Table of Contents

Advertisement

Quick Links

SINAUT MD740-1
User Manual

Advertisement

Table of Contents
loading

Summary of Contents for Siemens SINAUT MD740-1

  • Page 1 SINAUT MD740-1 User Manual...
  • Page 2 Warning The power supply unit to supply the SINAUT MD740-1 must comply with NEC Class 2 circuits as outlined in the National Electrical Code (ANSI/NFPA 70) only When connecting to a battery or accumulator, make sure that an all-pole circuit-breaker (main battery switch) with sufficient selectivity and a fuse with sufficient selectivity are provided between the device and the battery or accumulator.
  • Page 3 Antenna: Use only the antenna of the SINAUT TELECONTROL accessory program being released for the SINAUT MD740-1. Other antennas may cause damages and the device will loose official approvals like FCC. Installing antennas: The emission limits as recommended by the Commission on Radiological Protection (13/14 September 2001) must be observed.
  • Page 4 Please note that data packets exchanged for setting up connections, reconnecting, connect attempts (e.g. Server switched off, wrong destination address, etc.) as well as keeping the connection alive are also subject to charge. Product no. 3155 Doc. no. 3155AD001 Rev. 1.1 4 von 105 SINAUT MD740-1...
  • Page 5: Table Of Contents

    (10/100 BASE-T connector).............86 Prerequisites..................86 Making a connection to the SINAUT MD740-1 website ....86 5.3 Accessing the Web Server of the SINAUT MD740-1 from a remote computer via the GPRS network............87 Prerequisites..................87 Making a connection to the SINAUT MD740-1 website ....87 5.4 The website of the SINAUT MD740-1..........88...
  • Page 6 NAT (Network Address Translation) ..........99 Datagram..................99 IPSec .....................100 Spoofing, anti-spoofing ..............100 Symmetrical encryption ..............100 Port number...................100 IP address ..................101 X.509 Certificate ................102 8 Technical Data ....................103 Pin assignment interface Service...........104 Pin assignment interface 10/100 BASE-T........104 6 von 105 SINAUT MD740-1...
  • Page 7: Introduction

    Introduction Introduction The SINAUT MD740-1 serves the following purpose: The device establishes secure IP data connections by radio • via the GPRS (General Packet Radio Service) of a GSM network (Global System for Mobile Communication = mobile radio network). To do so, the device combines the following functions: •...
  • Page 8 The application is connected locally direct to the SINAUT MD740-1: e.g. statement printer, notebook or PC. This application uses the SINAUT MD740-1 in order to have secure access to a remote LAN as if it were connected direct to the LAN.
  • Page 9: To Be Able To Use The Sinaut Md740-1

    IP address of the remote site In order that a SINAUT MD740-1 can actively establish a VPN connection the remote site must have a fixed IP address (an IP address consists of a maximum of 4 numbers, separated by dots, which can each have up to three digits, e.g. 255.122.201.005). With many Internet Service Providers (ISPs), however, the IP addresses are assigned dynamically, i.e.
  • Page 10: The Leds Of The Sinaut Md740-1

    The LEDs of the SINAUT MD740-1 The LEDs of the SINAUT MD740-1 LEDs Power Status LEDs S (Status) Q (Quality) C (Connect) (Status), (Quality), (Connect) Status Meaning S, Q, C Fast lighting in sequence Boot procedure in sequence Slowly lighting in sequence...
  • Page 11: Dc5V, Stat, Linl, Vpn

    VPN tunnel established* VPN-Tunnel not established * Shortly after switching on of the SINAUT MD740-1, the LED VPN is set to on for a short period of time although the VPN tunnel has not yet been established. Cause: self-test of the components during starting procedure of the device.
  • Page 12: Putting The Device Into Operation

    When connecting to Optional: the network use a For the connection of a PC to display UTP cable (CAT 5). device, status and connection information. To connect, use a V.24 cable. Digital gate input Digital gate output 12 von 105 SINAUT MD740-1...
  • Page 13: Switching The Device On/Off

