Table of Contents

Advertisement

Quick Links

INTERFACE
User manual
UM EN PSI-MODEM-GSM/ETH
Order No.: 2910855
GPRS/EDGE modem with Ethernet interface

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the PSI-MODEM-GSM/ETH and is the answer not in the manual?

Questions and answers

Subscribe to Our Youtube Channel

Summary of Contents for Phoenix Contact PSI-MODEM-GSM/ETH

  • Page 1 INTERFACE User manual UM EN PSI-MODEM-GSM/ETH Order No.: 2910855 GPRS/EDGE modem with Ethernet interface...
  • Page 3 INTERFACE User Manual GPRS/EDGE modem with Ethernet interface 09/2009 Designation: UM EN PSI-MODEM-GSM/ETH Revision: Order No.: 2910855 This user manual is valid for: Designation Version Order No. PSI-MODEM-GSM/ETH 2313355 103965_en_00 PHOENIX CONTACT...
  • Page 4 Phoenix Contact accepts no liability for erroneous handling or damage to products from Phoenix Contact or third-party products resulting from disregard of information contained in this manual.
  • Page 5 The receipt of technical documentation (in particular data sheets, installation instructions, manuals, etc.) does not constitute any further duty on the part of Phoenix Contact to furnish information on alterations to products and/or technical documentation. Any other agreement shall only apply if expressly confirmed in writing by Phoenix Contact.
  • Page 6 Phoenix Contact. Violators are liable for damages. Phoenix Contact reserves all rights in the case of patent award or listing of a registered design, in as far as this concerns software of Phoenix Contact that meets the criteria of technicity or has technical relevance.
  • Page 7: Table Of Contents

    System ......................3-25 3.8.1 User (Password modification) ............3-25 3.8.2 Additional AT commands ..............3-26 3.8.3 RTC (Time and date setup) ............... 3-27 3.8.4 Reboot (Modem restart) ..............3-29 3.8.5 Firmware Update ................3-30 CIDR (Classless Inter-Domain Routing) ............3-31 103965_en_00 PHOENIX CONTACT...
  • Page 8 PSI-MODEM-GSM/ETH Creating certificates .........................4-1 Installing XCA ..................... 4-1 Creating a database ...................4-1 Creating a CA certificate..................4-3 Creating machine certificates ................4-7 4.4.1 Creating templates ................4-7 4.4.2 Creating machine certificates based on a template ......4-11 4.4.3 Exporting machine certificates ............4-14 Application examples for secure VPN connections..............5-1 Modem-to-modem connection via GPRS/EDGE ..........
  • Page 9: Description Of The Gsm Modem

    Description of the GSM modem Description The PSI-MODEM-GSM/ETH GSM modem is a high-performance modem for industrial Ethernet networks, which can be used to transmit sensitive data securely via GSM networks. The integrated firewall and the VPN support (Virtual Private Network) protect your application against unauthorized access.
  • Page 10: Ordering Data

    PSI-MODEM-GSM/ETH Ordering data Modem Description Type Order No. Pcs./Pkt. Quad band modem for GPRS/EDGE and GSM with Ethernet interface, PSI-MODEM-GSM/ETH 2313355 firewall, VPN support, and alarm inputs and outputs Accessories Description Type Order No. Pcs./Pkt. GSM quad band antenna with omnidirectional characteristics...
  • Page 11 According to IEC 60068-2-32 from a height of 1 m (without packaging) Test voltage 1.5 kV AC, 50 Hz, 1 min. between all ground levels according to DIN EN 61010-1/VDE 0411-1 and DIN EN 60950 CE conformance According to R&TTE Directive 1999/5/EC 103965_en_00 PHOENIX CONTACT...
  • Page 12 PSI-MODEM-GSM/ETH Electromagnetic compatibility Noise immunity according to EN 61000-6-2 Electrostatic discharge (ESD) EN 61000-4-2 Criterion B 8 kV air discharge 6 kV contact discharge Electromagnetic HF field EN 61000-4-3 Criterion A Amplitude modulation 10 V/m Pulse modulation 10 V/m Fast transients (burst)
  • Page 13: Hardware Installation

