Summary of Contents for Phoenix Contact PSI-MODEM-GSM/ETH
Page 1
INTERFACE User manual UM EN PSI-MODEM-GSM/ETH Order No.: 2910855 GPRS/EDGE modem with Ethernet interface...
Page 3
INTERFACE User Manual GPRS/EDGE modem with Ethernet interface 09/2009 Designation: UM EN PSI-MODEM-GSM/ETH Revision: Order No.: 2910855 This user manual is valid for: Designation Version Order No. PSI-MODEM-GSM/ETH 2313355 103965_en_00 PHOENIX CONTACT...
Page 4
Phoenix Contact accepts no liability for erroneous handling or damage to products from Phoenix Contact or third-party products resulting from disregard of information contained in this manual.
Page 5
The receipt of technical documentation (in particular data sheets, installation instructions, manuals, etc.) does not constitute any further duty on the part of Phoenix Contact to furnish information on alterations to products and/or technical documentation. Any other agreement shall only apply if expressly confirmed in writing by Phoenix Contact.
Page 6
Phoenix Contact. Violators are liable for damages. Phoenix Contact reserves all rights in the case of patent award or listing of a registered design, in as far as this concerns software of Phoenix Contact that meets the criteria of technicity or has technical relevance.
Description of the GSM modem Description The PSI-MODEM-GSM/ETH GSM modem is a high-performance modem for industrial Ethernet networks, which can be used to transmit sensitive data securely via GSM networks. The integrated firewall and the VPN support (Virtual Private Network) protect your application against unauthorized access.
PSI-MODEM-GSM/ETH Ordering data Modem Description Type Order No. Pcs./Pkt. Quad band modem for GPRS/EDGE and GSM with Ethernet interface, PSI-MODEM-GSM/ETH 2313355 firewall, VPN support, and alarm inputs and outputs Accessories Description Type Order No. Pcs./Pkt. GSM quad band antenna with omnidirectional characteristics...
Page 11
According to IEC 60068-2-32 from a height of 1 m (without packaging) Test voltage 1.5 kV AC, 50 Hz, 1 min. between all ground levels according to DIN EN 61010-1/VDE 0411-1 and DIN EN 60950 CE conformance According to R&TTE Directive 1999/5/EC 103965_en_00 PHOENIX CONTACT...
Page 12
PSI-MODEM-GSM/ETH Electromagnetic compatibility Noise immunity according to EN 61000-6-2 Electrostatic discharge (ESD) EN 61000-4-2 Criterion B 8 kV air discharge 6 kV contact discharge Electromagnetic HF field EN 61000-4-3 Criterion A Amplitude modulation 10 V/m Pulse modulation 10 V/m Fast transients (burst)
Hardware installation Hardware installation Housing dimensions PSI-MODEM-GSM/ETH Ord.-No. 23 13 355 103965A001 Figure 2-1 Housing dimensions (in mm) Mounting the module on a DIN rail NOTE: Only mount and remove the modem when the power supply is disconnected. NOTE: The DIN rail must be connected to PE to ensure safe operation.
PSI-MODEM-GSM/ETH Description of the connections and LEDs Connection terminal blocks Connection terminal blocks (COMBICON): 24 V power supply, 0 V power supply 6 switching inputs, digital 4 switching outputs, digital Connectors SMA female antenna connector PSI-MODEM-GSM/ETH RJ45, Ethernet interface (TP port) Ord.-No.
Disregarding this warning may result in damage to equipment and/or serious personal injury. WARNING: SELV operation The PSI-MODEM-GSM/ETH is designed exclusively for SELV operation according to IEC 60950/EN 60950/VDE 0805. WARNING: The modem must only be connected to devices, which meet the requirements of EN 60950 ("Safety of Information Technology Devices").
NOTE: Only use shielded twisted pair cables and corresponding shielded RJ45 connectors. The PSI-MODEM-GSM/ETH has an Ethernet interface on the front in RJ45 format, to which only twisted pair cables with an impedance of 100 Ω can be connected. •...
– The antenna has a diameter of 76 mm and is 21 mm high. – The cable is 2 meters long. • Secure the antenna using the washer and nut provided: 102678A005 Figure 2-5 PSI-GSM-900/1800-ANT antenna installation 103965_en_00 PHOENIX CONTACT...
