Advertisement

IR611-S Industrial Router
User Manual
InHand Networks
www.inhandnetworks.com
Version: v1.2
December 2016
FCC ID: 2AANYIR611S
IC: 11594A-IR611S / IC: 11594A à IR611S

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the IR611-S and is the answer not in the manual?

Questions and answers

Summary of Contents for InHand IR611-S

  • Page 1 IR611-S Industrial Router User Manual InHand Networks www.inhandnetworks.com Version: v1.2 December 2016 FCC ID: 2AANYIR611S IC: 11594A-IR611S / IC: 11594A à IR611S...
  • Page 2 The content in this manual is subject to change without notice. This manual is only used as the guidance. InHand makes every effort to provide accurate information in this manual, but InHand does not guarantee that there is no error in the manual. All statements, information and recommendations in this manual do not constitute any expressed or implied warranty.
  • Page 3 Preface This user manual will guide you on installing and configuring InHand IR6XX-S industrial router. Audience This manual is for:  Network Planner  Field technical support  Network administrators Conventions This manual uses the following conventions: Conventions Indication <>...
  • Page 4: Table Of Contents

    OUTER NTRODUCTION 1.1 Overview ............................ 1 1.2 Packing List ..........................1 1.2.1 Applicable to IR611-S series ........................ 1 1.2.2 Applicable to IR615-S series ........................ 2 1.3 Panel Introduction ........................2 1.3.1 Applicable to IR611-S Series ........................ 2 1.3.2 Applicable to IR6X5-S Series ........................ 2 1.
  • Page 5 3.1.4 Admin Access ............................9 3.1.5 System Log ............................11 3.1.6 Configuration Management ......................12 3.1.7 Task Schedule ............................ 12 3.1.8 System Upgrading ..........................13 3.1.9 Reboot ............................... 13 3.1.10 Logout ............................. 13 3. 2 Network ........................... 14 3.2.1 Dialup/Cellular Connection ....................... 14 3.2.2 WAN (Only Applicable to IR615-S Series) ..................
  • Page 6 3.4.5 Virtual IP Mapping ..........................31 3.4.6 DMZ ..............................31 3.4.7 MAC-IP Binding ..........................32 3.5 QoS ............................32 3.5.1 Bandwidth Control ..........................32 3.5.2 IP Bandwidth Limit ..........................33 3.6 VPN ............................33 3.6.1 IPSec Settings ............................ 34 3.6.2 IPSec Tunnels ............................. 35 3.6.3 GRE Tunnels ............................
  • Page 7: Contents

    Reliable VPN technology secures sensitive data. The IR6XX-S also utilizes remote management tools such as a CLI, a web interface and InHand Device Manager Cloud platform for batch configuration and monitoring. IR6XX-S series is ideal for large-scale Internet of Things (IoT) applications including kiosks, vending machines, medical equipment and industrial control systems.
  • Page 8: Preface

    3G/4G antenna (for 3G/4G models), 2 for hardware 3G/4G antenna version 40214, 60214 and 60625, 1 for others Wi-Fi antenna Dual Wi-Fi antennas (for Wi-Fi models) Hanger mounting To fix device wall-mounting accessories 1.3 Panel Introduction 1.3.1 Applicable to IR611-S Series 1.3.2 Applicable to IR6X5-S Series...
  • Page 9: Introductions To Status Led

    IR6XX-S series has a variety of panel appearances, but all of the installation methods are the same. The specific panel condition should be subject to the real object. 1. 4 Introductions to Status LED 1.4.1 Applicable to IR611-S series POWER STATUS...
  • Page 10: Installation

    Please be sure there is 3G/4G network coverage and there is no shield on site. 220V AC or 9~26VDC shall be provided on site. First installation shall be done under direction of the engineer recognized by InHand Networks.  1 PC...
  • Page 11: Installation Of Sim/Uim Card