    Hardware installation Hardware installation Housing dimensions PSI-MODEM-GSM/ETH Ord.-No. 23 13 355 103965A001 Figure 2-1 Housing dimensions (in mm) Mounting the module on a DIN rail NOTE: Only mount and remove the modem when the power supply is disconnected. NOTE: The DIN rail must be connected to PE to ensure safe operation.
  • Page 14: Description Of The Connections And Leds

    PSI-MODEM-GSM/ETH Description of the connections and LEDs Connection terminal blocks Connection terminal blocks (COMBICON): 24 V power supply, 0 V power supply 6 switching inputs, digital 4 switching outputs, digital Connectors SMA female antenna connector PSI-MODEM-GSM/ETH RJ45, Ethernet interface (TP port) Ord.-No.
  • Page 15: Establishing Connections

    Disregarding this warning may result in damage to equipment and/or serious personal injury. WARNING: SELV operation The PSI-MODEM-GSM/ETH is designed exclusively for SELV operation according to IEC 60950/EN 60950/VDE 0805. WARNING: The modem must only be connected to devices, which meet the requirements of EN 60950 ("Safety of Information Technology Devices").
  • Page 16: Connecting Ethernet Networks

    NOTE: Only use shielded twisted pair cables and corresponding shielded RJ45 connectors. The PSI-MODEM-GSM/ETH has an Ethernet interface on the front in RJ45 format, to which only twisted pair cables with an impedance of 100 Ω can be connected. •...
  • Page 17: Connecting The Antenna

    – The antenna has a diameter of 76 mm and is 21 mm high. – The cable is 2 meters long. • Secure the antenna using the washer and nut provided: 102678A005 Figure 2-5 PSI-GSM-900/1800-ANT antenna installation 103965_en_00 PHOENIX CONTACT...
  • Page 18: Inserting The Sim Card

    PSI-MODEM-GSM/ETH 2.4.4 Inserting the SIM card WARNING: Disconnect the device power supply before replacing the SIM card. The device only supports 1.8 and 3 V SIM cards. For older SIM cards, please contact your GSM service provider. NOTE: Electrostatic discharge The module contains components that can be damaged or destroyed by electrostatic discharge.
  • Page 19: Connecting The Supply Voltage

    Hardware installation 2.4.5 Connecting the supply voltage WARNING: The PSI-MODEM-GSM/ETH is designed exclusively for SELV operation according to IEC 60950/EN 60950/VDE 0805. The supply voltage must be between 10 V DC and 30 V DC. • Connect the 24 V supply voltage to the "24V" and "0V" terminal points on the plug-in screw terminal block.
  • Page 20: Connecting Switching Inputs And Outputs

    PSI-MODEM-GSM/ETH 2.4.6 Connecting switching inputs and outputs NOTE: The switching outputs are only enabled in software release 1.xx or later. They are not available in earlier versions. O1 O2 24V 0V I1 I2 I3 I4 I5 I6 O3 O4 Figure 2-8 Wiring the inputs •...
  • Page 21: Resetting The Modem (Reset)

    Press and hold down the reset button (1). Reconnect the Ethernet cable and hold down the reset button for a further 5 seconds. The IP address is reset to the setting default upon delivery. The modem can be accessed via 192.168.0.1. 103965_en_00 PHOENIX CONTACT...
  • Page 22 PSI-MODEM-GSM/ETH 2-10 PHOENIX CONTACT 103965_en_00...
  • Page 23: Configuration Via Wbm

    Starting web-based management (WBM) The PSI-MODEM-GSM/ETH is configured via web-based management (WBM). • Establish an Ethernet connection from the PSI-MODEM-GSM/ETH to a PC by means of an Internet connection. • Open a browser on the PC.
  • Page 24 PSI-MODEM-GSM/ETH • The user name is "admin" and the password is "admin". For security reasons, we recommend you change the password during initial configuration (see "User (Password modification)" on page 3-25). There are two user levels: – user: Read-only access to the "Device Information" menu item.
  • Page 25: Device Information (View Device Status)

    The MAC address enables the unique identification of an Ethernet device in a computer network. IMEI The IMEI (International Mobile Station Equipment Identity) is a 15-digit serial number, which can be used to clearly identify each GSM or UMTS termination device. 103965_en_00 PHOENIX CONTACT...
  • Page 26: Status

