Page 2
Information provided in this manual is intended to be accurate and reliable. However, Navigateworx Technologies assumes no responsibility for its use, or for any infringements on the rights of third parties that may result from its use.
Page 3
Industrial Cellular VPN Router NR300 Series User Manual Interference Issues Avoid possible radio frequency (RF) interference by following these guidelines: The use of cellular telephones or devices in aircraft is illegal. Use in aircraft may endanger operation and • disrupt the cellular network. Failure to observe this restriction may result in suspension or denial of cellular services to the offender, legal action, or both.
Industrial Cellular VPN Router NR300 Series User Manual Table of Contents Chapter 1. Product Overview ..........................5 Overview ..............................5 Features and Benefits .......................... 5 General Specifications ........................6 Mechanical Specifications ........................ 8 Package Checklist ..........................9 Order Information ..........................11 Chapter 2.
Page 5
Industrial Cellular VPN Router NR300 Series User Manual 4.7.1 OpenVPN .............................. 49 4.7.2 IPSec ............................... 54 4.7.3 GRE ................................57 Maintenance ............................58 4.8.1 Upgrade ..............................58 4.8.2 Software ..............................59 4.8.3 System ..............................60 4.8.4 Configuration ............................64 4.8.5 Debug Tools ............................
Chapter 1. Product Overview 1.1 Overview Navigateworx NR300 series industrial cellular VPN router offers a single, flexible platform to address a variety of wireless communications needs with over-the-air configuration and system monitoring for optimal connectivity. This router enables wireless data connectivity over public and private LTE cellular networks at 4G speeds.
Industrial Cellular VPN Router NR300 Series User Manual 1.4 Mechanical Specifications Dimension: 82.8mm x 93.3mm x 28.8mm FRONT SIDE TOP SIDE BOTTOM SIDE Antenna LEDs SIM Slot Terminal Ethernet 93.3 mm block 28.8 mm 28.8 mm 82.8 mm 82.8 mm 82.8 mm Page 8 / 70...
NR300 series Router includes the parts shown in below, please verify your components. NOTE: if any of the below items is missing or damaged, please contact your sales representative. Included equipment 1 x Navigateworx NR300 series Industrial Cellular VPN router • 1 x 7-pin 3.5 mm male terminal block for Power Input/RS232/RS485 •...
Industrial Cellular VPN Router NR300 Series User Manual 1.6 Order Information Model Part Number Description A301430 4G LTE, Dual SIMs, 1 x Eth, 1 x RS232 (3 PIN), 1 x NR300-4G 20101171 RS485, 9 - 36VDC. Page 11 / 70...
Industrial Cellular VPN Router NR300 Series User Manual Chapter 2. Installation 2.1 Product Overview Front Panel • ① Cellular Antenna ② RST Button ③ LED Indicator ④ SIM Slot ⑤ Power Input/RS232/RS485 ⑥ Ethernet Port Page 12 / 70...
Industrial Cellular VPN Router NR300 Series User Manual 2.2 LED Indicators Name Color Status Description Operating normally Slow Blinking (500ms duration) Fast Blinking System initialing Green Power is off Register to Highest priority network service (depend on Radio, e.g. Radio support LTE as Highest priority network).
Industrial Cellular VPN Router NR300 Series User Manual 2.3 Ethernet Port Indicator Name Status Description Connection is established Blinking Data is being transmitted Link indicator Connection is not established 2.4 PIN Definition of Terminal block Power Input & Serial Port •...
Industrial Cellular VPN Router NR300 Series User Manual 2.5 Reset Button Function Action Press the RST button within 3s under operation status Reboot Press the RST button between 3s to 10s, all LEDs blink few times then Factory Reset reboot the router manually. Press the RST button more than 10s, router will run normally without Run Normally reboot or factory reset.
Industrial Cellular VPN Router NR300 Series User Manual NOTE: NR300 router supports dual antennas with MAIN and AUX connectors. MAIN connector is for data receiving and transmission. AUX connector is for enhancing signal strength, which cannot be used separately. 2.8 DIN-rail Mounting Use 4 pcs of M3x6 flat head phillips screws to fix the DIN-rail to the router.
