Page 2
The contents of this manual may be changed due to product version upgrade or other reasons. InHand reserves the right to modify the contents of this manual without any notice or prompt. This manual is only used as the guidance.
Preface Welcome to the IG601 series industrial gateway user manual. This manual will guide you on how to configure the IG601. This preface includes the following contents: Intended Users Conventions in the Manual Obtaining Documentation Technical Support ...
Page 4
Support >> Software Download: Software updates, webinars and technical papers are available for download. Technical Support InHand is invested in supporting our products with fast and reliable customer service. Feel free to email. E-mail: support@inhandneworks.com Website: www.inhandnetworks.com Feedback If you have any comments or questions on your products, please send us feedback via email.
Contents Preface ..............................3 IG601 Introduction ..........................7 1.1 Overview ..........................7 1.2 Product Features ........................7 Login Gateway ........................... 9 2.1 Establish Network Connection ....................9 2.1.1 Automatic acquisition of IP address ................9 2.1.2 Set a static IP address ....................12 2.2 Test the network connection between the supervisory PC and InGateway.
Page 6
3.5.5 DMZ (All Port Mapping) ................... 58 3.5.6 MAC-IP Bundling ...................... 59 3.6 QoS ............................60 3.6.1 Bandwidth Control ..................... 60 3.6.2 IP Bandwidth Limit ....................61 3.7 Tools ............................ 62 3.7.1 Ping ........................... 62 3.7.2 Trace Route ........................ 63 3.7.3 Link Speed Test ......................
The IG601 supports both communications via the PLCs Ethernet port and via the serial port. IG601 also supports status queries, PLC controls and alarm message via SMS. The IG601 series utilizes the ubiquitous cellular network to the fullest and opens new horizons in remote management and machine to machine communication.
Page 8
3G/2G network. Users can check PLC’s operation and alarm messages anywhere via internet. Industrial Design In the aspects of EMC, anti-static grade, anti-surge level and wide temperature range, IG601 meet the requirements of industrial and operate easily under harsh environments. Metal enclosure. IP30.
Login Gateway This chapter covers the following: Establish Network Connection Test the connection between supervisory PC and InGateway Cancel the Proxy Server 2.1 Establish Network Connection 2.1.1 Automatic acquisition of IP address “ ” “ Please set the supervisory PC to automatic acquisition of IP address automatic acquisition of ”...
Page 10
Local Connection Properties”, as shown below. “ Click <Properties> to enter the window 10 / 92...
Page 11
Select “Internet Protocol Version 4 (TCP/IPv4).” Click <Properties> to enter “Internet Protocol Version 4(TCP/IPv4) Properties.” Select “Obtain an IP address automatically” and “Obtain DNS Server address automatically,” then click <OK> to complete the process, as shown below. 11 / 92...
2.1.2 Set a static IP address Please set the supervisory PC’s IP address in the same subnet as the gateway FE (or fast Ethernet) port. In this example, the default IP address of gateway FE port is 192.168.2.1, and the subnet mask is 255.255.255.0.
2.2 Test the network connection between the supervisory PC and InGateway. Click the button <Start> at the lower left corner. Type “cmd” into the field, and run cmd.exe. 批注 [Unknown A1]: More inconsistent font. 13 / 92...
Page 14
Enter “ping 192.168.2.1” and click the <OK> button. (192.168.2.1 is the default IP address of the InGateway). If the connection is good, you will see four returned packets. If there is no response, be sure to check your connection and your supervisory PC's network settings. 14 / 92...
2.3 Disconnect from the Proxy Server. If the supervisory PC uses a proxy server to access the Internet, it is necessary to disconnect from the proxy and remove any proxy settings. The operating steps are as follows: Open Internet Explorer. ...
Page 16
Select the tab “Connect” and click the button <LAN Setting(L)> to enter the window “LAN Setting.” If the option “Use a Proxy Server for LAN” is checked, uncheck it. Click the <OK> button and continue to the web configuration section of the manual. 16 / 92...
批注 [Unknown A2]: This section seems like it has been Web Configuration localized already. It only needed light editing. This chapter covers the following contents: 17 / 92...