    PSI-MODEM-GSM/ETH 3.3.2 Status Current status information about the GSM network and the network connections is displayed here. 3.3.2.1 Device Information >> Status >> GSM GSM Status Provider Provider name Networkstatus Status of the mobile phone network Registered home: Logged into the provider's home network...
  • Page 27 Sec. DNS Server IP address of the alternative DNS server Local Network Link The local Ethernet is connected (connected)/is not connected (not connected). IP Address Current Ethernet IP address Netmask Subnet mask of the local Ethernet network 103965_en_00 PHOENIX CONTACT...
  • Page 28: Local Network (Set Up Local Network)

    PSI-MODEM-GSM/ETH Local Network (Set up local network) 3.4.1 IP Configuration (Set up connection) The connection from the modem to the local Ethernet computer can be set up here. The IP configuration can also be modified here. The IP address, subnet mask, and the type of address assignment can be set.
  • Page 29: Wireless Network (Mobile Phone Settings)

    Depending on your contract, this can incur additional costs. Alternatively, you can specify a provider. Disable: Roaming is deactivated and only the provider's home network is used. If this network is unavailable, the modem cannot establish an Internet connection. 103965_en_00 PHOENIX CONTACT...
  • Page 30 PSI-MODEM-GSM/ETH Wireless Network >> GSM (continued) Provider Select a provider via which the modem is to establish the Internet connection. The country selected under Country limits the list of providers. Auto: The modem automatically selects the provider. PHOENIX CONTACT 103965_en_00...
  • Page 31: Gprs/Edge

    Enable: Enable manual DNS setting. DNS Server IP address of the primary DNS server in the mobile phone network Sec. DNS Server IP address of the alternative DNS server in the mobile phone network 103965_en_00 PHOENIX CONTACT...
  • Page 32: Ping

    PSI-MODEM-GSM/ETH 3.5.3 PING This option can be used to influence behavior on receipt of ICMP packets, which are sent from the external GPRS network to the modem. A ping can be used to check whether a device in an IP network can be accessed. This can be useful during startup.
  • Page 33: Remote Configuration (Remote Maintenance)

    Disable: External configuration via WBM is not possible. Set Management external this option if you can configure and maintain the modem locally. Enable: The modem can be configured externally via WBM. Remote maintenance of the modem is thus possible. 3-11 103965_en_00 PHOENIX CONTACT...
  • Page 34: Network Security (Security Settings)

    PSI-MODEM-GSM/ETH Network Security (Security settings) 3.6.1 Firewall (Definition of firewall rules) The GSM modem includes a Stateful Packet Inspection Firewall. The connection data of an active connection is recorded in a database (connection tracking). Rules can thus only be defined for one direction. This means that data from the other direction of the relevant connection, and only this data, is automatically allowed through.
  • Page 35 Log set to No (default setting) The "New" button adds a new firewall rule below the last rule. The "Delete" button deletes the relevant rule from the table. The arrows can be used to move the rule up/down a row. 3-13 103965_en_00 PHOENIX CONTACT...
  • Page 36 PSI-MODEM-GSM/ETH Network Security >> Firewall Outgoing Traffic Lists the firewall rules that have been set up. They apply for outgoing data connections that have been initiated internally in order to communicate with a remote partner. Default setting: A rule is defined by default that permits all outgoing connections.
  • Page 37: Nat Table (Addressing Table Setup)

    Log set to No (default setting) The "New" button adds a new rule below the last rule. The "Delete" button deletes the relevant rule from the table. The arrows can be used to move the rule up/down a row. 3-15 103965_en_00 PHOENIX CONTACT...
  • Page 38: Vpn

    PSI-MODEM-GSM/ETH Requirements for a VPN connection A general requirement for a VPN connection is that the IP addresses of the VPN partner are known and can be accessed. – In order to successfully establish an IPsec connection, the VPN partner must support IPsec with the following configuration: –...
  • Page 39: Ipsec Connections (Ipsec Connection Setup)