PSI-MODEM-GSM/ETH 2.4.4 Inserting the SIM card WARNING: Disconnect the device power supply before replacing the SIM card. The device only supports 1.8 and 3 V SIM cards. For older SIM cards, please contact your GSM service provider. NOTE: Electrostatic discharge The module contains components that can be damaged or destroyed by electrostatic discharge.
Hardware installation 2.4.5 Connecting the supply voltage WARNING: The PSI-MODEM-GSM/ETH is designed exclusively for SELV operation according to IEC 60950/EN 60950/VDE 0805. The supply voltage must be between 10 V DC and 30 V DC. • Connect the 24 V supply voltage to the "24V" and "0V" terminal points on the plug-in screw terminal block.
PSI-MODEM-GSM/ETH 2.4.6 Connecting switching inputs and outputs NOTE: The switching outputs are only enabled in software release 1.xx or later. They are not available in earlier versions. O1 O2 24V 0V I1 I2 I3 I4 I5 I6 O3 O4 Figure 2-8 Wiring the inputs •...
Press and hold down the reset button (1). Reconnect the Ethernet cable and hold down the reset button for a further 5 seconds. The IP address is reset to the setting default upon delivery. The modem can be accessed via 192.168.0.1. 103965_en_00 PHOENIX CONTACT...
Starting web-based management (WBM) The PSI-MODEM-GSM/ETH is configured via web-based management (WBM). • Establish an Ethernet connection from the PSI-MODEM-GSM/ETH to a PC by means of an Internet connection. • Open a browser on the PC.
Page 24
PSI-MODEM-GSM/ETH • The user name is "admin" and the password is "admin". For security reasons, we recommend you change the password during initial configuration (see "User (Password modification)" on page 3-25). There are two user levels: – user: Read-only access to the "Device Information" menu item.
The MAC address enables the unique identification of an Ethernet device in a computer network. IMEI The IMEI (International Mobile Station Equipment Identity) is a 15-digit serial number, which can be used to clearly identify each GSM or UMTS termination device. 103965_en_00 PHOENIX CONTACT...
PSI-MODEM-GSM/ETH 3.3.2 Status Current status information about the GSM network and the network connections is displayed here. 3.3.2.1 Device Information >> Status >> GSM GSM Status Provider Provider name Networkstatus Status of the mobile phone network Registered home: Logged into the provider's home network...
Page 27
Sec. DNS Server IP address of the alternative DNS server Local Network Link The local Ethernet is connected (connected)/is not connected (not connected). IP Address Current Ethernet IP address Netmask Subnet mask of the local Ethernet network 103965_en_00 PHOENIX CONTACT...
PSI-MODEM-GSM/ETH Local Network (Set up local network) 3.4.1 IP Configuration (Set up connection) The connection from the modem to the local Ethernet computer can be set up here. The IP configuration can also be modified here. The IP address, subnet mask, and the type of address assignment can be set.
Depending on your contract, this can incur additional costs. Alternatively, you can specify a provider. Disable: Roaming is deactivated and only the provider's home network is used. If this network is unavailable, the modem cannot establish an Internet connection. 103965_en_00 PHOENIX CONTACT...
Page 30
PSI-MODEM-GSM/ETH Wireless Network >> GSM (continued) Provider Select a provider via which the modem is to establish the Internet connection. The country selected under Country limits the list of providers. Auto: The modem automatically selects the provider. PHOENIX CONTACT 103965_en_00...
Enable: Enable manual DNS setting. DNS Server IP address of the primary DNS server in the mobile phone network Sec. DNS Server IP address of the alternative DNS server in the mobile phone network 103965_en_00 PHOENIX CONTACT...
PSI-MODEM-GSM/ETH 3.5.3 PING This option can be used to influence behavior on receipt of ICMP packets, which are sent from the external GPRS network to the modem. A ping can be used to check whether a device in an IP network can be accessed. This can be useful during startup.
Disable: External configuration via WBM is not possible. Set Management external this option if you can configure and maintain the modem locally. Enable: The modem can be configured externally via WBM. Remote maintenance of the modem is thus possible. 3-11 103965_en_00 PHOENIX CONTACT...