    Putting the device into operation Switching the device on/off The SINAUT MD740-1 switches on as soon as the operating voltage is supplied (see Connecting the device, page 12). The devices switches off when disconnected from the supply voltage. When switching on When the device is switched on the POWER LED comes on first. If the device has a valid configuration and the SIM card is inserted the device automatically books into the GPRS network.
  • Page 14: Configuring The Pin

    Putting the device into operation Configuring the PIN In order for the SINAUT MD740-1 to be able to communicate via the GPRS network of your network operator you must tell the device the PIN (Personal Identification Number) of the SIM card. Then you can insert the SIM card into the device.
  • Page 15: Inserting Or Changing The Sim Card

    Putting the device into operation Inserting or changing the SIM card SINAUT MD740-1 must be switched off when you insert or change the SIM card A plug-in SIM card (3 Volt) is used. 1. Make sure that the device is disconnected from the supply voltage.
  • Page 16 7. Raise the flap of the SIM card holder so that you can insert the SIM card. In the illustration below, the compartment into which you can insert the SIM card is emphasized in white. 16 von 105 SINAUT MD740-1...
  • Page 17 (see illustration). 9. Slide the SIM card down into the flap as far as possible. 10. Lower the flap paying attention to the notched corner of the SIM card (see illustration). SINAUT MD740-1 17 von 105...
  • Page 18 Close the housing by slightly pressing the housing parts together so that the clamps on the upper and lower parts of the housing engage. The housing is locked when all clamps have clicked shut. 18 von 105 SINAUT MD740-1...
  • Page 19: Configuration

    Configuration Configuration ! Remote configuration is possible only if the SINAUT MD740-1 is Remote configured for remote access (see page 64). In this case, configuration proceed exactly as described as from section Establish configuration connection, page 20. • Prerequisites for...
  • Page 20: Establish Configuration Connection

    • the DNS address of the network operator • the local IP address of the SINAUT MD740-1, provided that it is configured to resolve hostnames in IP addresses, see Services menu. To determine the Domain Name Server in the TCP/IP configuration of your network adapter, proceed as described above.
  • Page 21 Under Windows menu Start, Settings, Control Panel, Network Connections / Network and Dial-up Connections right-click on the appropriate icon and select Deactivate in the context menu. • Enter the address of the SINAUT MD740-1 plus slash: https://192.168.1.1/ SINAUT MD740-1 21 von 105...
  • Page 22 5. You are prompted to enter the user name and the password. The default setting is: User name: admin Password: tainy Start page of the 6. Consequence: the Administrator website of the Administrator SINAUT MD740-1 appears - see next page. website 22 von 105 SINAUT MD740-1...
  • Page 23: Perform Configuration

    To do so, click on the Refresh icon in the browser's icon bar. Depending on how you configure the SINAUT MD740-1, you may then have to adapt the network interface of the connected computer or network accordingly.
  • Page 24: Network Menu

    Network # # # # Local Internal IPs An internal IP is the IP address at which the SINAUT MD740-1 can be accessed by devices of the locally connected network. The default setting for the IP address is as follows:...
  • Page 25 Network # # # # GPRS User (user name) Password When the SINAUT MD740-1 logs into the GPRS network it is generally asked for the user name and the password before it is given access to the network. Some GSM/GPRS network operators dispense with access control via user name and/or password.
  • Page 26 PIN of the SIM card inserted in the device When putting the device into In order for the SINAUT MD740-1 to be able to operate with the operation: SIM card of your network operator you must tell the device the PIN (Personal Identification Number) of the SIM card, provided that the 1.
  • Page 27: Firewall Menu

