Page 2
Information in this document is subject to change without notice and does not represent a commitment on the part of Navigateworx Technologies. Navigateworx Technologies provides this document as is, without warranty of any kind, either expressed or implied, including, but not limited to, its particular purpose. Navigateworx...
Page 3
Information provided in this manual is intended to be accurate and reliable. However, Navigateworx Technologies assumes no responsibility for its use, or for any infringements on the rights of third parties that may result from its use.
Industrial VPN Router NR500 Series User Manual Table of Contents Chapter 1. Product Overview ..........................5 Overview ..............................5 Features and Benefits .......................... 5 General Specifications ........................6 Mechanical Specifications ........................ 8 Package Checklist ..........................9 Order Information ..........................11 Chapter 2.
Page 5
Industrial VPN Router NR500 Series User Manual 4.7.1 OpenVPN .............................. 55 4.7.2 IPSec ............................... 61 4.7.3 GRE ................................64 Maintenance ............................66 4.8.1 Upgrade ..............................66 4.8.2 Software ..............................66 4.8.3 System ..............................67 4.8.4 Configuration ............................71 4.8.5 Debug Tools ............................72 Appendix A -Glossary ...............................
Chapter 1. Product Overview 1.1 Overview Navigateworx NR500 series industrial VPN router offers a single, flexible platform to address a variety of wireline communications needs with over-the-air configuration and system monitoring for optimal connectivity. This router enables wireline data connectivity.
Industrial VPN Router NR500 Series User Manual 1.3 General Specifications Wi-Fi Interface (Optional) Standards: 802.11b/g/n, 300Mbps • 2 x RP-SMA male antenna connector • Support Wi-Fi AP and Client modes • Security: WEP, WPA and WPA2 encryption • Encryption: TKIP, CCMP •...
Page 8
Industrial VPN Router NR500 Series User Manual Network protocols: DHCP, ICMP, PPPoE, HTTP, HTTPS, DNS, VRRP, NTP… • VPN: IPSec, GRE, OpenVPN, DMVPN • Policy: RIPv1/RIPv2/OSPF/BGP dynamic route (optional) • Firewall & Filter: Port forwarding, DMZ, anti-DoS, ACL • Serial port: TCP server and client, UDP •...
NR500 series Router includes the parts shown in below, please verify your components. NOTE: if any of the below items is missing or damaged, please contact your sales representative. Included equipment 1 x Navigateworx NR500 series Industrial VPN router (Wi-Fi optional) • NR500 SNC NR500 PNC 1 x 3-pin 3.5 mm male terminal block with lock for power supply...
Industrial VPN Router NR500 Series User Manual 1.6 Order Information Model Part Number Description No Cellular Module, 2 x Eth, 1 x RS232 (3 PIN), 1 x A502033 RS485, 2 x DI, 2 x DO, 9 - 48VDC NR500-SNC No Cellular Module, 2 x Eth, 1 x RS232 (3 PIN), 1 x A512033 RS485, 2 x DI, 2 x DO, 9 - 48VDC, 2.4GHz Wi-Fi...
Industrial VPN Router NR500 Series User Manual Chapter 2. Installation 2.1 Product Overview Front Panel • ① Wi-Fi Antenna ② Wi-Fi Antenna ③ LED Indicator ④ Serial port & DIDO ⑤ Ethernet port Left Side Panel • ① SIM Card Slot ②...
Industrial VPN Router NR500 Series User Manual 2.2 LED Indicators Name Color Status Description Operating normally Slow Blinking (500ms duration) Fast Blinking System initialing Green Power is off Wi-Fi is enable but without data transmission Green Blinking Wi-Fi is enabled and data USR: Wi-Fi transmission Wi-Fi is disable or initialize failed...
Industrial VPN Router NR500 Series User Manual 2.3 Ethernet Port Indicator Name Status Description Connection is established Blinking Data is being transmitted Link indicator Connection is not established NOTE:There are two LED indicators for each Ethernet port. Due to the chipset design NR500 router would only light up the green one(Link indicator) on left side, the right LED is Off without meaning.
Industrial VPN Router NR500 Series User Manual Power Input • Description V+ (Red line) Positive V- (Yellow line) Negative PGND 2.5 Reset Button Function Action Press the RST button within 3s under operation status Reboot Press the RST button between 3s to 10s, all LEDs blink few times then Factory Reset reboot the router manually.