Industrial Cellular VPN Router NR300 Series User Manual 2.9 Power Supply Installation Remove the pluggable connector from the unit, then loosen the screws for the locking flanges as needed. Connect the wires of the power supply to the terminals. 2.10 Power On The Router Connect one end of the Ethernet cable to the LAN port on the unit and the other end to a LAN port on a PC.
Industrial Cellular VPN Router NR300 Series User Manual Chapter 3. Access to Web page 3.1 PC Configuration NR300 router contains a DHCP server which will automatically assign an IP address to your PC, however in some cases the user may need to change the network settings on their PC to accept the IP address from the N300.
Industrial Cellular VPN Router NR300 Series User Manual Set to a static IP address • click "Use the following IP address" to assign a static IP manually within the same subnet of the router. NOTE:Default gateway and DNS server is not necessary if PC not routing all traffic go through NR500 router.
Industrial Cellular VPN Router NR300 Series User Manual 3.3 Login to Web Page 1. Start a Web browser on your PC (Chrome and IE are recommended), enter 192.168.5.1 into the address bar of the web browser. 2. Then use the default username and password(admin/admin), to log in to the router. Page 20 / 70...
Industrial Cellular VPN Router NR300 Series User Manual Chapter 4. Web Configuration 4.1 Web Interface The N300 router Web interface is divided into two sections. In the left pane is the main navigation menu. On the right is the content area for each page. NOTE: The navigation menu may contain fewer sections than shown here depending on which options are installed in your unit.
Page 23
Industrial Cellular VPN Router NR300 Series User Manual Reboot: reset the router within power disconnect. • Logout: logout to web authorization page. • Save: save the configuration on current page. • Apply: apply the changes on current page immediately. • Close: exit without changing the configuration on current page.
Industrial Cellular VPN Router NR300 Series User Manual 4.2 Overview 4.2.1 Status You can view the system information of the router on this page. System Information Device Module • Displays the model name of router System Uptime • Displays the duration the system has been up in hours, minutes and seconds. System Time •...
Page 25
Industrial Cellular VPN Router NR300 Series User Manual Active Link Information Link Type • Current interface for internet access. IP Address • Displays the IP address assigned to this interface. Netmask • Displays the subnet mask of this interface. Gateway •...
Industrial Cellular VPN Router NR300 Series User Manual 4.2.2 Syslog Syslog Information Download Diagnosis • Download the Diagnosis file for analysis. Download Syslog • Download the complete syslog since last reboot. Clear • Clear the current page syslog printing. Refresh •...
Industrial Cellular VPN Router NR300 Series User Manual Link Management This section shows you the setup of link management. 4.3.1 Connection Manager Connection Manager->Status Type • Displays the connection interface Status • Displays the connection status of this interface. IP Address •...
Page 28
Industrial Cellular VPN Router NR300 Series User Manual Connection Manager->Connection Priority • Displays the priority list of default routing selection. Enable • Displays the connection enable status. Connection Type • Displays the name of this interface. Description • Displays the description of this connection. Connection Settings Priority •...
Page 29
Industrial Cellular VPN Router NR300 Series User Manual Interval • The duration of each ICMP detection in seconds. Retry Interval • The interval in seconds between each ping if no packets have been received. Timeout • Enter timeout for received ping reply to determine the ICMP detection failure. Retry Times •...
Industrial Cellular VPN Router NR300 Series User Manual 4.3.2 Cellular NR300 Router main function is connecting to Internet by cellular modem. Cellular->Status Modem • Displays the module of the modem used by this WWAN interface. Registration • Displays the registration status of SIM card. •...
Page 31
Industrial Cellular VPN Router NR300 Series User Manual PLMN ID • Displays the current PLMN ID, including MCC, MNC, LAC and Cell ID. Local Area Code • Displays the location area code of the SIM card. Cell ID • Displays the Cell ID of the SIM card location. IMSI •...