    For two end points to create a secure connection, a key exchange procedure is required. With automatic key configuration, session keys are negotiated automatically via certificates. Click on Edit to specify the settings for IKE (see page 3-20). 3-17 103965_en_00 PHOENIX CONTACT...
  • Page 40 PSI-MODEM-GSM/ETH 3.7.1.1 Settings >> Edit VPN >> IPsec >> Connections >> Settings >> Edit IPsec Connection Settings Name The name of the VPN connection entered under IPsec Connections. Specifies whether the defined VPN connection should be active (Enable) or not (Disable).
  • Page 41 Here, specify the address of the network or computer, which is connected locally to the modem. Remote Connection Here you can specify from which side the connection can be established. The VPN connection is started by the modem (Initiate) or initiated by the partner (Accept). 3-19 103965_en_00 PHOENIX CONTACT...
  • Page 42 PSI-MODEM-GSM/ETH 3.7.1.2 IKE >> Edit VPN >> IPsec >> Connections >> IKE >> Edit IPsec - Internet Key Name The name of the VPN connection entered under IPsec Exchange Settings Connections. Phase 1 ISAKMP SA ISAKMP SA Encryption algorithm Encryption...
  • Page 43 Default setting: 30 seconds. DPD Timeout (sec.) Period of time in seconds after which the connection to the partner should be declared dead, if there has been no response to the Keep Alive requests. Default setting: 120 seconds. 3-21 103965_en_00 PHOENIX CONTACT...
  • Page 44: Ipsec Certificates (Certificate Upload)

    PSI-MODEM-GSM/ETH 3.7.2 IPsec Certificates (Certificate upload) A certificate that is loaded on the modem is used to authenticate the modem at the partner. The certificate acts as an ID card for the modem, which it shows to the relevant partner.
  • Page 45 Overview of the imported PKCS#12 certificates. Click on "Delete" to delete a certificate. The symbols indicate whether a CA certificate, a machine certificate or a private key was found in the PKCS#12 file (green = present). 3-23 103965_en_00 PHOENIX CONTACT...
  • Page 46: Ipsec Status (Status Of The Vpn Connection)

    PSI-MODEM-GSM/ETH 3.7.3 IPsec Status (Status of the VPN connection) VPN >> IPsec >> Status Status Active IPsec Status of the active VPN connection. Connection 3-24 PHOENIX CONTACT 103965_en_00...
  • Page 47: System

    Old password: Old password New password: New password Retype new password: Enter new password again User Restricted access (read-only) Default: user Old password: Old password New password: New password Retype new password: Enter new password again 3-25 103965_en_00 PHOENIX CONTACT...
  • Page 48: Additional At Commands

    PSI-MODEM-GSM/ETH 3.8.2 Additional AT commands The AT command set is used to configure and parameterize modems. The "AT Commands" option is intended for use during servicing in order to access the GSM engine. It has no significance for normal use.
  • Page 49: Rtc (Time And Date Setup)

    So that the GSM modem can act as the NTP server, it must reference the current date and the current time from an NTP server (time server). To do this, the address of an NTP server must be specified. In addition, NTP Synchronisation must be set to Enable. 3-27 103965_en_00 PHOENIX CONTACT...
  • Page 50 PSI-MODEM-GSM/ETH System >> RTC Daylight saving time Disable: Daylight saving is not taken into consideration. Enable: Daylight saving is taken into consideration. Time Server for Local Time Server Enable: The GSM modem acts as the time server in the local Network network.
  • Page 51: Reboot (Modem Restart)

    Following a reboot the modem must log into the mobile phone network again. The provider resets the data connection and calculates charges. Regular rebooting provides protection against the provider aborting and reestablishing the connection at an unforeseeable point in time. Time Time specified in Hours:Minutes:Seconds. 3-29 103965_en_00 PHOENIX CONTACT...
  • Page 52: Firmware Update

    PSI-MODEM-GSM/ETH 3.8.5 Firmware Update System >> Firmware Update Firmware Update GSM Updates can be installed for the firmware for the GSM Engine connection, the modem firmware, and web-based management. Firmware Update Modem Updates ensure that you can benefit from enhanced functions Update Web Based and product updates.
  • Page 53: Cidr (Classless Inter-Domain Routing)

    11110000 00000000 00000000 00000000 4 224.0.0.0 11100000 00000000 00000000 00000000 3 192.0.0.0 11000000 00000000 00000000 00000000 2 128.0.0.0 10000000 00000000 00000000 00000000 1 0.0.0.0 00000000 00000000 00000000 00000000 0 Example: 192.168.1.0/255.255.255.0 corresponds in CIDR format to: 192.168.1.0/24 3-31 103965_en_00 PHOENIX CONTACT...
  • Page 54 PSI-MODEM-GSM/ETH 3-32 PHOENIX CONTACT 103965_en_00...
  • Page 55: Creating Certificates