Logging in the Browser Interface System Network Service Firewall QoS Tools Status 3.1 Login the Web Configuration Page of Gateway Run the Web browser, enter “http://192.168.2.1” in the address bar, and press Enter to skip to the Web login page, as shown below.
Click <Sync Time> to synchronize the gateway's clock with the system time of the host. For security, it is highly recommended that you modify the default password after your first login. Store the password information in a secure location. 3.2 System The system configuration process involves nine steps: •...
3.2.1 Basic Setup From the navigation panel, select System >> Basic Setup, then enter the “Basic Setup” page, as 批注 [Unknown A3]: This is inconsistent with the previous part of the document, but it actually is much shown below. cleaner looking. Page description is shown below: Parameters Description...
The terms are explained below: Parameters Description Default : : Gateway Time Display the system time of Gateway 2000-01-01 08 PC Time The current time of supervisory PC Timezone Set time zone Custom Custom TZ String Set the time zone of the Gateway CST-8 Auto update Time Time Update Interval...
Page description is shown below: Parameters Description Default Baud Rate Serial baud rate 115200 Data Bit Serial data bits Parity Set parity bit of serial data None Stop Bit Set stop bit of serial data Software Flow Control Enable Software Flow Control Disable Mode Select serial type...
Page 23
TELNET Telnet protocol provides telnet and virtual terminal functions through a network. The device supports both a client mode and a server mode. In client mode, the telnet client sends request to the telnet server, creating a session. While in server mode, the device supports Telnet connections for incoming clients, allowing for remote access.
Page 24
New Password Input new password. Confirm New Input the new password again. Password Management:HTTP/HTTPS/TELNET/Console Enable Select to enable HTTP. Enabled Service Port Select management port. 80/443/23/N/A Local Access Enable—allow management of Enabled the IG601 over the local network, 24 / 92...
However, these accounts will be non-privileged, meaning the new users cannot create new username. A non-privileged account may only do web logins. In “Non-privileged Users” section, we can create multiple usernames. Technicians can utilize multiple usernames while logging on a IG601 via serial port or Telnet. 3.2.5 System Log A remote log server can be set through “System Log Settings,”...
Kiwi Syslog Daemon is free log server software for Windows, which can receive, record and display logs from host (such as gateway, exchange board and Unix host). After downloading and installing Kiwi Syslog Daemon, it mus be configured through the menus “File >> Setup >> Input >> UDP.” From the navigation panel, select System >>...
Page 27
Parameters Description Default Gateway Import/Backup configuration Configuration Restore default Click to reset IG601. To complete the reset, configuration users need to reboot the IG601. Network Provider The technician must configure the local APN, username, password, and other configs the (ISP) same as their ISP.
3.2.7 System Upgrade From the navigation panel, select System >> Upgrade, then enter the “Upgrade” page, as shown below. To upgrade the system, click the System, tab then <System upgrade> to enter upgrade page, then follow the steps below: Step one: Click <Browse> choose the upgrade file, and then click <Open>, as shown below: Step Two: Click <Update>...
Step Three: Upgrade firmware succeed, and click <Reboot> to restart the IG601. 3.2.8 Reboot If users need to reboot system, please click the System tab, then <Reboot> and click <OK> to restart the system. 3.2.9 Logout If users want to logout, click System >> Logout, and then click <OK>.
This section covers network settings include Dialup/Cellular, LAN, DNS, DDNS, and Static Routes. 3.3.1 Dialup/Cellular Connection With following configuration, IG601 can access the internet through the wireless cellular network. From the navigation panel, select Network >> Dialup, then enter the “Dialup” tab, as shown below.
Page 32
Terminology is listed below: Parameters Description Default Basic Config Enable Enable PPP dialup. Enable Time Schedule Select timetable for online and offline. We need defined timetable through “Schedule Management” in advance. Enabled—enable “NAT,” or network SHARED Enable address translation. Local addresses can be translated to global WAN address on a one-to-many basis.