Page 32
Industrial Cellular VPN Router NR300 Series User Manual SIM Card Settings SIM Card • Displays the current SIM card settings. Auto APN • Check this box enable auto checking the Access Point Name provided by the carrier. Dial Number • Enter the dial number of the carrier.
Industrial Cellular VPN Router NR300 Series User Manual 4.3.3 Ethernet The same instructions apply to settings for all Ethernet interfaces. Ethernet->Status Ethernet Port Information • Displays the port physical connected states. Interface Information • Displays the name and MAC address of Ethernet interface. DHCP Lease Table •...
Page 34
Industrial Cellular VPN Router NR300 Series User Manual Ethernet->Port Settings Port • Indicate the current configurate port. Interface • Select belong subnet for current configurate port. Ethernet->LAN Interface • Displays current name of LAN subnet. IP Address • Displays LAN IP address of this subnet. Netmask •...
Page 35
Industrial Cellular VPN Router NR300 Series User Manual Ethernet->LAN Interface • Select the configurate LAN port of this subnet. IP Address • Enter LAN IP address for this interface. Netmask • Enter subnet mask for this subnet. • Maximum Transmission Unit, maximum packet size allowed to be transmitted. Should be left as default value of 1500 in most cases.
Page 36
Industrial Cellular VPN Router NR300 Series User Manual Select the DHCP working mode from “Server” or “Relay”. Relay Server • Enter the IP address of DHCP relay server. IP Pool Start • External LAN devices connected to this unit will be assigned IP address in this range when DHCP is enabled.
Page 37
Industrial Cellular VPN Router NR300 Series User Manual Ethernet->VLAN->VLAN Trunk Settings Interface • Select the LAN port for VLAN trunk. • Specify the VLAN ID for VLAN trunk. IP Address • Enter IP address for this VLAN trunk. Netmask • Enter subnet mask for this VLAN trunk.
Industrial Cellular VPN Router NR300 Series User Manual 4.4 Industrial Interface The Industrial page contains tabs for making configuration settings for Serial RS232 and RS485. Select Serial from the main navigation menu to navigate to this page. 4.4.1 Serial You could review the status of serial connection. Serial->Status Enable •...
Page 39
Industrial Cellular VPN Router NR300 Series User Manual Serial->Connection Enable • Displays status of current serial function. Port • Displays the serial type of COM port. Baud Rate • Displays the serial port baud rate. Data Bits • Displays the serial port Data Bits. Stop Bits •...
Page 40
Industrial Cellular VPN Router NR300 Series User Manual Serial->Connection Settings Baud Rate • Select the serial port baud rate. Supported values are 300, 600, 1200, 2400, 4800, 9600, 19200, 38400, 57600, or 115200. Data Bits • Select the values from 7 or 8. Stop Bits •...
Page 41
Industrial Cellular VPN Router NR300 Series User Manual Below window displays different settings when you select UDP on Protocol. Serial->Connection Settings Local IP Address • Enter the IP Address of the local endpoint. Local Port • The port number assigned to the serial IP port on which communications will take place. Remote IP Address •...
Industrial Cellular VPN Router NR300 Series User Manual 4.5 Network 4.5.1 Firewall Firewall rules are security rule-sets to implement control over users, applications or network objects in an organization. Using the firewall rule, you can create blanket or specialized traffic transit rules based on the requirement.
Page 43
Industrial Cellular VPN Router NR300 Series User Manual Firewall->ACL Description • Add a description for this rule. Protocol • All: Any protocol number. TCP: The TCP protocol. UDP: The UDP protocol. TCP & DUP: both TCP and UDP protocol ICMP: The ICMP protocol. Source Address •...
Page 44
Industrial Cellular VPN Router NR300 Series User Manual Local Port • Sets the LAN port number range used when forwarding to the destination IP address. Firewall->DMZ Enable • Check this box to enable DMZ function. Remote Address • Optionally restricts DMZ access to only the specified WAN IP address. NOTE: If set to 0.0.0.0/0, the DMZ is open to all incoming WAN IP addresses.
Industrial Cellular VPN Router NR300 Series User Manual 4.5.2 Route Static Routing refers to a manual method of setting up routing between networks. Select the Static Routing tab to add static routes to the Static Route Table. Please refer current route table as below. Route->Route Table Information Destination •...