    Configuration Firewall menu The SINAUT MD740-1 comes with a Stateful Packet Inspection Firewall. The connection data of an active connection are collected in a database (connection tracking). This means that rules are only to be defined for one direction, while data from the other direction of a connection, and only these, are allowed through automatically.
  • Page 28 - the event is to be logged - set Log to Yes - or not - set Log to No (default setting) Log entries for unknown connection attempts: This logs all connection attempts which are not recorded by the prevalent rules. 28 von 105 SINAUT MD740-1...
  • Page 29 This lists the fixed firewall rules. These apply to outgoing data packets which belong to GPRS connections initiated by the SINAUT MD740-1 to communicate with a remote site. If no rule is set, all outgoing connections are prohibited (except VPN).
  • Page 30 IP address (or one of the external IP addresses) of the SINAUT MD740-1 and for a particular port of the SINAUT MD740-1 are rewritten in such a way that they are forwarded to the internal network to a particular computer and to a particular port of this computer.
  • Page 31 IP addresses) of the SINAUT MD740-1. Should a dynamic change of the external IP address of the SINAUT MD740-1 take place, so that it cannot be given, use the following variable: %extern. The special value %extern refers to the first IP address in the list when using several static IP addresses for the external interface.
  • Page 32 You can make the following possible entries: From IP 0.0.0.0/0 means all addresses, i.e. all internal IP addresses are subjected to the NAT procedure. To denote a range, use CIDR syntax - see CIDR (Classless InterDomain Routing), page 79. 32 von 105 SINAUT MD740-1...
  • Page 33 "enabled FTP" the called-up server in turn establishes an additional condition to the caller in order to transmit the data via this connection. With "disabled FTP" the client establishes this additional SINAUT MD740-1 33 von 105...
  • Page 34 ICMP from extern to the TAINY With this option you can influence behaviour when receiving ICMP messages which are sent from the external network to the SINAUT MD740-1. You have the following possibilities: Reject: All ICMP messages sent to the SINAUT MD740-1 are rejected.
  • Page 35 The format corresponds to that commonly used under Linux. There are special evaluation programs which present the information from the logged data in a more easily legible format. SINAUT MD740-1 35 von 105...
  • Page 36: Vpn Menu

    If the remote site is behind a NAT router it must support NAT-T. Alternatively, the NAT router must recognise the IPsec protocol (IPsec/VPN Passthrough). In both cases, only IPsec tunnel connections are possible for technical reasons. 36 von 105 SINAUT MD740-1...
  • Page 37 Then click on OK or Apply. Editing a VPN connection Click on the Edit button next to the connection concerned. Perform the desired or necessary settings (see following illustration and explanations). Then click on OK or Apply. SINAUT MD740-1 37 von 105...
  • Page 38 Configuration A descriptive name for the connection You can name or rename the connection as you wish. Enabled Determine whether the connection is to be enabled (= Yes) or not (= No). 38 von 105 SINAUT MD740-1...
  • Page 39 DynDNS service. See IP address of the remote site, page 9. • If the SINAUT MD740-1 is to be ready to accept the connection actively initiated and established by a remote site with any IP address to the local SINAUT MD740-1, then...
  • Page 40 The IP header information is not encrypted. Transport (L2TP Microsoft Windows) If this connection is enabled on the remote computer, you should also set the SINAUT MD740-1 to Transport (L2TP Microsoft Windows). The SINAUT MD740-1 will then work accordingly. The L2TP/PPP protocol creates a tunnel within the IPsec Transport connection.
  • Page 41 Remote site's VPN gateway address field (see above). Wait for the remote site In this case the local SINAUT MD740-1 is ready to accept the connection actively initiated and established by a remote site to the local SINAUT MD740-1. %any can be entered in the Remote site's VPN gateway address field (see above).
  • Page 42 Configuration X.509 Certificate This method is supported by most newer IPSec implementations. The SINAUT MD740-1 encrypts the authentication datagrams that it sends to the remote site - the "end of the tunnel" - with the remote site's public key (file name *.cer or *.pem).
  • Page 43 The longer the key, the more time-consuming the encryption process. This aspect is of no consequence to the SINAUT MD740-1 because it works with hardware-based encryption technology. Nevertheless, this aspect could be significant for the remote site.
  • Page 44 With these two entries you give the address of the client (network or computer) that is connected locally to the SINAUT MD740-1 direct and which is protected by the das SINAUT MD740-1. This address defines the local endpoint of the connection.
  • Page 45 Tunnel: the address of the local network (can also be an individual computer) Internet GPRS IPsec tunnel SINAUT MD740-1 To the remote site Devices and addresses of remote site Tunnel: the address of the opposite network (can also be an individual computer)
  • Page 46 As there, you can make the following possible entries: Protocol: All means: TCP, UDP, ICMP and other IP protocols. IP address: 0.0.0.0/0 means all addresses. To denote a range, use CIDR syntax - see CIDR (Classless InterDomain Routing), page 79. 46 von 105 SINAUT MD740-1...
  • Page 47 Log entries for unknown connection attempts: This logs all connection attempts which are not recorded by the prevalent rules. If several firewall rules have been set, they are followed in the order of the entries. SINAUT MD740-1 47 von 105...
  • Page 48 Configuration VPN # # # # Machine Certificate Certificate This denotes the currently imported X.509 certificate with which the SINAUT MD740-1 identifies itself to other VPN gateways. After a certificate has been imported the following information is displayed: subject The owner to whom the certificate has been issued.
  • Page 49 If you do not have a secure mode of transfer, you should then compared the fingerprint displayed by the SINAUT MD740-1 via a secure channel. Only one certificate file (PKCS#12 file) can be imported into the device.
  • Page 50 Within the IPsec transport connection the L2TP in turn contains a PPP connection. Consequently, a kind of tunnel is created between 2 networks. The SINAUT MD740-1 informs the remote site via PPP as to which addresses are being used: for itself and the remote site.
  • Page 51 If there are problems, it is recommended to look at the VPN logs of the computer to which the connection was established, because the initiating computer receives no detailed error messages for security reasons. The message SINAUT MD740-1 51 von 105...
  • Page 52 VPN # # # # L2TP Status Display only: Provides information the L2TP status if this has been chosen as the connection type. See VPN Connections, page 37. If this connection type was not selected, see the display illustrated. 52 von 105 SINAUT MD740-1...
  • Page 53 Display only: This lists all VPN events. The format corresponds to that commonly used under Linux. There are special evaluation programs which present the information from the logged data in a more easily legible format. SINAUT MD740-1 53 von 105...
  • Page 54: Services Menu