Page 33
Advanced Options Initial Commands Used for advanced parameters. PIN code Set the use of the SIM card PIN code. Dial Timeout Set dialup timeout. The IG601 will 120 seconds reboot after timeout. Set max transmit unit, or max frame 1500 size.
noccp. ICMP Detection Set the ICMP Detection Server. Blank Blank Server represents none. ICMP Detection Set the ICMP Detection Interval. 30 seconds Interval ICMP Detection Set ICMP Detection Timeout (IR6X1 20 seconds Timeout will reboot if ICMP time out) ICMP Detection Set the max number of retries if ICMP Max Retries failed...
The settings are explained below: Parameters Description Default MAC Address The host MAC address in LAN, which is provided 00:18:05:15:11:8D by the manufacturers. IP Address Set the IP Address in LAN 192.168.2.1 Net mask Set the subnet mask of a local network. 255.255.255.0 Set MTU length options to either Default or 1500...
internet, so that instead of memorizing IP numbers, people can use words to make domain-names. The device supports the following two functions through the domain name configuration service: DNS Server: the device can function as a local DNS Server. ...
Page 37
Page description is shown below: Parameters Description Default Current Show the current IP address Blank Address Service Type Select DDNS Provider Disabled Automatically generate, users do not http://www.3322.org/ need to set Username Registered username for DDNS Password Registered password for DDNS Hostname Registered hostname for DDNS Wildcard...
Whether to update the mailbox record Backup MX Whether to update the mailbox record Disabled Force Update Force update records after modifying Disabled the settings 3.3.5 Static Routes Static routes are created manually and have many different uses. After the static route is set, packets will be transferred to appointed routes.
3.4 Service In the service section, this manual covers nine configurations, including DHCP service, DNS relay, VRRP, Device Manager, DTU, Modbus to SMS, SMS alarm rules, and Mbsms variable template. 3.4.1 DHCP Service DHCP (Dynamic Host Configuration Protocol) is a network protocol for LAN utilizing UDP and TCP. DHCP automatically distributes IP addresses for either a local network or network service provider, and can aid network administrators in managing all the computers on a network.
The page is described below: Parameters Description Default Enable DHCP Check to enable DHCP. Enable IP Pool Set the starting IP address of DHCP 192.168.2.2 Starting pool. Address IP Pool Ending Set the ending IP address of DHCP 192.168.2.100 Address pool.
The page description is shown below: Parameters Description Default IP Address Map an IP to a hostname. Host Set the name of DNS entries. Description Describe DNS entry. When enabling DHCP, the DHCP relay is also enabled automatically. Relay cannot be disabled without disabling DHCP. While using dynamic DNS, the DNS relay service should be turned on.
Select to enable. Disable Monitor Select WAN to start monitoring None WAN interface traffic; select None do not monitor. 3.4.4 Device Manager The device manager, or DM, is the InHand intelligent cloud platform for network management service. 42 / 92...
Page 43
You can remotely manage your IG601, find the current status and so on. To configure the device manager, go to the navigation panel, select Services >> Device Manager, then enter “Device Manager” page, as shown below. Terms are described below:...
Set a trusted cell phone list. 3.4.5 DTU If you connect a serial device to IG601, you need enable the DTU converter. IG601 can support a multi-protocol uplink to allow conversion of serial data and IP data. Users must select the correct serial mode on the window “Serial Port”...
Page 45
The page is described below: Parameters Description Default Enable Check to enable the DTU. Disable DTU Protocol Set the DTU protocol. Please see more in related Transparent Quick Guide. Protocol TCP and UDP are both options. Mode Set the DTU as a client or server. Client Frame Interval Set the frame interval.
To enable SMS, find the navigation panel, select Services >> Modbus to SMS to enter into the “Modbus to SMS” page. After you add your PLC here, the daemon of IG601 periodically queries the PLC variables and cache to memory.
Page 47
The variable address will be replaced by variable name in SMS. PLC ID in IG601 cannot be repeated, neither can PLC names. Variable names cannot be repeated in one PLC variable list.
The IG601 will collect different variables depending on the alarm rules set by the user. When a variable matches the rules, IG601 will send an SMS alarm to all users on the “alarm user list”. IG601 can also send user-defined SMS to designated users.
Page 49
The IG601 performs an action corresponding to different commands and then sends a response to the SMS user. Users can send SMS to IG601 via mobile phone or SMS modem. Two types of SMS formats and response message are as follows:...