PSI-MODEM-GSM/ETH Network Security (Security settings) 3.6.1 Firewall (Definition of firewall rules) The GSM modem includes a Stateful Packet Inspection Firewall. The connection data of an active connection is recorded in a database (connection tracking). Rules can thus only be defined for one direction. This means that data from the other direction of the relevant connection, and only this data, is automatically allowed through.
Page 35
Log set to No (default setting) The "New" button adds a new firewall rule below the last rule. The "Delete" button deletes the relevant rule from the table. The arrows can be used to move the rule up/down a row. 3-13 103965_en_00 PHOENIX CONTACT...
Page 36
PSI-MODEM-GSM/ETH Network Security >> Firewall Outgoing Traffic Lists the firewall rules that have been set up. They apply for outgoing data connections that have been initiated internally in order to communicate with a remote partner. Default setting: A rule is defined by default that permits all outgoing connections.
Log set to No (default setting) The "New" button adds a new rule below the last rule. The "Delete" button deletes the relevant rule from the table. The arrows can be used to move the rule up/down a row. 3-15 103965_en_00 PHOENIX CONTACT...
PSI-MODEM-GSM/ETH Requirements for a VPN connection A general requirement for a VPN connection is that the IP addresses of the VPN partner are known and can be accessed. – In order to successfully establish an IPsec connection, the VPN partner must support IPsec with the following configuration: –...
For two end points to create a secure connection, a key exchange procedure is required. With automatic key configuration, session keys are negotiated automatically via certificates. Click on Edit to specify the settings for IKE (see page 3-20). 3-17 103965_en_00 PHOENIX CONTACT...
Page 40
PSI-MODEM-GSM/ETH 3.7.1.1 Settings >> Edit VPN >> IPsec >> Connections >> Settings >> Edit IPsec Connection Settings Name The name of the VPN connection entered under IPsec Connections. Specifies whether the defined VPN connection should be active (Enable) or not (Disable).
Page 41
Here, specify the address of the network or computer, which is connected locally to the modem. Remote Connection Here you can specify from which side the connection can be established. The VPN connection is started by the modem (Initiate) or initiated by the partner (Accept). 3-19 103965_en_00 PHOENIX CONTACT...
Page 42
PSI-MODEM-GSM/ETH 3.7.1.2 IKE >> Edit VPN >> IPsec >> Connections >> IKE >> Edit IPsec - Internet Key Name The name of the VPN connection entered under IPsec Exchange Settings Connections. Phase 1 ISAKMP SA ISAKMP SA Encryption algorithm Encryption...
Page 43
Default setting: 30 seconds. DPD Timeout (sec.) Period of time in seconds after which the connection to the partner should be declared dead, if there has been no response to the Keep Alive requests. Default setting: 120 seconds. 3-21 103965_en_00 PHOENIX CONTACT...
PSI-MODEM-GSM/ETH 3.7.2 IPsec Certificates (Certificate upload) A certificate that is loaded on the modem is used to authenticate the modem at the partner. The certificate acts as an ID card for the modem, which it shows to the relevant partner.
Page 45
Overview of the imported PKCS#12 certificates. Click on "Delete" to delete a certificate. The symbols indicate whether a CA certificate, a machine certificate or a private key was found in the PKCS#12 file (green = present). 3-23 103965_en_00 PHOENIX CONTACT...
PSI-MODEM-GSM/ETH 3.7.3 IPsec Status (Status of the VPN connection) VPN >> IPsec >> Status Status Active IPsec Status of the active VPN connection. Connection 3-24 PHOENIX CONTACT 103965_en_00...
Old password: Old password New password: New password Retype new password: Enter new password again User Restricted access (read-only) Default: user Old password: Old password New password: New password Retype new password: Enter new password again 3-25 103965_en_00 PHOENIX CONTACT...
PSI-MODEM-GSM/ETH 3.8.2 Additional AT commands The AT command set is used to configure and parameterize modems. The "AT Commands" option is intended for use during servicing in order to access the GSM engine. It has no significance for normal use.
So that the GSM modem can act as the NTP server, it must reference the current date and the current time from an NTP server (time server). To do this, the address of an NTP server must be specified. In addition, NTP Synchronisation must be set to Enable. 3-27 103965_en_00 PHOENIX CONTACT...