    Services menu Services # # # # DNS If the SINAUT MD740-1 is to establish a connection to a remote site (e.g. VPN gateway or NTP server), it must know the die IP address of the remote site in question. If it is given the address in the form of a domain address (i.e.
  • Page 55 Makes it easier for the user to enter a domain name: if the user enters the domain name in abbreviated form, the SINAUT MD740-1 supplements his entry with the given domain suffix which is fixed here under domain search path.
  • Page 56 IP address is registered under a fixed name. See also IP address of the remote site, page 9 Once you are registered with a DynDNS service supported by the SINAUT MD740-1 you can make the corresponding entries in this dialogue box. Register this TAINY at a DynDNS Service? Yes / No Select Yes if you are registered with a DynDNS provider and the SINAUT MD740-1 is to use the service.
  • Page 57 Standard: 420 (sec). Whenever the IP address of the device's own Internet connection is or has been changed, the SINAUT MD740-1 informs the DynDNS service of the new IP address. For reliability reasons this message is also sent at the time intervals fixed here.
  • Page 58 DHCP range start: Start and end of the address range from which the DHCP server of the DHCP range end: SINAUT MD740-1 is to assign IP addresses to the locally connected clients. Local netmask: Default setting: 255.255.255.0 Default gateway:...
  • Page 59 Only one DHCP server per subnet must be used. When you start the DHCP server of the SINAUT MD740-1 you must configure the locally connected clients in such a way that they receive their IP addresses automatically (see below).
  • Page 60 Displays the current NTP state Enable NTP time synchronization: Yes / No As soon as the NTP is enabled the SINAUT MD740-1 sources the time from the Internet and displays it as the current system time. Synchronization may take a few seconds.
  • Page 61 CET-1CEST,M3.5.0,M10.5.0/3 Time stamp in file system (2h granularity): Yes / No If this switch is set to Yes, the SINAUT MD740-1 writes the current system into its memory every 2 hours. Consequence: If the SINAUT MD740-1 is switched off and then back on, after being switched on a time in this 2-hour time window will be displayed and not a time on 1 January 2000.
  • Page 62: Access Menu