Page 50
perameter commands. By entering multiple registers, multiple variables can be found at the same time. Different PLCs are separated by comma. Request Response Message Description ALARM Alarm total: 55, #53 date-time Find a count of historical context1, #54 date-time alarm records and return context2, #55 date-time context3 the latest three historical alarms.
Page 51
ALARM CLEAN xx- Delete xx-xx alarm Delete the historical records SUCCESS within the a range. WHITELIST ON|OFF WHITELIST ON|OFF Start or stop using a white list. ADD 13812345678 ADD 13812345678 OK Add users to the alarm list. DELETE DELETE 13812345678 Delete users on an alarm list.
Page 52
example, temperature >= 200 means that when the temperature is greater than or equal to 200, an alarm will be sent. Define the relationship between the first expression and the second expression in the fifth column by selecting OR, AND or XOR. ...
3.4.8 Mbsms Variable Template Users can download a PLC variable template file which you might have added in section 3.3 “Modbus to SMS.” A template file is composed of all the variables in a PLC, and the IG601 supports up to eight templates.
A firewall is necessary for blocking out malicious packets from the internet. On today's internet, security is more important than ever, which is why the IG601 is well equipped to protecting the local network and provide a security barrier from external threats.
config page, as shown below. The page description is shown below: Parameters Description Default Choose to either “Accept” or Default Filter Policy Accept “Block” filtering. Block Anonymous Check to deny anonymous ICMP Disable Request (ping) ping requests. Filter Multicast Check to filter multicast packets. Enable Defend DoS Attack Select to enable DoS attack...
Describe your configuration. 3.5.3 Port Mapping The IG601 support Network Address and Port Translation. It allows remote computers (for example, computers on the Internet) to connect to the local device that linked to LAN interface. To configure port mapping, go into the navigation panel, select Firewall >> Port Mapping, then enter “Port Mapping”...
Page description is shown below: Parameters Description Default Enable Check enable port Enable mapping. Protocol Select either TCP or UDP. Source Set an external source IP. 0.0.0.0/0 Service Port Set the external port of 8080 service. Internal Address internal Blank mapping.
Page description is shown below: Parameters Description Default Virtual IP for Gateway Set a virtual IP for the Blank InGateway. Source IP Range Set range of the external Blank source IP addresses. Virtual IP Set an external virtual IP. Blank Real IP Set a real IP.
Set a range of restricted Blank source IP addresses. The IG601's management port should never be mapped to a DMZ. 3.5.6 MAC-IP Bundling When a firewall denies all access to the external network, only a PC with MAC-IP bundling can access the internet.
The page description is shown below: Parameters Description Default MAC Address Set the bundling PC's 00:00:00:00:00:00 mac address. IP Address Set the bundling PC's 192.168.2.2 IP address. Description Describe this Blank configuration. 3.6 QoS This chapter covers QoS, or Quality of Service. QoS is a set of services that ensures bandwidth availability for sensitive applications.
The page description is shown below: Parameters Description Default Enable Check to enable. Disable Outbound Limit Max Set the maximum upload rate. 100000kbit/s Bandwidth Inbound Limit Max Set the download bandwidth limit. 100000kbit/s Bandwidth 3.6.2 IP Bandwidth Limit Technicians may limit the bandwidth on individual hosts and devices by setting IP based bandwidth limits.
Priority Set the priority. Medium Description Describe the configuration. 3.7 Tools The IG601 comes with several tools to help admins diagnose network problems, including: • Ping • Trace route • Link Speed Test 3.7.1 Ping Ping a tool many technicians are familiar with. It simply sends ICMP packets across the network to a remote host, and then retransmits an ICMP packet back to the original sender.
Page description is shown below: Parameters Description Default Host Destination IP for the ping. Ping Count Number of pings sent. 4 times Packet Size The size of the ping packet sent. 32 Bytes 32B is recommended. Expert Options Advanced parameters 3.7.2 Trace Route The trace route tool sends an ICMP or UDP packet to a remote host.