    Serial port: At least one Ethernet port: At least one (10M/100M) IE version: Above 5.0 Resolution ratio: Above 640*480  1 SIM card: Ensure the card is enabled with data service and its service is not suspended because of an overdue charge. ...
  • Page 12: Installation Of Protective Grounding

    2.5 Installation of Power Supply Upon installation of the antenna, connect the device to 9~26V DC power and see if the Power LED on the panel of the device is on. If not, please contact technical support of InHand Networks immediately.
  • Page 13: Web Configuration

    <OK>. IV. Log in/Exit Web Settings Page Open IE or other browser and enter IP address of IR611-S, such as http://192.168.2.1 in address bar (default setting of IR611-S). Upon connection, log in from the login interface as a system admin, i.e.
  • Page 14: Basic Setup

    3.1.1 Basic Setup Here, WEB configuration interface language can be set; name of mainframe of router can be customized. From the navigation tree, select System >> Basic Setup, then enter the “Basic Setup” page. Table 3-1-1 Basic Setup Parameters Basic settings Function description: Select display language of the router configuration interface and set personalized name.
  • Page 15: Serial Port

    Time select when startup very 1/2/...hours. 3.1.3 Serial Port Setting the parameters of router’s serial port according to the serial port of the terminal device connected with router to achieve the normal communication between router and terminal device. From the navigation tree, select System >> Serial Port, then enter “Serial Port” page. Table 3-1-3 Serial Port Setting Parameter Description Serial Port...
  • Page 16 The device supports Telnet Client and Telnet Server. Console The console port, also called the access or serial port, refers for initial configuration and subsequent management of a device. It has the same terminal as the telnet client. From the navigation tree, select System >> Admin Access, then enter “Admin Access” page. Table 3-1-4 Parameters of Admin Access Admin Access Function description:...
  • Page 17: System Log

    admin functions (without influencing router configuration) Console Login User (Click <new> button after setting a group of username and password) Username Configure console login user, custom Password Configure the password, custom Other Parameters Log Timeout Set login timeout (router will automatically disconnect 500 seconds the configuration interface after login timeout) ...
  • Page 18: Configuration Management

    3.1.6 Configuration Management Here you can back up the configuration parameters, import the desired parameters backup and reset the router. From the navigation tree, select System >> Config Management, then enter the “Config Management” page. Table 3-1-6 Parameters of Configuration Management Configuration Management Function description: Set parameters of configuration management.
  • Page 19: System Upgrading

    From the navigation tree, select System >> Task Schedule, then enter “Task Schedule” page. 3.1.8 System Upgrading The upgrading process can be divided into two steps. In the first step, upgrading files will be written in backup firmware zone, e.g. , the process in the section of System Upgrading; in second step: files in backup firmware zone will be copied to main firmware zone, which should be carried out during system restart.
  • Page 20: Network

    3. 2 Network Network settings include Dialup/Cellular, WAN (only for IR615-S series), Link Backup, LAN, WLAN Mode Switch, WLAN, DNS, DDNS and Static Routes. 3.2.1 Dialup/Cellular Connection SIM card dial out through dial access to achieve the wireless network connection function of router.
  • Page 21: Wan (Only Applicable To Ir615-S Series)

    CARD(China Telecom) Network Type Auto, 2G Only, 3G Only, 4G Only Auto Optional always online, dial on demand, Connection Mode Always Online manual dialing Redial Interval Set the redialing time when login fails. 30 s Show Advanced Click to show advanced options (parameters Disable Options of advanced options are listed below)
  • Page 22 Router cannot access to the Internet via Router. Default route Enable default route Enable 00:18:05:08:07:3D (provided MAC Address MAC Address of the device InHand Networks), provided for device manufacturer IP Address Set IP address of WAN 192.168.1.29 255. 255. 255.
  • Page 23 Default route Enable default route Enable 00:18:05:08:07:3D (provided MAC Address MAC Address of the device InHand Networks), provided for device manufacturer Max. transmission unit, default/manual default (1500) settings Table 3-2-2-3 ADSL Dialing (PPPoE) Parameters of WAN WAN - ADSL Dialing (PPPoE) Function description: Set ADSL dialing parameters.
  • Page 24: Link Backup