    Configuration Access menu Access # # # # Passwords The SINAUT MD740-1 offers 3 levels of user rights. To log in at a particular level the user must enter the password which is allocated to the privilege level in question.
  • Page 63 Access # # # # Language Please select your preferred language If (Automatic) is selected in the language selection list, the device automatically adopts the language setting from the computer's browser. SINAUT MD740-1 63 von 105...
  • Page 64 If you want to enable HTTPS remote access, set this switch to Yes. In this case, make sure that the firewall rules on this page are set so that the SINAUT MD740-1 can be accessed from the outside. If you set this parameter to No by remote access, no further entries by HTTPS remote access are possible.
  • Page 65 For each individual firewall rule you can determine whether, when the rule is applied, • the event is to be logged - set Log to Yes • or not - set Log to No (default setting). SINAUT MD740-1 65 von 105...
  • Page 66 If you want to enable SSH remote access, set this switch to Yes. In this case, make sure that the firewall rules on this page are set so that the SINAUT MD740-1 can be accessed from the outside. Port for incoming SSH connections (remote administration...
  • Page 67 Configuration If this SINAUT MD740-1 can be reached via the Internet using the address 192.144.112.5, and if a different port number has been set for remote access, then this number must be entered at the remote site in the SSH client (e.g.
  • Page 68: Features Menu

    Ask your dealer or distributor whether and how you can obtain a software update. Under no circumstances should you disconnect the power supply of the SINAUT MD740-1 during the update. The device could be damaged and can only be reactivated by the manufacturer.
  • Page 69 Features # # # # Update Server If you are provided with a software update (Features Install Update, page 68) for the SINAUT MD740-1 on a remote server, enter the server's address here. This must always come before the protocol used.
  • Page 70 To do so, please contact your distributor. Should new versions be available you can update the software in the device. See Features Install Update, page 68. 70 von 105 SINAUT MD740-1...
  • Page 71 Configuration Features # # # # Hardware Information Display only: For experienced system administrators / support. SINAUT MD740-1 71 von 105...
  • Page 72: Support Menu

    Pre-Shared Keys from VPN connections are contained in the snapshots.) To create a snapshot, proceed as follows: 1. Click on Download. 2. Store the file under the name snapshot.tar.gz Make the file available to support if requested to do so. 72 von 105 SINAUT MD740-1...
  • Page 73 Network mode Operating mode of the SINAUT MD740-1: modem External IP The IP address of the SINAUT MD740-1 at its connection for the external network (WAN or Internet). Default gateway via external IP The external IP address of the SINAUT MD740-1.
  • Page 74 SINAUT MD740-1 is receiving the current time (Greenwich Mean Time) from a time server via the Network Time Protocol. not synchronized : the SINAUT MD740-1 is not connected to a time server and therefore cannot provide the current time.
  • Page 75: System Menu

    System # # # # Configuration Profiles You have the possibility to save the settings of the SINAUT MD740-1 as a configuration profile under any name in the SINAUT MD740-1. You can create several such configuration profiles. You can then activate whichever configuration profile you require when using the SINAUT MD740-1 in different operating environments.
  • Page 76 Display / activate default setting The default setting is saved as a configuration profile under the name Factory Default in the SINAUT MD740-1. Display: Click on the name Factory Default. Activate: Click on the Restore button next to the name Factory Default.
  • Page 77 A reboot is required in the event of an error. It may also be necessary after a software update. At the end of the reboot the text "Rebooted" is displayed. A reboot can also be effected by switching the device off and back on again. SINAUT MD740-1 77 von 105...
  • Page 78 Following a reboot of the device, entries are already made in the log file before the device can synchronize the system time. In this case, the time stamps are not chronologically arranged. The entries are, however, in chronological order. 78 von 105 SINAUT MD740-1...
  • Page 79: Cidr (Classless Interdomain Routing)