Advanced parameters 3.7.3 Link Speed Test The IG601 uses a simple upload and download to test the link speed. To start the speed test, enter the navigation panel, select Tools>>Link Speed Test, then enter “Link Speed Test” page, as shown below.
3.8 Status The status chapter covers the following: • System • Modem • Network Connections • Routing Table • Device List • ModbusPLC • Event Logs 3.8.1 System From navigation panel, select Status >> System, then enter the “System” page, as shown below. This page displays system statistics, including Name, Model, Current Version, Gateway Time, PC Time, UP Time, CPU Load, Memory Consumption, etc.
3.8.2 Modem From navigation panel, select Status >> Modem, then enter “Modem” page, as shown below. This page shows Modem status, including Signal Level, Register status, etc. 66 / 92...
3.8.3 Network Connections From navigation panel, select Status >> Network Connections, then enter “Network Connections” page, as shown below. This page shows the connection status of Dialup and LAN. 67 / 92...
3.8.4 Route Table From navigation panel, select Status >> Route Table, then enter “Route Table” page, as shown below. This page shows the route table of IG601. 68 / 92...
3.8.6 Modbus PLC From navigation panel, select Status >> Modbus PLC, then enter “Modbus PLC” page, as shown below. This page shows the parameters of Modbus PLC linked with IG601. 3.8.7 Log From navigation panel, select Status >> Log, then enter “Log” page, as shown below. This page show system log, including Download Log File.
3.9 VPN VPN is a new technology that rapidly developed in recent years with the extensive application of Internet. It is for building a private dedicated network on a public network. 'Virtuality" mainly refers to that the network is a logical network. Two Basic Features of VPN: ...
Fundamental Principle of VPN The fundamental principle of VPN indicates to enclose VPN message into tunnel with tunneling technology and to establish a private data transmission channel utilizing VPN Backbone so as to realize the transparent message transmission. Tunneling technology encloses the other protocol message with one protocol. Also, encapsulation protocol itself can be enclosed or carried by other encapsulation protocols.
Page 72
Page description is shown below: Parameters Description Default Show Advanced Options Advanced Options Disable Basic Parameters Tunnel Name IPSec_tunnel_ Name the tunnel Destination Address Set the destination address of 0.0.0.0 IPSec VPN server Startup Modes Auto Activated/Triggered by Auto Data/Passive/Manually Activated Activated Restart WAN when failed Click to enable...
Page 73
Advanced Options) authenticity of data packet from hacker intercepting data packet or inserting false data packet on the internet. ESP: encrypt the user data needing protection, and then enclose into IP packet for the purpose of confidentiality of data. Tunnel Mode: besides source host and destination host, special gateway will be operated with password to ensure the safety...
end can not receive IPSec cryptographic message sent by peer end within interval of triggering DPD, receiving end can make DPD check, send request message to opposite end automatically, detect whether IKE peer pair exists. Receiving end will make DPD check and send request message automatically to opposite end for DPD Timeout...
Remote Netmask Set remote netmask 255.255.255.0 Set tunnel key Click to enable NAT Disable Description Add description 3.9.3 L2TP Client From navigation panel, select VPN>>L2TP, then enter “L2TP Clients” page, click <Add> and enter “Edit L2TP Tunnel” page, as shown below. Page description is shown below: Parameters Description...
Authentication Type CHAP or PAP CHAP Enable Challenge secrets Click to enable Disable Local IP Address Set local IP address Remote IP Address Set remote IP address Remote Subnet Set remote subnet Remote Netmask Set remote netmask 255.255.255.0 Link Detection Interval Set link detection interval Max Retries for Link Set the max number of retries...
1500 byte Enable Debug Click to enable Expert Options For InHand R&D team 3.9.5 OpenVPN 3.9.5.1 OpenVPN From navigation panel, select VPN>>OpenVPN, then enter “OpenVPN Tunnels” page, click <Add> and enter “Edit OpenVPN Tunnel” page, as shown below. 77 / 92...
Page 78
Page description is shown below: Parameters Description Default Tunnel name Set tunnel name OpenVPN_T_1 Enable Click to enable Enable Mode Client or Server Client Protocol Same with the protocol of remote server Port Input port 1194 OPENVPN Server Input remote server IP address Authentication Type Select type None...