Page 50
PSI-MODEM-GSM/ETH System >> RTC Daylight saving time Disable: Daylight saving is not taken into consideration. Enable: Daylight saving is taken into consideration. Time Server for Local Time Server Enable: The GSM modem acts as the time server in the local Network network.
Following a reboot the modem must log into the mobile phone network again. The provider resets the data connection and calculates charges. Regular rebooting provides protection against the provider aborting and reestablishing the connection at an unforeseeable point in time. Time Time specified in Hours:Minutes:Seconds. 3-29 103965_en_00 PHOENIX CONTACT...
PSI-MODEM-GSM/ETH 3.8.5 Firmware Update System >> Firmware Update Firmware Update GSM Updates can be installed for the firmware for the GSM Engine connection, the modem firmware, and web-based management. Firmware Update Modem Updates ensure that you can benefit from enhanced functions Update Web Based and product updates.
These instructions for creating self-signed certificates are based on Version 0.6.4 of the XCA program. • Once installed, start the XCA program. Figure 4-1 XCA Version 0.6.4 (1) • Create a new database via the "File… New DataBase" menu item. 103965_en_00 PHOENIX CONTACT...
Page 56
PSI-MODEM-GSM/ETH Figure 4-2 XCA Version 0.6.4 (2) • Assign a password to encrypt the database. • Select the "File... Options" menu item. Figure 4-3 XCA Version 0.6.4 (3) • Change the hash algorithm from SHA 256 to SHA 1. PHOENIX CONTACT...
• Switch to the "Certificate" tab and click on "New Certificate". Figure 4-4 XCA Version 0.6.4 (4) In the program window shown, there is already a preset self-signed certificate with the signature algorithm SHA-1. 103965_en_00 PHOENIX CONTACT...
Page 58
PSI-MODEM-GSM/ETH • Switch to the "Subject" tab. Figure 4-5 XCA Version 0.6.4 (5) • Here, enter the information about the owner of the root certificate. • Click on "Generate a new key". Figure 4-6 XCA Version 0.6.4 (6) • Do not change the default key size and type.
Page 59
In this example, the period of validity is set to 10 years. The certificate type is already set to "Certification Authority" by default. • Activate all the options as shown in Figure 4-7. 103965_en_00 PHOENIX CONTACT...
Page 60
PSI-MODEM-GSM/ETH • Switch to the "Key Usage" tab. Figure 4-8 XCA Version 0.6.4 (8) • Select the "Certificate Sign" and "CRL Sign" options and click "OK" to complete root certificate creation. This certificate has been successfully created. • A new root certificate is now listed in the overview, from which further machine certificates can be derived.
• Click on "New template" to create a terminal certificate. • In the "Preset Template values" prompt that appears, select "Nothing". On the "Subject" tab, specify the settings for the certificates that are to be created later. 103965_en_00 PHOENIX CONTACT...
Page 62
PSI-MODEM-GSM/ETH • The following window appears. Stay on the "Subject" tab. Figure 4-11 XCA Version 0.6.4 (11) Two names appear in angular brackets ("Internal name" and "Common name"). The names in the angular brackets are simply placeholders, as the actual names are assigned to the certificates.
Page 63
Change the certificate type to "End Entity", as the template is to be used for machine certificates. 365 days should be specified as the period of validity of the certificates to be created. After the resulting end date, the certificates can no longer be used. 103965_en_00 PHOENIX CONTACT...
Page 64
PSI-MODEM-GSM/ETH • Switch to the "Key Usage" tab. Figure 4-13 XCA Version 0.6.4 (13) • Select the "Digital Signature", "Data Encipherment", and "Key Agreement" options and click "OK" to create the template. The template can now be used to create certificates signed with the root certificate.
XCA Version 0.6.4 (14) • On the "Source" tab, specify the root certificate that is to be used for signing. • In addition, you can select a template that has been created and read it in by clicking "Apply". 4-11 103965_en_00 PHOENIX CONTACT...
Page 66
When entering information on this tab, please note that the certificates must differ at least with regard to their name ("Internal name" and "Common name"). For example, the equipment identification of the machine or PSI-MODEM-GSM/ETH modem can be used as the name here.