    Enable IP header Click to enable IP header compression Disable compression Use Peer DNS Click to enable use peer DNS Enable Link detection interval Set link detection interval 55 s Link detection Max. Retries Set link detection max. retries Enable Debug Click to enable debug Disable Expert Option...
  • Page 25: Switch Of Wlan Mode

    Function description: LAN is the gateway address of router. Parameters Description Default MAC Address MAC Address of the device LAN 00:18:05:08:15:77 (provided by InHand Networks), provided for device manufacturer IP Address Set IP address of LAN 192.168.2.1 (New IP address of LAN needs to be entered after modification...
  • Page 26: Wlan Client (Sta Mode)

    Table 3-2-7 Parameters of WLAN Client WLAN Client Function description: Support WiFi function and access to wireless LAN access as client. Parameters Description Default Mode Support many modes including 802.11b/g/n 802.11b/g/n SSID Name of the SSID to be connected inHand...
  • Page 27: Dns

    Authentication method Keep consistent with the access point to Open type be connected Encryption Keep consistent with the access point to NONE be connected 3.2.8 DNS DNA (Domain Name System) is a DDB used in TCP/IP application programs, providing switch between domain name and IP address.
  • Page 28: Static Route

    3322. org. IR611-S &IR615-S DDNS service types include QDNS (3322)-Dynamic, QDNS(3322)-Static, DynDNS-Dynamic, DynDNS-Static, DynDNS-Custom and No-IP.com. To set DDNS, click the "Network >> Dynamic Domain Name" menu in the navigation tree, then enter “Dynamic Domain Name”...
  • Page 29: Service

    Static Route Function description: Add/delete additional static rote of router. Generally, it's unnecessary for users to set it. Parameters Description Default Destination Set IP address of the destination Address 255. 255. Subnet Mask Set subnet mask of the destination 255. 0 Gateway Set the gateway of the destination Select LAN/CELLULAR/WAN (only applicable to IR615-S...
  • Page 30: Dns Relay

    automatically, then such service must be activated. Static designation of DHCH allocation could help certain host to obtain specified IP address. Parameters Description Default Enable DHCP Enable DHCP service and dynamically allocate IP Enable address IP Pool Starting Address Set starting IP address of dynamic allocation 192.
  • Page 31: Vrrp: Virtual Router Redundancy Protocol

    When enabling DHCP, the DHCP relay is also enabled automatically. Relay cannot be disabled without disabling DHCP. 3.3.3 VRRP: Virtual Router Redundancy Protocol VRRP (Virtual Router Redundancy Protocol) adds a set of routers that can undertake gateway function into a backup group to form a virtual router. The election mechanism of VRRP will decide which router to undertake the forwarding task and the host in LAN is only required to configure the default gateway for the virtual router.
  • Page 32: Device Manager

    router with highest priority becomes the gateway for the transmission task. From navigation tree, select "Network >>VRRP" menu, then enter “VRRP” page. Table 3-3-3 VRRP Parameters VRRP Function description: Configure parameters of VRRP. Parameters Description Default Enable VRRP-I Click to enable VRRP function Disable Group ID Select ID of router group (range: 1-255)
  • Page 33: Dtu

    Set name of equipment supplier Default Equipment ID Set ID of router 611341234 Server Set address of device manager server to which c.inhand.com.cn the router will access Port Set default server port 20003 Login Retry Times Set login retry times...
  • Page 34: Sms

    Max. Reconnect Set the max. reconnect interval 180 s Interval DTU ID Set DTU ID. Source address Set the Source IP. Report DTU ID interval Set report of DTU ID interval Multi-Server Set server address and port 3.3.6 SMS SMS permits message-based reboot and manual dialing. Configure Permit to Phone Number and click <Apply and Save>.
  • Page 35: Basic Setup