Industrial VPN Router NR500 Series User Manual 2.7 DIN-rail Mounting Use 4 pcs of M3x6 flat head phillips screws to fix the DIN-rail to the router. Insert the upper lip of the DIN-rail into the DIN-rail mounting kit. Press the router towards the DIN-rail until it snaps into place. 2.8 Protective Grounding Installation Remove the grounding nut.
Industrial VPN Router NR500 Series User Manual 2.9 Power Supply Installation Remove the pluggable connector from the unit, then loosen the screws for the locking flanges as needed. Connect the wires of the power supply to the terminals. 2.10 Power On The Router Connect one end of the Ethernet cable to the LAN port on the unit and the other end to a LAN port on a PC.
Industrial VPN Router NR500 Series User Manual Chapter 3. Access to Web page 3.1 PC Configuration NR500 router contains a DHCP server which will automatically assign an IP address to your PC, however in some cases the user may need to change the network settings on their PC to accept the IP address from the NR500.
Industrial VPN Router NR500 Series User Manual Set to a static IP address • click "Use the following IP address" to assign a static IP manually within the same subnet of the router. NOTE:Default gateway and DNS server is not necessary if PC not routing all traffic go through NR500 router.
Industrial VPN Router NR500 Series User Manual 3.3 Login to Web Page 1. Start a Web browser on your PC (Chrome and IE are recommended), enter 192.168.5.1 into the address bar of the web browser. 2. Then use the default username and password(admin/admin), to log in to the router. Page 20 / 77...
Industrial VPN Router NR500 Series User Manual Chapter 4. Web Configuration 4.1 Web Interface The NR500 router Web interface is divided into two sections. In the left pane is the main navigation menu. On the right is the content area for each page. NOTE: The navigation menu may contain fewer sections than shown here depending on which options are installed in your unit.
Page 23
Industrial VPN Router NR500 Series User Manual Reboot: reset the router within power disconnect. • Logout: logout to web authorization page. • Save: save the configuration on current page. • Apply: apply the changes on current page immediately. • Close: exit without changing the configuration on current page. •...
Industrial VPN Router NR500 Series User Manual 4.2 Overview 4.2.1 Status You can view the system information of the router on this page. System Information Device Module • Displays the model name of router System Uptime • Displays the duration the system has been up in hours, minutes and seconds. System Time •...
Page 25
Industrial VPN Router NR500 Series User Manual Active Link Information Link Type • Current interface for internet access. IP Address • Displays the IP address assigned to this interface. Netmask • Displays the subnet mask of this interface. Gateway • Displays the gateway of this interface.
Industrial VPN Router NR500 Series User Manual 4.2.2 Syslog Syslog Information Download Diagnosis • Download the Diagnosis file for analysis. Download Syslog • Download the complete syslog since last reboot. Clear • Clear the current page syslog printing. Refresh • Reload the current page with latest syslog printing.
Industrial VPN Router NR500 Series User Manual Link Management This section shows you the setup of link management. 4.3.1 Connection Manager Connection Manager->Status Type • Displays the connection interface Status • Displays the connection status of this interface. IP Address •...
Page 28
Industrial VPN Router NR500 Series User Manual Connection Manager->Connection Priority • Displays the priority list of default routing selection. Enable • Displays the connection enable status. Connection Type • Displays the name of this interface. Description • Displays the description of this connection. Connection Settings Priority •...
Page 29
Industrial VPN Router NR500 Series User Manual Primary Server • Enter the primary IP address that pings will be sent to, to detect the link state. Recommend entering the IP address of known external reachable server or network (e.g. 8.8.8.8). Secondary Server •...
Industrial VPN Router NR500 Series User Manual 4.3.2 Ethernet The same instructions apply to settings for all Ethernet interfaces. Ethernet->Status Ethernet Port Information • Displays the port physical connected states. Interface Information • Displays the name and MAC address of Ethernet interface. DHCP Lease Table •...
Page 31
Industrial VPN Router NR500 Series User Manual Ethernet->Port Settings Port • Indicate the current configurate port. Interface • Select belong subnet for current configurate port. Ethernet->WAN Connection Type • If you select DHCP Client, external DHCP server will assign an IP address to this unit. •...
Page 32
Industrial VPN Router NR500 Series User Manual Ethernet->WAN->Static IP or PPPoE IP Address • Static address for this interface. It must be on the same subnet as the gateway. Netmask • Will be assigned by the gateway. Gateway • IP address of the Gateway (DHCP Host). If not known this can be left as all zeros. Primary DNS •...