Page 67
In the previous steps, a self-signed certificate was created as a CA certificate. A machine certificate has now been created, which has been signed by the CA. Figure 4-17 XCA Version 0.6.4 (17) The machine certificate must be exported so that it can be used on the modem. 4-13 103965_en_00 PHOENIX CONTACT...
PSI-MODEM-GSM/ETH 4.4.3 Exporting machine certificates • Select the relevant certificate from the list and click on "Export". The entire certificate including the private key must be in PKCS#12 format and can then be uploaded to the relevant component as a machine certificate.
Log into web-based management as the administrator. • Open "VPN… IPsec… Certificates". First load the partner certificate (Remote Certificate). • To do this, click on "Browse" and select the corresponding *.crt certificate file. • Click "Apply" to load the certificate file. 103965_en_00 PHOENIX CONTACT...
Page 70
PSI-MODEM-GSM/ETH Next load the machine certificate (Own PKCS#12 Certificate). • To do this, click on "Browse" and select the corresponding *.p12 certificate file. • Click "Apply" to load the certificate file. The loaded certificates are shown at the bottom of the screen:...
Page 71
3-31). • Under Address Local Network, enter the IP address/subnet mask of the local network. Use CIDR format (see page 3-31). • For the modem that is to establish the VPN connection, select "Initiate" under Remote Connection. 103965_en_00 PHOENIX CONTACT...
PSI-MODEM-GSM/ETH • Then switch to "VPN… IPsec… Connections". • In the IKE column, click on "Edit" to set the IKE options. • Change ISAKMP SA Encryption and IPsec SA Encryption to "AES-128". • To ensure that the VPN connection is reestablished in the event of a connection abort, activate the "Restart"...
Click "Apply" to load the certificate file. Next load the machine certificate (Own PKCS#12 Certificate). • To do this, click on "Browse" and select the corresponding *.p12 certificate file. • Click "Apply" to load the certificate file. 103965_en_00 PHOENIX CONTACT...
Page 74
PSI-MODEM-GSM/ETH The loaded certificates are shown at the bottom of the screen: Setting up the VPN connection on the modem • Open "VPN… IPsec… Connections". • Assign a name to the IPsec VPN connection and confirm with "Apply". PHOENIX CONTACT...
Page 75
Under Address Local Network, enter the IP address/subnet mask of the local network. Use CIDR format (see page 3-31). The modem must establish the VPN connection. • Select "Initiate" under Remote Connection. • Then switch to "VPN… IPsec… Connections". 103965_en_00 PHOENIX CONTACT...
PSI-MODEM-GSM/ETH • In the IKE column, click on "Edit" to set the IKE options. • Change ISAKMP SA Encryption and IPsec SA Encryption to "AES-128". • To ensure that the VPN connection is reestablished in the event of a connection abort, activate the "Restart"...
Page 77
• To do this, click on "Browse" and select the corresponding *.crt certificate file. • Click on "Import". Once imported, the loaded certificate appears under Certificate. • Remember to save the imported certificate by clicking on "Apply". 103965_en_00 PHOENIX CONTACT...
PSI-MODEM-GSM/ETH 5.2.3 Setting a packet filter on the FL MGUARD RS VPN We recommend that communication is not restricted in the packet filter only when starting up the VPN connection. For normal operation, set the packet filter so that only your application's data traffic is permitted.
Page 79
Select the previously imported machine certificate as the Local X.509 Certificate. • Load the partner certificate (Remote Certificate). To do this, click on "Browse" and select the corresponding *.crt certificate file. • Click on "Upload" to load the certificate file. 5-11 103965_en_00 PHOENIX CONTACT...
Page 80
PSI-MODEM-GSM/ETH • Switch to the "IKE Options" tab. • Under ISAKMP SA (Key Exchange), change the Encryption Algorithm to "AES-128". • Under IPsec SA (Data Exchange), change the Encryption Algorithm to "AES-128". • Click "Apply" to save the changes. 5-12...
The VPN connection is established successfully and can be used. However, if this is not established possible, the VPN gateway is causing problems for the partner. In this case, deactivate and reactivate the connection to reestablish the connection. 5-13 103965_en_00 PHOENIX CONTACT...
Need help?
Do you have a question about the PSI-MODEM-GSM/ETH and is the answer not in the manual?
Questions and answers