Interface Type TUN-data packet, TAP-data frame Expert Options For InHand R&D team 3.9.5.2 OpenVPN Advanced From navigation panel, select VPN>>OpenVPN Advanced, then enter “OpenVPN Advanced” page, click <Add> and click <Apply>, as shown below. Page description is shown below: Parameters...
Page 80
Page description is shown below: Parameters Description Default Protect Key Set protect key Protect Key Confirm Confirm protect key Enable SCEP (Simple Click to enable Certificate Enrollment Disable Protocol) SCEP Parameters Force to re-enroll Click to enable Disable Server URL Set sever URL Common Name Set common name...
How to prevent unexpected downtime of automation equipment? How to monitor the operating status of the device? How to reduce engineer's travel for maintenance? InHand Networks, combining market and user’s needs, provides complete remote maintenance solutions for automation equipment. As a gateway, IG601 build a secure channel between remote equipment, device cloud platform and maintenance engineers.
Appendix I FAQ 1, InGateway is powered on, but can`t access Internet through it? Please check: Whether the InGateway is inserted with a SIM card. Whether the SIM card is enabled with data service, whether the service of the SIM card is suspended because of an overdue charge.
Page 83
Please check: When upgrading locally, check if the local PC and InGateway are in the same network segment. When upgrading remotely, please first make sure the InGateway can access Internet. 6, After InGateway establishes VPN with the VPN server, your PC under InGateway can connect to the server, but the center can`t connect to your PC under InGateway? Please make sure the firewall of your computer is disabled.
3. When ERR LED is on, release the RESET button; 4. Within a few seconds, ERR LED should go off; then press and hold the RESET button again; 5. When the ERR LED blinks, release the RESET button; If the ERR LED goes off, that means InGateway601 is now restoring to factory default settings;...
Page 85
: display the current factory serial number of IG601 Description www.inhandnetworks.com Current version : display the current version of IG601 Current version of Bootloader: display the current version of IG601 3.2 show system [Command] show system [Function] display the system information of IG601 [View] all views...
Page 86
3.5 show log [Command] show log [lines <n>] [Function] display the system log of IG601 and display the latest 100 logs in default. [View] all views [Parameter]lines <n> limits the log numbers displayed, wherein, n indicates the latest n logs in case that it is positive integer and indicates the earliest n logs in case that it is negative integer and indicates all the logs in case that it is 0.
Page 87
[Example] enter: show arp Display the ARP list of system 5 Internet Testing Command IG601 has provided ping, telnet and traceroute for internet testing. 5.1 ping [Command]ping <hostname> [count <n>] [size <n>] [source <ip>] [Function] apply ICMP testing for appointed mainframe.
Page 88
6 Configuration Command In super user view, IG601 can use configure command to switch it over configure view for management. Some setting command can support no and default, wherein, no indicates the setting of cancelling some parameter and default indicates the recovery of default setting of some parameter.
Page 89
[Command]clock set <YEAR/MONTH/DAY> [<HH:MM:SS>] [Function] set the date and time of IG601. [View] Configuration view [Parameter]<YEAR/MONTH/DAY> date, format: Y-M-D <HH:MM:SS > time, format: H-M-S [Example] enter clock set 2009-10-5 10:01:02 in configuration view The time of router set is 10:01:02 of Oct. 5 , 2009 morning.
Page 90
7.3 enable password [Command] enable password [<password>] [Function] modify the password of super user. [View] configuration view [Parameter]<password> new super user password [Example] enter enable password in configuration view Enter password according to the reminder. 7.4 username [Command] username <name> [password [<password>]] no username <name>...
Appendix III Description of LED Operation Status: STATUS WARN ERROR Description Green Yellow Power on Blink Power on succeed Blink Blink Dialing Blink Dialing succeed Blink Blink Blink Upgrading Blink Blink Reset Succeed Signal Status: Green LED 1 Green LED 2 Green LED 3 Description No signal detected...
Page 92
MODEM Green LED Description Modem in normal status Modem abnormal 92 / 92...
Need help?
Do you have a question about the IG601 and is the answer not in the manual?
Questions and answers