    3.4.1 Basic Setup From the navigation tree, select Firewall >> Basic Setup, then enter the “Basic Setup” page. Table 3-4-1 Firewall - Basic Setup Parameters Basic Setup of Firewall Function description: Set basic firewall rules. Parameters Description Default Default Filter Policy Select accept/block Accept Filter PING detection from Internet...
  • Page 36: Filtering

    Click to enable log and the log about access control will be Disable recorded in the system. Description Convenient for recording parameters of access control 3.4.3 Filtering Configuration of mapping rules is generally used to disable access to network settings. From navigation tree, select "Firewall>>Filtering"...
  • Page 37: Virtual Ip Mapping

    External address Set external address/tunnel name of port mapping (optional) Description For recording significance of each port mapping rule 3.4.5 Virtual IP Mapping Both router and the IP address of the host of intranet can correspond with one virtual IP. Without changing IP allocation of intranet, the extranet can access to the host of intranet via virtual IP.
  • Page 38: Mac-Ip Binding

    The IR6x1's management port should never be mapped to the device port by this function. 3.4.7 MAC-IP Binding If the default process in the basic setting of firewall is disabled, only hosts specified in MAC-IP can have an access to outer net. From the navigation tree, select Firewall >>...
  • Page 39: Ip Bandwidth Limit

    From the navigation tree, select QoS >> Bandwidth Control, then enter the “Bandwidth Control” page. Table 3-5-1 Parameters of Bandwidth Control Bandwidth Control Function description: Configure bandwidth control. Parameters Description Default Click to enable the function of bandwidth Enable Disable control Outbound Limit:...
  • Page 40: Ipsec Settings

    meanwhile can be used by unauthorized VPN users so that what VPN users obtained is only a logistic private network. This public network is regarded as VPN Backbone. Build a credible and secure link by connecting remote users, company branches, partners to the network of the headquarters via VPN so as to realize secure transmission of data.
  • Page 41: Ipsec Tunnels

    dangers such as password and bank account information stolen and tampered, user identity imitated, suffering from malicious network attack, etc. After disposal of IPSec on the network, it can protect data transmission and reduce risk of information disclosure. IPSec is a group of open network security protocol made by IETF, which can ensure the security of data transmission between two parties on the Internet via data origin authentication, data encryption, data integrity and anti-replay function on the IP level.
  • Page 42 Parameters Description Default Click to enable advanced Disable (open advanced Show Advanced Options options options after enabling) Basic parameters Tunnel Name User defines tunnel name IPSec_tunnel_1 Set destination IP address or Destination Address 0. 0. 0. 0 domain name Select Auto Activated/Triggered Startup Modes...
  • Page 43: Gre Tunnels

    username User defines XATUTH XATUTH password password MODECFG Click to enable MODECFG Disable Phase II Parameters IPSec Strategy Multiple strategies available 3DES-MD5-96 IPSec Life Cycle Set IPSec life cycle 3600 s Perfect Forward Secrecy Select disable/Group 1/Group Disable (this needs to match (PFS) (Advanced Option) 2/Group 5 the server)
  • Page 44 X Network X Network GRE Tunnel Along with the extensive application of IPv4, to have messages from some network layer protocol transmitted on IPv4 network, those messages could by encapsulated by GRE to solve the transmission problems between different networks. In following circumstances GRE tunnel transmission is applied: ...
  • Page 45: L2Tp Client

    Enable Click to enable GRE Enable Name User defines name of GRE tunnel tun0 Local visual IP Set local virtual IP 0. 0. 0. 0 Destination Address Set remote IP address 0. 0. 0. 0 Peer visual IP Set peer virtual IP 0.
  • Page 46 RADIUS Server RADIUS Server Enterprise Enterprise Branch Headquarter L2TP Tunnel Dialling User L2TP Tunnel Mobile Office Staff (L2TP Dialling Software) From navigation tree, select VPN>>L2TP Client, enter "L2TP Client" and click <add>. Table 3-6-4 Parameters of L2TP Client 3 L2TP Client Function description: Configure parameters of L2TP client.
  • Page 47: Pptp Client