    The method is described in RFC 1518. To advise a range of IP addresses to the SINAUT MD740-1, e.g. when configuring the firewall, it may be necessary to give the address space in CIDR syntax. The following table shows the IP netmask on the left, with the corresponding CIDR syntax on the far right.
  • Page 80 11110000 00000000 00000000 00000000 4 224.0.0.0 11100000 00000000 00000000 00000000 3 192.0.0.0 11000000 00000000 00000000 00000000 2 128.0.0.0 10000000 00000000 00000000 00000000 1 0.0.0.0 00000000 00000000 00000000 00000000 0 Example: 192.168.1.0 / 255.255.255.0 corresponds to CIDR: 192.168.1.0/24 80 von 105 SINAUT MD740-1...
  • Page 81: 4.10 Network Example Diagram

    The following diagram shows how the IP addresses could be distributed in a local network with subnets, which network addresses result and what the specification of an additional internal route could be in the SINAUT MD740-1. GPRS/Internet Address from outside: 80.81.192.37...
  • Page 82 Network: Network mask 255.255.255.0 255.255.255.0 255.255.255.0 255.255.255.0 192.168.27.0/24 Gateway: 192.168.11.2 Further settings of the routers, e.g. internal routers for communication from Network B to Network C, are not taken into consideration in the above example. 82 von 105 SINAUT MD740-1...
  • Page 83: Integrated Website Showing Device And Connection Data

    Integrated website showing device and connection data Integrated website showing device and connection data The SINAUT MD740-1 has an integrated Web server. The Web server provides a website with information on device and connection data. There are different ways of accessing the website using a Web browser: •...
  • Page 84: Creating The Dial-Up Connection For The Service Interface

    2. Select Connect to the Internet, Set up my connection manually..., Connect using a dial-up modem. Follow the instructions in the dialogue boxes. Make sure that no area codes or local access numbers are entered. 84 von 105 SINAUT MD740-1...
  • Page 85: Making A Connection To The Sinaut Md740-1 Website

    The user name and password are both: service 2. Click on Select. Effect: User name.: service The computer is connected to the SINAUT MD740-1 in such a Password: service way that the integrated Web server can be addressed. 3. Start your Web browser, e.g. MS Internet Explorer.
  • Page 86: Accessing The Web Server Locally Via The Application Interface

    • Prerequisites A GPRS connection must be active, i.e. the LED C of the SINAUT MD740-1 is lit and indicates that an IP address has been assigned by the GPRS network. • NAT must take place for the address of the locally connected computer that is to access the internal website (see Firewall # NAT, page27).
  • Page 87: Accessing The Web Server Of The Sinaut Md740-1 From A Remote

    Integrated website showing device and connection data Accessing the Web Server of the SINAUT MD740-1 from a remote computer via the GPRS network • Prerequisites Access is dependent on the configuration of the GPRS network and on how your LAN is linked to the GPRS.
  • Page 88: The Website Of The Sinaut Md740-1

    Integrated website showing device and connection data The website of the SINAUT MD740-1 To be able to view the website of the SINAUT MD740-1 with a Web browser the appropriate preparatory measures must be taken, depending on whether you want to access the website with your Web browser •...
  • Page 89: Device Information Page

    Telecommunication Union (ITU) standards. In the case of mobile phones the IMSI is stored on the SIM card. Own numbers: The (own) telephone numbers stored on the SIM card. (1..6): If available the voice, data and fax numbers are displayed. SINAUT MD740-1 89 von 105...
  • Page 90: Session Statistics And Total Statistics Pages

    Sent: Number of bytes sent in a PPP frame Total: Sum total of all bytes sent and received at PPP level Invalid: Number of incorrect bytes Online time: Specifies the duration of the current GPRS connection. Displayed as "Hours.Minutes.Seconds“. 90 von 105 SINAUT MD740-1...
  • Page 91: Ip Layer (Ip - Internet Protocol)

    Invalid: Number of incorrect bytes within an IP packet Device IP: The IP address which the SINAUT MD740-1 has received from the network provider on establishment of the connection into the GPRS network. This dynamic IP address is assigned to the device and is the IP address for incoming data packets.
  • Page 92: Status Information Page