Industrial Cellular VPN Router NR300 Series User Manual IP Address • Enter the IP address of the destination network. Netmask • Enter the subnet mask of the destination network. Gateway • Enter the IP address of the local gateway. Interface •...
Industrial Cellular VPN Router NR300 Series User Manual 4.6 Applications 4.6.1 DDNS DDNS is a system that allows the domain name data of a computer with a varying (dynamic) IP addresses held in a name server to be updated in real time in order to make it possible to establish connections to that machine without the need to track the actual IP addresses at all times.
Industrial Cellular VPN Router NR300 Series User Manual Check IP Path • Check IP Path for custom type. Enable SSL • Enable SSL for connection. Username • Enter the user name used when setting up the account. Used to login to the Dynamic DNS service. Password •...
Industrial Cellular VPN Router NR300 Series User Manual 4.6.3 Schedule Reboot Schedule reboot allows user to define the time for router reboot itself. Application->Schedule Reboot Enable • Check this box to enable schedule reboot feature. Time to Reboot • Enter the time of each day to reboot device. Format: HH(00-23):MM(00-59). Day to Reboot •...
Industrial Cellular VPN Router NR300 Series User Manual 4.7 VPN 4.7.1 OpenVPN OpenVPN is an open source virtual private network (VPN) product that offers a simplified security framework, modular network design, and cross-platform portability. You could review all OpenVPN connection as below. VPN->OpenVPN->Status Enable •...
Page 51
Industrial Cellular VPN Router NR300 Series User Manual VPN->OpenVPN Enable • Check this box to enable OpenVPN tunnel. Description • Enter a description for this OpenVPN tunnel. Mode • Select from “Client” or “P2P”. Protocol • Select from “UDP” or “TCP Client”. Connection Type •...
Page 52
Industrial Cellular VPN Router NR300 Series User Manual Enter the negotiate port on OpenVPN server. Authentication Method • Select from "X.509", "Pre-shared", "Password", and "X.509 And Password". Encryption Type • Select from "BF-CBC", "DES-CBC", "DES-EDE-CBC", "DES-EDE3-CBC", "AES-128-CBC", "AES-192-CBC" and "AES-256-CBC". Username •...
Page 53
Industrial Cellular VPN Router NR300 Series User Manual VPN->OpenVPN->Advanced Settings Enable NAT • Check this box to enable NAT, the source IP of host behind router will be disguised before accessing the remote end. Enable PKCS#12 • It is an exchange of digital certificate encryption standard, used to describe personal identity information.
Page 54
Industrial Cellular VPN Router NR300 Series User Manual VPN->OpenVPN->X.509 Certificate Connection Index • Displays the current connection index for OpenVPN channel. CA Certificate • Import CA certificate file. Local Certificate File • Import Local Certificate file. Local Private Key • Import Local Private Key file.
Industrial Cellular VPN Router NR300 Series User Manual 4.7.2 IPSec IPSec facilitates configuration of secured communication tunnels. The various tunnel configurations will be displayed in the Tunnel Table at the bottom of the page. All tunnels are create using the ESP (Encapsulating Security Payload) protocol. VPN->IPSec->Status Enable •...
Page 56
Industrial Cellular VPN Router NR300 Series User Manual VPN->IPSec Enable • Select Enable will launch the IPSec process. Description • Enter a description for this IPSec VPN tunnel. Remote Gateway • Enter the IP address of the remote endpoint of the tunnel. IKE Version •...
Page 57
Industrial Cellular VPN Router NR300 Series User Manual VPN->IPSec Encryption Algorithm (IKE) • Select 3DES AES-128, AES-192, or AES-256 encryption. Hash Algorithm (IKE) • Select from MD5, SHA1, SHA2 256, SHA2 384 or SHA2 512 hashing. Diffie-Hellman Group (IKE) • Negotiate (None) or use 768 (Group 1), 1024 (Group 2), 1536 (Group 5) or 2048 (Group 14) etc.