    Expert Option (not Set expert option, not recommended recommended) 3.6.5 PPTP Client From navigation tree, select VPN>>PPTP Client, enter "PPTP Client" and click <add>. Table 3-6-5 Parameters of PPTP Client 4 PPTP Client Function description: Configure parameters of PPTP client. Parameters Description Default...
  • Page 48 SSLv3/TLSv1 protocol are massively used. In OpenVPN, if a user needs to access to a remote virtual address (address family matching virtual network card), then OS will send the data packet (TUN mode) or data frame (TAP mode) to the visual network card through routing mechanism. Upon the reception, service program will receive and process those data and send them out through outer net by SOCKET, owing to which, the remote service program will receive those data and carry out processing, then send them to the virtual network card, then application software receive and accomplish a complete...
  • Page 49: Openvpn Advanced

    Expert Option (not Set expert option, not recommended recommended) 3.6.7 OpenVPN Advanced From navigation tree, select "VPN>>OpenVPN Advanced" and enter "OpenVPN Advanced" interface. Table 3-6-7 Configuration Parameters of OpenVPN Advanced OpenVPN Advanced Function description: Configure parameters of OpenVPN Advanced. Parameters Description Default Enable Client-to-Client...
  • Page 50: Tools

    cannot be changed an enrollment Server URL Set server URL Common Name Set common name FQDN Set FQDN Unit 1 Set unit 1 Unit 2 Set unit 2 Domain Set domain Serial Number Set serial number Challenge Set challenge Challenge Confirm Challenge confirm Protect Key Set protect key...
  • Page 51: Link Speed Test

    “Traceroute” page. Table 3-7-2 Traceroute Parameters Traceroute Function description: Applied for network routing failures detection. Parameters Description Default Address of the destination host which to Host be detected is required. Max. Hops Set the max. hops for traceroute Timeout Set the timeout of traceroute Protocol ICMP/UDP Advanced parameter for traceroute is...
  • Page 52: Network Connections

    3.8.3 Network Connections From navigation tree, select Status >> Network Connections, then enter “Network Connections” page to see the connections status. This page shows the basis information of dialup and LAN. Dialup includes connection type, IP address, netmask, gateway, DNS, MTU, status and connection time.
  • Page 53: Appendix A Faq

    Appendix A FAQ 1. InRouter is powered on, but can't access Internet through it? Please first check:  Whether the InRouter is inserted with a SIM card.  Whether the SIM card is enabled with data service, whether the service of the SIM card is suspended because of an overdue charge.
  • Page 54 server, but the center can't connect to your PC under InRouter? Please make sure the firewall of your computer is disabled. 7. After InRouter establishes VPN with the VPN server, your PC under InRouter can't connect to the server ping? Please make sure “Shared Connection”...
  • Page 55: Appendix B Instruction Of Command Line