Page 33
Industrial VPN Router NR500 Series User Manual Ethernet->LAN Interface • Select the configurate LAN port of this subnet. IP Address • Enter LAN IP address for this interface. Netmask • Enter subnet mask for this subnet. • Maximum Transmission Unit, maximum packet size allowed to be transmitted. Should be left as default value of 1500 in most cases.
Page 34
Industrial VPN Router NR500 Series User Manual Relay Server • Enter the IP address of DHCP relay server. IP Pool Start • External LAN devices connected to this unit will be assigned IP address in this range when DHCP is enabled.
Page 35
Industrial VPN Router NR500 Series User Manual Ethernet->LAN->Multiple IP Settings Interface • Select the configurate LAN port of this subnet. IP Address • Enter multiple IP address for this interface. Netmask • Enter subnet mask for this subnet. Ethernet->VLAN->VLAN Trunk Settings Interface •...
Industrial VPN Router NR500 Series User Manual 4.3.3 Wi-Fi NR500 router could only be set to function as either a Wi-Fi Client or a Wi-Fi Access Point, but not both simultaneously. Select Wi-Fi (Access Point) from the main navigation menu to Wi-Fi (default as Access Point) page, which contains tabs for configuration of the Wi-Fi Access Point interface.
Page 37
Industrial VPN Router NR500 Series User Manual Wi-Fi AP Wi-Fi AP settings page as below. Wi-Fi->Wi-Fi AP Enable • Check this box will enable the Wireless interface. SSID • The SSID is the name of the wireless local network. Devices connecting to the NR500 router WiFi access will identify the Access Point by this SSID.
Page 38
Industrial VPN Router NR500 Series User Manual Channel • Select the Wi-Fi channel the module will transmit on. If there are other Wi-Fi devices in the area the NR500 router should be set to a different channel than the other access points. Channels available for selection depend on the selected Band.
Page 39
Industrial VPN Router NR500 Series User Manual Wi-Fi Client Wi-Fi Client settings page as below. Page 38 / 77...
Page 40
Industrial VPN Router NR500 Series User Manual Wi-Fi->Wi-Fi Client Enable • Check this box will enable the Wireless interface. Connect to Hidden SSID • Check this box will enable connect to hidden SSID. SSID • The SSID of external access point. Password •...
Industrial VPN Router NR500 Series User Manual 4.4 Industrial Interface The Industrial page contains tabs for making configuration settings for Serial RS232 and RS485, Digital input and output. Select Serial & Digital IO from the main navigation menu to navigate to this page.
Page 42
Industrial VPN Router NR500 Series User Manual Port • Displays the serial type of COM port. Baud Rate • Displays the serial port baud rate. Data Bits • Displays the serial port Data Bits. Stop Bits • Displays the serial port Stop Bits. Parity •...
Page 43
Industrial VPN Router NR500 Series User Manual Select the transmission method for serial port. Optional for “Transparent”, “Modbus RTU Gateway” and “Modbus ASCII Gateway”. • Maximum Transmission Unit, maximum packet size allowed to be transmitted. Should be left as default value of 1024 in most cases. Protocol •...
Page 44
Industrial VPN Router NR500 Series User Manual Serial->Connection Settings Local IP Address • Enter the IP Address of the local endpoint. Local Port • The port number assigned to the serial IP port on which communications will take place. Remote IP Address •...
Industrial VPN Router NR500 Series User Manual 4.4.2 Digital IO This section allows you to set the Digital IO parameters. The Digital input could be used for triggering alarm, and Digital output could be used for controlling the slave device by digital signal.
Page 46
Industrial VPN Router NR500 Series User Manual Digital IO->Digital Output Enable • Check this box to enable digital output function. Alarm Source • Select from “Digital Input1” or “Digital Input2”, Digital output triggers the related action when there is alarm comes from Digital Input. Alarm ON Action •...
Industrial VPN Router NR500 Series User Manual 4.5 Network 4.5.1 Firewall Firewall rules are security rule-sets to implement control over users, applications or network objects in an organization. Using the firewall rule, you can create blanket or specialized traffic transit rules based on the requirement.
Page 48
Industrial VPN Router NR500 Series User Manual Firewall->ACL Description • Add a description for this rule. Chain • Specify the forward rule of ACL, choose from “FORWARD” and “INPUT”. Protocol • All: Any protocol number. TCP: The TCP protocol. UDP: The UDP protocol. TCP &...
Page 49
Industrial VPN Router NR500 Series User Manual Sets the LAN address of a device connected to one of the Fusion’s LAN interfaces. Inbound requests will be forwarded to this IP address. Local Port • Sets the LAN port number range used when forwarding to the destination IP address. Firewall->DMZ Enable •...
