunneling) validates Purpose the identity of devices or users before they gain access to network resources. You can configure the UTN server for the EAP-FAST net- work authentication.
Page 107
Security The UTN server is defined as user (with user name and password) Requirements on a RADIUS server. Proceed as follows: 1. Start the myUTN Control Center. 2. Select SECURITY – Authentication. 3. Select FAST from the Authentication method list. 4.
Security How to Encrypt Data Transfer You can encrypt the data transfer between the clients and the UTN server (and the connected USB devices). Only payload will be encrypted. Control and log data will be trans- mitted without encryption. Encrypted connection means that client and UTN server communi- cate via the UTN SSL port.
Page 109
Security The encrypted connection will be displayed client-side in the SEH UTN Manager under 'Properties'. Fig. 17: SEH UTN Manager - Encryption myUTN User Manual Windows...
Maintenance 7 Maintenance Various maintenance activities can be carried out on the UTN server. This chapter contains information on securing and resetting the parameter values. You will also learn how to carry out a restart and a device update. •...
Page 111
Maintenance Upon delivery, the SD card is already inserted into the SD card reader and ready for use (installation or formatting are not required). By means of the backup, the whole configuration can be quickly and easily loaded to other UTN servers (e.g. when exchanging a UTN server).
Page 112
Maintenance 3. Click the icon The current parameter values are displayed. 4. Save the '<default name>_parameters.txt' file on a local system with the help of your browser. The parameter file is copied and secured. Loading the Parameter file onto the UTN Server Proceed as follows: 1.
Maintenance How to Reset the UTN Parameters to their Default Values It is possible to reset the UTN Server’s parameters to the default val- ues (factory settings). All previously configured parameter values will be deleted in this process. Installed certificates will not be deleted.
Page 114
Maintenance 2. Select MAINTENANCE – Default settings. 3. Click Default settings. A security query appears. 4. Confirm the security query. The parameters are reset. Resetting the Parameters via the InterCon-NetTool Proceed as follows: 1. Start the InterCon-NetTool. 2. Select the UTN server from the device list. 3.
Recommended? and if a new software or firmware version with new functions or bug fixes has been released by SEH Computertechnik GmbH. Check the installed software and firmware version on the UTN server. You will find the version number on the myUTN Control Cen- ter 'START' page or in the product list in the InterCon-NetTool.
Maintenance How to Restart the UTN Server The UTN server will automatically restart after changes to the parameters or after an update. If the UTN server is in an undefined state, it can also be manually restarted. ’Restarting the UTN Server via the myUTN Control Center’ What Do You Want 116 To Do?
SEH UTN Manager The software tool SEH UTN Manager handles the access of the USB devices. The software is installed on all clients that are meant to access a USB device in the network. The SEH UTN Manager shows...
Page 119
00-c0-eb-00-01-ff Manufactu Device number The hardware address can be found on the housing, in the SEH UTN Manager or in the InterCon-NetTool. The use of separators within the hardware address depends on the platform. In Windows '-' are used. IP Address The IP address is the unique address of each node in a network, i.e.
Page 120
USB devices. If a compound USB device is connected to a USB port of the UTN server, in the myUTN Control Center and the selection list of the SEH UTN Manager all integrated USB devices will be displayed on the USB port.
Appendix - Parameter List Parameter List This chapter gives an overview of all available parameters of the UTN server. The parameter list gives details about the functions and val- ues of the individual parameters. • ’Parameter List - IPv4’ 122 What Information Do You Need? •...
Page 122
Appendix - Parameter List Table 14: Parameter List - IPv4 Parameters Value Default Description ip_addr valid IP address 169.254. Specifies the IP address of the [IP address] 0.0/16 UTN server. ip_mask valid IP address 255.255. Specifies the subnet mask of [Subnet mask] the UTN server.
Page 123
Appendix - Parameter List Parameters Value Default Description ipv4vlan_on_1 on/off Enables/disables the forwarding of IPv4 client ipv4vlan_on_20 VLAN data. [VLAN] ipv4vlan_addr_1 valid IP address 192.168. Specifies the IP address of the UTN server within the IPv4 ipv4vlan_addr_20 client VLAN. [IP address] ipv4vlan_mask_1 valid IP address 255.255.