    These instructions for creating self-signed certificates are based on Version 0.6.4 of the XCA program. • Once installed, start the XCA program. Figure 4-1 XCA Version 0.6.4 (1) • Create a new database via the "File… New DataBase" menu item. 103965_en_00 PHOENIX CONTACT...
  • Page 56 PSI-MODEM-GSM/ETH Figure 4-2 XCA Version 0.6.4 (2) • Assign a password to encrypt the database. • Select the "File... Options" menu item. Figure 4-3 XCA Version 0.6.4 (3) • Change the hash algorithm from SHA 256 to SHA 1. PHOENIX CONTACT...
  • Page 57: Creating A Ca Certificate

    • Switch to the "Certificate" tab and click on "New Certificate". Figure 4-4 XCA Version 0.6.4 (4) In the program window shown, there is already a preset self-signed certificate with the signature algorithm SHA-1. 103965_en_00 PHOENIX CONTACT...
  • Page 58 PSI-MODEM-GSM/ETH • Switch to the "Subject" tab. Figure 4-5 XCA Version 0.6.4 (5) • Here, enter the information about the owner of the root certificate. • Click on "Generate a new key". Figure 4-6 XCA Version 0.6.4 (6) • Do not change the default key size and type.
  • Page 59 In this example, the period of validity is set to 10 years. The certificate type is already set to "Certification Authority" by default. • Activate all the options as shown in Figure 4-7. 103965_en_00 PHOENIX CONTACT...
  • Page 60 PSI-MODEM-GSM/ETH • Switch to the "Key Usage" tab. Figure 4-8 XCA Version 0.6.4 (8) • Select the "Certificate Sign" and "CRL Sign" options and click "OK" to complete root certificate creation. This certificate has been successfully created. • A new root certificate is now listed in the overview, from which further machine certificates can be derived.
  • Page 61: Creating Machine Certificates

    • Click on "New template" to create a terminal certificate. • In the "Preset Template values" prompt that appears, select "Nothing". On the "Subject" tab, specify the settings for the certificates that are to be created later. 103965_en_00 PHOENIX CONTACT...
  • Page 62 PSI-MODEM-GSM/ETH • The following window appears. Stay on the "Subject" tab. Figure 4-11 XCA Version 0.6.4 (11) Two names appear in angular brackets ("Internal name" and "Common name"). The names in the angular brackets are simply placeholders, as the actual names are assigned to the certificates.
  • Page 63 Change the certificate type to "End Entity", as the template is to be used for machine certificates. 365 days should be specified as the period of validity of the certificates to be created. After the resulting end date, the certificates can no longer be used. 103965_en_00 PHOENIX CONTACT...
  • Page 64 PSI-MODEM-GSM/ETH • Switch to the "Key Usage" tab. Figure 4-13 XCA Version 0.6.4 (13) • Select the "Digital Signature", "Data Encipherment", and "Key Agreement" options and click "OK" to create the template. The template can now be used to create certificates signed with the root certificate.
  • Page 65: Creating Machine Certificates Based On A Template

    XCA Version 0.6.4 (14) • On the "Source" tab, specify the root certificate that is to be used for signing. • In addition, you can select a template that has been created and read it in by clicking "Apply". 4-11 103965_en_00 PHOENIX CONTACT...
  • Page 66 When entering information on this tab, please note that the certificates must differ at least with regard to their name ("Internal name" and "Common name"). For example, the equipment identification of the machine or PSI-MODEM-GSM/ETH modem can be used as the name here.
  • Page 67 In the previous steps, a self-signed certificate was created as a CA certificate. A machine certificate has now been created, which has been signed by the CA. Figure 4-17 XCA Version 0.6.4 (17) The machine certificate must be exported so that it can be used on the modem. 4-13 103965_en_00 PHOENIX CONTACT...
  • Page 68: Exporting Machine Certificates

    PSI-MODEM-GSM/ETH 4.4.3 Exporting machine certificates • Select the relevant certificate from the list and click on "Export". The entire certificate including the private key must be in PKCS#12 format and can then be uploaded to the relevant component as a machine certificate.
  • Page 69: Application Examples For Secure Vpn Connections