Industrial VPN Router NR500 Series User Manual Firewall->URL Filter • Enter the URL to block the data traffic to go to the website. For example, www.google.com 4.5.2 Route Static Routing refers to a manual method of setting up routing between networks. Select the Static Routing tab to add static routes to the Static Route Table.
Page 51
Industrial VPN Router NR500 Series User Manual Route->Static Route Settings Description • Enter the description of current static route rule. IP Address • Enter the IP address of the destination network. Netmask • Enter the subnet mask of the destination network. Gateway •...
Industrial VPN Router NR500 Series User Manual 4.5.3 VRRP The Virtual Router Redundancy Protocol (VRRP) is a computer networking protocol that provides automatic assignment of available Internet Protocol (IP) routers for participating hosts. The VRRP router who has the highest number will become the virtual master router. The VRRP router number ranges from 1 to 255 and usually we use 255 for the highest priority and 100 for backup.
Industrial VPN Router NR500 Series User Manual 4.5.4 IP Passthrough IP Passthrough mode, disables NAT and routing and passes the WAN IP address from the WAN interface to the device connected on the local Interface. It is used instead of Network Address Translation (NAT) in order to make the router "transparent"...
Industrial VPN Router NR500 Series User Manual 4.6 Applications 4.6.1 DDNS DDNS is a system that allows the domain name data of a computer with a varying (dynamic) IP addresses held in a name server to be updated in real time in order to make it possible to establish connections to that machine without the need to track the actual IP addresses at all times.
Industrial VPN Router NR500 Series User Manual Enable • Check this box to enable the DDNS service. Provider • Select the DDNS provider from the list, options from “DynDNS”, “no-ip”,”3322” and custom. DDNS Server • The internet address to communicate the Dynamic DNS information to. This option is available after you select custom on DDNS Provider.
Industrial VPN Router NR500 Series User Manual 4.7 VPN 4.7.1 OpenVPN OpenVPN is an open source virtual private network (VPN) product that offers a simplified security framework, modular network design, and cross-platform portability. You could review all OpenVPN connection as below. VPN->OpenVPN->Status>OpenVPN Information Enable •...
Page 57
Industrial VPN Router NR500 Series User Manual VPN->OpenVPN Enable • Check this box to enable OpenVPN tunnel. Description • Enter a description for this OpenVPN tunnel. Mode • Select from “P2P”, “Client” or “Server”. Protocol • Select from “UDP”, “TCP Client” or “TCP Server” Connection Type •...
Page 58
Industrial VPN Router NR500 Series User Manual Max Client • Allow max OpenVPN client connect to OpenVPN server. Authentication Method • Select from "X.509", "Pre-shared", "Password", and "X.509 And Password". Encryption Type • Select from "BF-CBC", "DES-CBC", "DES-EDE-CBC", "DES-EDE3-CBC", "AES-128-CBC", "AES-192-CBC" and "AES-256-CBC".
Page 59
Industrial VPN Router NR500 Series User Manual VPN->OpenVPN->Advanced Settings Enable NAT • Check this box to enable NAT, the source IP of host behind router will be disguised before accessing the remote end. Enable Default Gateway • Check this box to enable default gateway, all the data traffic will go through the VPN tunnel. Enable PKCS#12 •...
Page 60
Industrial VPN Router NR500 Series User Manual VPN->OpenVPN->X.509 Certificate OpenVPN Mode • Select OpenVPN working mode between Server and Client. Connection Index • Displays the current connection index for OpenVPN channel. CA Certificate • Import CA certificate file. Local Certificate File •...
Page 61
Industrial VPN Router NR500 Series User Manual VPN->OpenVPN->Configuration Files Connection Index • Select OpenVPN connection index. Configuration Files • Import the OpenVPN client file. Configuration Files Download • Download the OpenVPN client configuration. Configuration Files List • Display the imported OpenVPN client file. Page 60 / 77...
Industrial VPN Router NR500 Series User Manual 4.7.2 IPSec IPSec facilitates configuration of secured communication tunnels. The various tunnel configurations will be displayed in the Tunnel Table at the bottom of the page. All tunnels are create using the ESP (Encapsulating Security Payload) protocol. VPN->IPSec->Status Enable •...
Page 63
Industrial VPN Router NR500 Series User Manual VPN->IPSec Enable • Select Enable will launch the IPSec process. Description • Enter a description for this IPSec VPN tunnel. Remote Gateway • Enter the IP address of the remote endpoint of the tunnel. IKE Version •...