Page 124
Appendix - Parameter List Parameters Value Default Description ipv6_gate n:n:n:n:n:n:n:n Defines the IPv6 unicast [Router] address of the router. The UTN server sends its 'Router Solicitations' (RS) to this router. ipv6_plen 0–64 Defines the length of the sub- [Prefix length] [1–2 characters;...
Page 125
Appendix - Parameter List Table 18: Parameter List - SSL Connections Parameters Value Default Description sslmethod tls10 Defines the encryption [Encryption sslv3 protocol to be used for protocol] tls10 SSL/TLS connections. tls11 sslv3 = SSL 3.0 tls12 tls10 = TLS 1.0 tls11 = TLS 1.1 tls12 = TLS 1.2 Do not use the encryption...
Page 126
Appendix - Parameter List Parameters Value Default Description sessKeys on/off Enables/disables the myUTN [Restrict Control Control Center access restric- Center access] tion. If access is restricted, a login screen is displayed when opening the myUTN Control Center. Note: If access is restricted, user accounts must be defined.
Page 127
Appendix - Parameter List Table 20: Parameter List – USB device type blocking Parameters Value Default Description utn_hid on/off De-/activates the blocking of [Disable input input devices (HID - human devices (HID interface devices). class)] on = no blocking off = blocking Table 21: Parameter List - TCP port access Parameters...
Page 128
Appendix - Parameter List Parameters Value Default Description hw_filter_1 valid hardware 00:00:00: Defines elements that are address 00:00:00 excluded from port locking, hw_filter_8 using the hardware address. [MAC address] Table 22: Parameter List - UTN port Parameters Value Default Description utn_port 1–9200 9200...
Page 129
Default Description utn_heartbeat 1–1800 This parameter can only be [1–4 characters; 0–9] used after consultation with the SEH support team. utn_accctrt_1 [---] Specifies methods for limiting the access and use of the USB utn_accctrt_20 port and the connected USB [Method] keyids device.
Page 130
= power off utn_poffdura_1 0–100 This parameter can only be [1–3 characters; 0–9] used after consultation with utn_poffdura_20 the SEH support team. utn_prereset_1 on/off This parameter can only be used after consultation with utn_prereset_20 the SEH support team. Table 26:...
Page 131
Appendix - Parameter List Table 27: Parameter List - SNMP Parameters Value Default Description snmpv1 on/off Enables/disables SNMPv1. [SNMPv1] snmpv1_ronly on/off Enables/disables the write [Read-only] protection for the community. snmpv1_community max. 64 characters public Defines the name of the [Community] [a–z, A–Z, 0–9] SNMP community.
Page 132
Appendix - Parameter List Table 28: Parameter List - Date/Time Parameters Value Default Description on/off Enables/disables the use of a [Date/Time] time server (SNTP). ntp_server max. 64 characters pool.ntp. Defines a time server via the [Time server] [a–z, A–Z, 0–9] IP address or the host name.
Page 133
Appendix - Parameter List Table 30: Parameter List - Authentication Parameters Value Default Description auth_typ --- [None] ---- Defines the authentication [Authentication method that is used to identify method] devices or users in the net- TTLS work. PEAP FAST auth_name max.
Page 134
Appendix - Parameter List Table 31: Parameter List - POP3 (only myUTN-80 and later) Parameters Value Default Description pop3 on/off Enables/disables the POP3 [POP3] functionality. pop3_srv max. 128 characters [blank] Defines the POP3 server via [Server name] the IP address or the host name.
Page 135
Appendix - Parameter List Table 32: Parameter List - SMTP (only myUTN-80 and later) Parameters Value Default Description smtp_srv max. 128 characters [blank] Defines the SMTP server via [Server name] the IP address or the host name. The host name can only be used if a DNS server was configured beforehand.
Page 136
Appendix - Parameter List Table 33: Parameter List - Notification (only myUTN-80 and later) Parameters Value Default Description trapto_1 valid IP address 0.0.0.0 Defines the SNMP trap trapto_2 address of the recipient. [Address] trapcommu_1 max. 64 characters public Defines the SNMP trap trapcommu_2 [a–z, A–Z, 0–9] community of the recipient.
Page 137
Appendix - Parameter List Parameters Value Default Description noti_dev_1 on/off Enables/disables the sending noti_dev_2 of emails after a USB device [Send email if was connected to/removed USB devices are from the UTN server. connected or disconnected] noti_act_1 on/off Enables/disables the sending noti_act_2 of emails after a USB port was [Send email if...