Industrial Cellular VPN Router NR300 Series User Manual 4.7.3 GRE Generic Routing Encapsulation (GRE) is a protocol that encapsulates packets in order to route other protocols over IP networks. It’s a tunneling technology that provides a channel through which encapsulated data message could be transmitted and encapsulation and decapsulation could be realized at both ends.
Industrial Cellular VPN Router NR300 Series User Manual VPN->GRE Enable • Check this box to enable GRE. Description • Enter the description of current VPN channel. Mode • Specify the running mode of GRE, optional are “Layer 2” and “Layer 3”. Remote Gateway •...
Industrial Cellular VPN Router NR300 Series User Manual 4.8.2 Software When release a new feature(APP Package) of NR300 router, the user can manually install to the unit by uploading a package. Or user can uninstall this feature(APP Package) from router. NOTE: The unit need manually reboots once the upload/uninstall completes, thus taking the NR300 router out of service during approximately 1 minute.
Industrial Cellular VPN Router NR300 Series User Manual 4.8.3 System This section allows you to review the device system settings. System->General Hostname • User-defined router name, which might be use for IPSec local ID identify. User LED Type • Defined the User LED behavior. Time Zone •...
Page 62
Industrial Cellular VPN Router NR300 Series User Manual System->Account Administrator • Displays the name of current administrator, default as “admin”. Old Password • Enter the old password of administrator. New Password • Enter the new password of administrator. Confirm Password •...
Page 63
Industrial Cellular VPN Router NR300 Series User Manual Syslog displays system logs that are stored in the log buffers. System->Syslog Log Location • Select the log store location to “RAM”. Log Level • Select the log output level from “Debug”, “Notice”, “Info”, “Warning” or “Error”. Enable Remote Syslog •...
Page 64
Industrial Cellular VPN Router NR300 Series User Manual System->Telnet Telnet Port • Enter the port for telnet access. A well-known port for HTTP is port 23. System->SSH SSH Port • Enter the port for SSH access. A well-known port for HTTP is port 22. Allow Password Authentication •...
Industrial Cellular VPN Router NR300 Series User Manual Remote Telnet Access • Check this box to allow remote Telnet access. Remote SSH Access • Check this box to allow remote SSH access. DDoS Defenses • Check this box to enable DDoS defenses 4.8.4 Configuration The Unit Configuration tab allows you to save parameters (settings in the Web interface) to a file.
Page 66
Industrial Cellular VPN Router NR300 Series User Manual Ping Count • Enter the ping times. Local IP Address • Enter the ping source IP address or leave it blank. Debug Tools->Traceroute Host Address • Enter a host IP address or domain name for traceroute. Max Hops •...
Industrial Cellular VPN Router NR300 Series User Manual Appendix A -Glossary APN: Access Point Name GPRS: General Packet Radio Service HSPA: High Speed Packet Access HSDPA: High-Speed Downlink Packet Access HSUPA: High-Speed Uplink Packet Access LTE: 3GPP Long Term Evolution IMEI: International Mobile Equipment Identity ICCID:...
Industrial Cellular VPN Router NR300 Series User Manual Appendix B -Q&A No Signal Phenomenon NR300 Router modem status show no signal. Possible Reason Antenna installation is wrong. • Modem failure. • Solution Check the LTE antenna or replace with new one. •...
Industrial Cellular VPN Router NR300 Series User Manual IPSec VPN established, but LAN to LAN cannot communicate Phenomenon IPSec VPN established, but LAN to LAN cannot communicate Possible Reason Both subnets are not match the interested traffic. • IPSec second phase (ESP) settings is not match. •...
Command-line interface (CLI) is a software interface that provide another configurable way to set parameters on our router. We could use Telnet or SSH connect to our router for CLI input. NR300 CLI Access navigateworx.router login: admin Password: admin >...
Page 71
Industrial Cellular VPN Router NR300 Series User Manual How to Configure the CLI CONTEXT SENSITIVE HELP [?] - Display context sensitive help. This is either a list of possible command completions with summaries, or the full syntax of the current command. A subsequent repeat of this key, when a command has been resolved, will display a detailed reference.