    settings. Appendix B Instruction of Command Line 1Help Command Help command can be obtained after entering help or “?” into console, “?” can be entered at any time during the process of command input to obtain the current command or help from command parameters, and command or parameters can be automatically complemented in case of only command or command parameter.
  • Page 56 inputting will be given in case of no entering. [Example] Enter exit in ordinary user view: enable 123456 Switchover to super users and the password 123456. 2.2 Disable [Command] Disable [Function] Exit the privileged user level. [View] Super user view, configure view [Parameter] No [Example] Enter in super user view:...
  • Page 57 : display the current factory type of equipment Serial number : display the current factory serial number of equipment Description : www.inhand.com.cn Current version : display the current version of equipment Current version of Bootloader: display the current version of equipment 3.
  • Page 58 Example: 00:00:38 up 0 min, load average: 0.00, 0.00, 0.00 3. 3 show clock [Command] Show clock [Function] Display the system time of router [View] All views [Parameter] No [Example] Enter: show clock Display the following information: For example Sat Jan 1 00:01:28 UTC 2000 3.
  • Page 59 [Function] Display the log of router system and display the latest 100 logs in default. [View] All views [Parameter] Lines <n> limits the log numbers displayed, wherein, n indicates the latest n logs in case that it is positive integer and indicates the earliest n logs in case that it is negative integer and indicates all the logs in case that it is 0.
  • Page 60 Enter: show startup-config Display the starting configuration of system. 3. 8 Show running-config [Command] Show running-config [Function] Display the operational configuration of router [View] Super user view and configuration view [Parameter] No [Example] Enter: show startup-config Display the operational configuration of system. 4 Check Network Status Command 4.
  • Page 61 Display system ip status 4. 3 Show route [Command] Show route [Function] Display the routing list of router [View] All views [Parameter] No [Example] enter: show route Display the routing list of system 4. 4 Show arp [Command] Show arp [Function] Display the ARP list of router [View] All views [Parameter] No...
  • Page 62 [Example] Enter: ping www.g.cn Test www. g. cn and display the testing results 5. 2 Telnet [Command] Telnet <hostname> [<port>] [source <ip>] [Function] Telnet logs in the appointed mainframe [View] All views [Parameter] <hostname> in need of the address or domain name of mainframe logged in. <port>telnet port source <ip>...
  • Page 63 management. Some setting command can support no and default, wherein, no indicates the setting of canceling some parameter and default indicates the recovery of default setting of some parameter. 6. 1 Configure [Command] Configure terminal [Function] Switchover to configuration view and input the equipment at the terminal end. [View] Super user view [Parameter] No [Example]...
  • Page 64 [Command] Clock timezone <timezone><n> default clock timezone [Function] Set the time zone information of the router. [View] Configure view. [Parameter] <timezone> timezone name, 3 capitalized English letters <n> time zone deviation value, -12~+12 [Example]  Enter in configured view: clock timezone CST -8 The time zone of IG601is east eighth area and the name is CST (China's standard time).
  • Page 65 [Function] Set the customer end of Internet time server [View] Configure view. [Parameter] <hostname> address or domain name of mainframe of time server [Example]  Enter in configured view: ntp server pool.ntp.org Set the address of Internet time server pool. ntp. org. ...
  • Page 66 The config. is imported. 7 System Management Command 7. 1 Reboot [Command] Reboot [Function] System restarts. [View] Super user view and configuration view [Parameter] No [Example] Enter in super user view: reboot System restarts. 7. 2 Enable username [Command] Enable password [<name>] [Function] Modify the username of super user.
  • Page 67 Enter password according to the hint. 7. 4 Username [Command] Username <name> [password [<password>]] no username <name> default username [Function] Set user name, password [View] Configure view. [Parameter] No [Example]  Enter in configured view: username abc password 123 Add an ordinary user, the name is abc and the password is 123. ...
  • Page 68 FCC STATEMENT 1. This device complies with Part 15 of the FCC Rules. Operation is subject to the following two conditions: (1) This device may not cause harmful interference. (2) This device must accept any interference received, including interference that may cause undesired operation.
  • Page 69 IC STATEMENT La operación de este equipo está sujeta a las siguientes doscondiciones: (1) es posible que este equipo o dispositivo nocause interferencia perjudicial y (2) este equipo o dispositivodebe aceptar cualquier interferencia, incluyendo la que pueda causar su operación no deseada. This radio transmitter (11594A-IR611S) has been approved by Industry Canada to operate with the antenna types listed below with the maximum permissible gain indicated.
  • Page 70 fonctionner avec les types d'antenne énumérés ci-dessous et ayant un gain admissible maximal. Les types d'antenne non inclus dans cette liste, et dont le gain est supérieur au gain maximal indiqué, sont strictement interdits pour l'exploitation de l'émetteur. types d'antenne: WIFI: Reverse SMA Gain:2.0dBi 4G: SMA-J Gain:2.0dBi...

Table of Contents