    -109dBm to -53dBm -51dBm or better cannot be read / unknown GPRS-Attach: Yes or No is used to specify whether or not the SINAUT MD740-1 is booked into the GPRS network. booked in (Attach) not booked in 92 von 105 SINAUT MD740-1...
  • Page 93: Firmware Update Via The Integrated Ftp Server

    Firmware update via the integrated FTP server Firmware update via the integrated FTP server The SINAUT MD740-1 has an integrated FTP server (FTP = File Transfer Protocol). This can be used to load an update - if available - of the communication software into the SINAUT MD740-1.
  • Page 94: Glossary

    APN: • the Internet, • a private corporate network connected via a dedicated line. The APN denotes the point of access to the other network. 94 von 105 SINAUT MD740-1...
  • Page 95: Asymmetrical Encryption

    Domain Name Servers on the Internet accordingly. If a remote computer now wants to establish a connection to the local computer which is registered with the DynamicDNS provider, the remote computer uses the local computer's hostname as the SINAUT MD740-1 95 von 105...
  • Page 96: Tcp/Ip (Transmission Control Protocol/Internet Protocol)

    On a Windows PC the WINSOCK.DLL (or WSOCK32.DLL) takes over the handling of both these protocols. (# datagram) Service Provider A company or institution which provides users with access to the Internet or an online service. 96 von 105 SINAUT MD740-1...
  • Page 97: Protocol, Transmission Protocol

    (subnets) via a public network, e.g. the Internet, to form a Private Network) shared network. Confidentiality and authenticity are ensured by using cryptographic protocols. A VPN therefore provides an inexpensive alternative to dedicated lines when it comes to setting up a supraregional corporate network. SINAUT MD740-1 97 von 105...
  • Page 98: Des / 3Des

    X.509 Certification Authority (CA). The signature - an encryption with the signature key - can be checked with the private key issued by the CA to the certificate holder. 98 von 105 SINAUT MD740-1...
  • Page 99: Nat (Network Address Translation)

    The TCP/UDP header contains the following information: the port of the sender (source port) the port of the recipient (destination port) a checksum for the TCP header and some information from the IP header (e.g. source and destination IP address) SINAUT MD740-1 99 von 105...
  • Page 100: Ipsec

    UDP/TCP and the application processes takes place via these port numbers. The assignment of port numbers to application processes takes place dynamically and randomly. Fixed port number are assigned to certain frequently used application processes. These are known as assigned numbers. 100 von 105 SINAUT MD740-1...
  • Page 101: Ip Address

    Class B network, i.e. the last 2 bytes can be used freely for host addresses. In terms of figures, this results in address space for 65,536 possible hosts (256 x 256). SINAUT MD740-1 101 von 105...
  • Page 102: Certificate

    The additional key information also simplifies the administrability of the key. X.509 certificates are employed, e.g. in e-mail encryption, using S/MIME or IPsec. 102 von 105 SINAUT MD740-1...
  • Page 103: Technical Data

    Protection class: IP20 Dimensions: 114 mm x 45 mm x 99 mm Weight: approx. 280g Approvals R&TTE (GSM) GSM/GPRS engine with GCF approval EMV/ESD: EN 55024 EN 55022 Class A EN 61000-6-2 Electrical safety: EN 60950 SINAUT MD740-1 103 von 105...
  • Page 104: Pin Assignment Interface Service

    Pin7 Input Pin8 Output Pin9 Output Pin assignment interface 10/100 BASE-T Signals RJ45 socket - Ethernet (Signal direction DTE) Pin1 Pin2 Pin3 Pin4 Not connected Pin5 Not connected Pin6 Pin7 Not connected Pin8 Not connected 104 von 105 SINAUT MD740-1...
  • Page 105 Copyright Statement The information contained in this publication is protected by copyright. Translations, reproduction, copying and storage in data processing systems require the explicit approval of SIEMENS AG. © 2005 SIEMENS AG All rights reserved. SIEMENS Automation and Drives www.siemens.de Specifications are subject to change without notice.

Table of Contents