Page 64
Industrial VPN Router NR500 Series User Manual VPN->IPSec Encryption Algorithm (IKE) • Select 3DES AES-128, AES-192, or AES-256 encryption. Hash Algorithm (IKE) • Select from MD5, SHA1, SHA2 256, SHA2 384 or SHA2 512 hashing. Diffie-Hellman Group (IKE) • Negotiate (None) or use 768 (Group 1), 1024 (Group 2), 1536 (Group 5) or 2048 (Group 14) etc. Lifetime (IKE) •...
Industrial VPN Router NR500 Series User Manual 4.7.3 GRE Generic Routing Encapsulation (GRE) is a protocol that encapsulates packets in order to route other protocols over IP networks. It’s a tunneling technology that provides a channel through which encapsulated data message could be transmitted and encapsulation and decapsulation could be realized at both ends.
Page 66
Industrial VPN Router NR500 Series User Manual VPN->GRE Enable • Check this box to enable GRE. Description • Enter the description of current VPN channel. Mode • Specify the running mode of GRE, optional are “Layer 2” and “Layer 3”. Remote Gateway •...
Industrial VPN Router NR500 Series User Manual 4.8 Maintenance 4.8.1 Upgrade When newer versions of NR500 firmware become available, the user can manually update the unit by uploading a package to the unit. NOTE: The unit need manually reboots once the upload completes, thus taking the NR500 router out of service during approximately 1 minute.
Industrial VPN Router NR500 Series User Manual 4.8.3 System This section allows you to review the device system settings. System->General Hostname • User-defined router name, which might be use for IPSec local ID identify. User LED Type • Defined the User LED behavior. Time Zone •...
Page 69
Industrial VPN Router NR500 Series User Manual System->Account Administrator • Displays the name of current administrator, default as “admin”. Old Password • Enter the old password of administrator. New Password • Enter the new password of administrator. Confirm Password • Confirm the new password of administrator.
Page 70
Industrial VPN Router NR500 Series User Manual Syslog displays system logs that are stored in the log buffers. System->Syslog Log Location • Select the log store location from “RAM” or “Flash”. Log Level • Select the log output level from “Debug”, “Notice”, “Info”, “Warning” or “Error”. Enable Remote Syslog •...
Page 71
Industrial VPN Router NR500 Series User Manual System->Telnet Telnet Port • Enter the port for telnet access. A well-known port for HTTP is port 23. System->SSH SSH Port • Enter the port for SSH access. A well-known port for HTTP is port 22. Allow Password Authentication •...
Industrial VPN Router NR500 Series User Manual Import previously-saved configuration file. 4.8.5 Debug Tools Debug Tools->Ping Host Address • Enter a host IP address or domain name for ping. Ping Count • Enter the ping times. Local IP Address • Enter the ping source IP address or leave it blank.
Page 74
Industrial VPN Router NR500 Series User Manual Debug Tools->Sniffer Source Host • Enter the source host IP address. Source Port • Enter the source port. Destination Host • Enter the destination host IP address. Destination Port • Enter the destination port. Interface •...
Industrial VPN Router NR500 Series User Manual Appendix A -Glossary DHCP: Dynamic Host Configuration Protocol LAN: Local Area Network LED: Light-Emitting Diode NTP: Network Time Protocol SMA: SubMiniature version A (connector) SSID: Service Set Identifier TCP/IP: Transmission Control Protocol / Internet Protocol UDP: User Datagram Protocol VPN:...
Possible Reason PC did not have the same IP network with 192.168.5.x • Insert the ethernet cable to the wrong ethernet port of NR500 NC • Solution Check the IP on PC to make sure under same IP network 192.168.5.x •...
Command-line interface (CLI) is a software interface that provide another configurable way to set parameters on our router. We could use Telnet or SSH connect to our router for CLI input. NR500 CLI Access navigateworx.router login: admin Password: admin >...
Page 79
Industrial VPN Router NR500 Series User Manual 64 bytes from 14.215.177.38: seq=1 ttl=54 time=10.284 ms 64 bytes from 14.215.177.38: seq=2 ttl=54 time=10.073 ms 64 bytes from 14.215.177.38: seq=3 ttl=54 time=10.031 ms 64 bytes from 14.215.177.38: seq=4 ttl=54 time=10.347 ms --- www.baidu.com ping statistics --- 5 packets transmitted, 5 packets received, 0% packet loss round-trip min/avg/max = 10.031/10.312/10.826 ms >...