Page 138
Appendix - Parameter List Parameters Value Default Description notistat_h 1 = 1. hour Specifies the time at which a [hh] 2 = 2. hour status email is sent. 3 = 3. hour etc. notistat_tm 0 = 00 min Specifies the time at which a [mm] 1 = 10 min status email is sent.
Page 139
Appendix - Parameter List Table 35: Parameter List - Acoustic signal (only myUTN-800) Parameters Value Default Description beepPwr on/off Enables/disables the acoustic [Only one power signal that sounds if the UTN supply provides server only is supplied by one power] power supply.
Appendix - Information Shown in the Display Panel (myUTN-800 only) Information Shown in the Display Panel (myUTN-800 only) The Dongleserver myUTN-800 has a display panel at its front side. It provides status information (error states). Text Description Troubleshooting The Dongleserver is operational. (identifier 51) The Dongleserver is restarting.
Appendix - SEH UTN Manager - Function Overview SEH UTN Manager - Function Overview Functions in the SEH UTN Manager can be shown as inactive (grayed out) or not shown at all. This depends on the following factors: • Settings of the selection list mode (global list / user list) •...
Page 142
Appendix - SEH UTN Manager - Function Overview Table 37: SEH UTN Manager - Function Overview Windows Global Selection User-Specific Selection List List Adminis Adminis User User trative trative (rw) rights User rights (INI) (INI) Menu Selection List – Edit ...
This chapter describes some problems and their solutions. • ’The UTN server signalizes the BIOS mode’ 143 Problem • ’Some functions in the SEH UTN Manager are hidden, enabled or appear dimmed’ 144 • ’USB devices are not shown in the SEH UTN Manager’ 145 •...
Page 144
The software will be saved in the UTN server. The UTN server switches to the normal mode. Some functions in the SEH UTN Manager are hidden, enabled or appear dimmed Your user account does not have the required administrative Possible Cause rights.
Page 145
USB devices are not shown in the SEH UTN Manager Eliminate possible error sources. Check first if the USB device is con- nected to the UTN server. The SEH UTN Manager and the firmware/software on the UTN Possible Cause server are incompatible. Update the SEH UTN Manager (28) and the firmware/software (115).
Page 146
A connection to the UTN server cannot be established A common port will be used for the data transfer between the UTN server and the SEH UTN Manager that is installed on the client. 52. The port numbers are not identical.
Page 147
Appendix - Troubleshooting The cipher suites of the encryption level are not supported by the browser 80. Password and/or user name is no longer available Access to the myUTN Control Center can be restricted. If the pass- word and/or user name is no longer available, you can reset the parameter values of the UTN server to their default settings to get access 111.
The additional tool 'utnm' has been developed for the myUTN prod- ucts of SEH Computertechnik GmbH. It is used for the activation and deactivation of USB ports including connected USB devices. In order to activate or deactivate a USB port with utnm, commands are entered and run in a special syntax in the command-line inter- face of the operating system.
Page 149
Syntax and Note the following syntax: Commands "<path utnm.exe>" /c "command string" [/<command>] The file 'utnm.exe' can be found in the program folder of the SEH UTN Manager. myUTN User Manual Windows...
Page 150
Appendix - Additional Tool 'utnm' The following commands are supported: Command Description Runs a command. The command is specified in greater /c "command string" detail by the command string. The following command strings can be used: • activate UTN server port number Activates the connection to a USB port and the /command "command connected USB device.
Page 151
Appendix - Additional Tool 'utnm' Command Description Specifies a USB port key. /k USB port key In the course of the port key control a key is specified for the USB port via the myUTN Control Center so that the /key USB port key USB device that is connected to the USB port is protected against unwanted access (86).
The port key is too long. Example A USB device is to be activated. Commands and syntax: "<path utnm.exe>" /c "activate UTN server port number" Results in: "C:\Program Files\SEH Computertechnik GmbH\SEH UTN Manager\ utnm.exe" /c "activate 192.168.0.140 4" myUTN User Manual Windows...
Appendix - Index Index Installation 97 Certificate request 97 Certificates Delete 100 Acoustic Signals 58 Channel 49 Ad hoc mode 49 Cipher Suite 83 Address Command-line interface 148 Hardware address 119 Communication mode 49 IP address 119 Complete version 22 MAC address 119 Compound USB device 66 ARP/PING 17...
Need help?
Do you have a question about the myUTN-50a and is the answer not in the manual?
Questions and answers