    Log into web-based management as the administrator. • Open "VPN… IPsec… Certificates". First load the partner certificate (Remote Certificate). • To do this, click on "Browse" and select the corresponding *.crt certificate file. • Click "Apply" to load the certificate file. 103965_en_00 PHOENIX CONTACT...
  • Page 70 PSI-MODEM-GSM/ETH Next load the machine certificate (Own PKCS#12 Certificate). • To do this, click on "Browse" and select the corresponding *.p12 certificate file. • Click "Apply" to load the certificate file. The loaded certificates are shown at the bottom of the screen:...
  • Page 71 3-31). • Under Address Local Network, enter the IP address/subnet mask of the local network. Use CIDR format (see page 3-31). • For the modem that is to establish the VPN connection, select "Initiate" under Remote Connection. 103965_en_00 PHOENIX CONTACT...
  • Page 72: Setting Up Modem 2

    PSI-MODEM-GSM/ETH • Then switch to "VPN… IPsec… Connections". • In the IKE column, click on "Edit" to set the IKE options. • Change ISAKMP SA Encryption and IPsec SA Encryption to "AES-128". • To ensure that the VPN connection is reestablished in the event of a connection abort, activate the "Restart"...
  • Page 73: Connection From A Modem To A Control Center Via Gprs/Edge And The Internet

    Click "Apply" to load the certificate file. Next load the machine certificate (Own PKCS#12 Certificate). • To do this, click on "Browse" and select the corresponding *.p12 certificate file. • Click "Apply" to load the certificate file. 103965_en_00 PHOENIX CONTACT...
  • Page 74 PSI-MODEM-GSM/ETH The loaded certificates are shown at the bottom of the screen: Setting up the VPN connection on the modem • Open "VPN… IPsec… Connections". • Assign a name to the IPsec VPN connection and confirm with "Apply". PHOENIX CONTACT...
  • Page 75 Under Address Local Network, enter the IP address/subnet mask of the local network. Use CIDR format (see page 3-31). The modem must establish the VPN connection. • Select "Initiate" under Remote Connection. • Then switch to "VPN… IPsec… Connections". 103965_en_00 PHOENIX CONTACT...
  • Page 76: Loading Certificates On The Fl Mguard Rs Vpn

    PSI-MODEM-GSM/ETH • In the IKE column, click on "Edit" to set the IKE options. • Change ISAKMP SA Encryption and IPsec SA Encryption to "AES-128". • To ensure that the VPN connection is reestablished in the event of a connection abort, activate the "Restart"...
  • Page 77 • To do this, click on "Browse" and select the corresponding *.crt certificate file. • Click on "Import". Once imported, the loaded certificate appears under Certificate. • Remember to save the imported certificate by clicking on "Apply". 103965_en_00 PHOENIX CONTACT...
  • Page 78: Setting A Packet Filter On The Fl Mguard Rs Vpn

    PSI-MODEM-GSM/ETH 5.2.3 Setting a packet filter on the FL MGUARD RS VPN We recommend that communication is not restricted in the packet filter only when starting up the VPN connection. For normal operation, set the packet filter so that only your application's data traffic is permitted.
  • Page 79 Select the previously imported machine certificate as the Local X.509 Certificate. • Load the partner certificate (Remote Certificate). To do this, click on "Browse" and select the corresponding *.crt certificate file. • Click on "Upload" to load the certificate file. 5-11 103965_en_00 PHOENIX CONTACT...
  • Page 80 PSI-MODEM-GSM/ETH • Switch to the "IKE Options" tab. • Under ISAKMP SA (Key Exchange), change the Encryption Algorithm to "AES-128". • Under IPsec SA (Data Exchange), change the Encryption Algorithm to "AES-128". • Click "Apply" to save the changes. 5-12...
  • Page 81: Checking The Status Of The Vpn Connection In Mguard

    The VPN connection is established successfully and can be used. However, if this is not established possible, the VPN gateway is causing problems for the partner. In this case, deactivate and reactivate the connection to reestablish the connection. 5-13 103965_en_00 PHOENIX CONTACT...
  • Page 82 PSI-MODEM-GSM/ETH 5-14 PHOENIX CONTACT 103965_en_00...

This manual is also suitable for:

2910855

Table of Contents