CPU, HL31 supports setting up more than 200 node transmission at the same time with low power consumption. HL31 has a line of sight up to 1 km and supports data rates up to 32 Mbps, which is suitable for IoT sensors and picture camera applications.
1 × PoE Splitter 1 × Warranty Card (Optional) If any of the above items is missing or damaged, please contact your sales representative. 2.2 Hardware Overview 2.3 LED Indicator and Reset Button LED Indicators Indication Status Description The power is off Power &...
SIM card, press the SIM card and it will pop up automatically. 3.2 Power Supply HL31 can be powered by USB (5V) or a DC power connector (5-12V) by default. When installing the power cables, pass them with Ethernet cables through the groove.
Additionally, it can also be powered by an 802.3af standard PoE source via a PoE splitter. 3.3 Gateway Installation HL31 supports multiple installation methods like desktop, wall mounting, ceiling mounting, etc. Before you start, make sure that all cables have been installed and configurations are completed.
Page 10
2. Align the mounting plate horizontally to the desired position on the wall or ceiling to mark two mounting holes, drill two holes as these marks, insert wall plugs into the holes respectively. 3. Fix the mounting plate to the wall plugs with screws. 4.
Chapter 4 Access to Web GUI This chapter explains how to access to Web GUI of the HL31. Username: admin Password: password 4.1 Wireless Access 1. Enable Wireless Network Connection on your computer and search for access point Gateway_XXXXXX_2.4G, type default password iotpassword to connect it. (XXXXXX=last 6 digits of MAC address) 2.
5. You can view system information and perform configuration of the gateway. 4.2 Wired Access Connect PC to HL31 ETH port directly to access the web GUI of gateway. The following steps are based on Windows 10 system for your reference.
Page 13
2. Go to “Properties” → “Internet Protocol Version 4(TCP/IPv4)” and select “Use the following IP address”, then assign a static IP manually within the same subnet of the gateway. 3. Open a Web browser on your PC (Chrome is recommended) and type in the IP address 192.168.23.150 to access the web GUI.
Chapter 5 Application Examples 5.1 Wi-Fi HaLow Access Point Application Example Configure HL31 as Wi-Fi HaLow AP to allow connection from X1 Wi-Fi HaLow cameras. Configuration Steps 1. Go to Network > Interface > WLAN to configure wireless parameters and save the...
2. Select the region parameter of X1 camera the same as the gateway, search and connect to the access point of HL31. 3. Go to Status > WLAN of HL31 gateway, and you can check the AP settings and information of the connected client/user.
Page 16
through Ethernet port. Go to Network > Interface > Port page to select the connection type and configure Ethernet port configuration, then save the settings. Connect Ethernet port of gateway to network devices like router or modem. Go to Maintenance > Tools > Ping page to check network connectivity. Related Topic Port Setting...
5.3 Cellular Connection (Cellular Version Only) We are about to take an example of configuring the gateway to get access to the Internet through cellular. 1. Go to Network > Interface > Cellular > Cellular Setting and configure the necessary info of SIM card, then save the settings.
Related Topic Cellular Setting Cellular Status 5.4 Restore Factory Defaults Method 1: Log in web interface, and go to Maintenance > Backup and Restore, click Reset button, you will be asked to confirm if you’d like to reset it to factory defaults. Then click Reset button. Then the gateway will reboot and restore to factory settings immediately.
SYS LED blinks. 5.5 Firmware Upgrade It is suggested that you contact Milesight technical support first before you upgrade gateway firmware. The gateway firmware file suffix is “.bin”. After getting firmware file, please refer to the following steps to complete the upgrade.
Related Topic Upgrade Chapter 6 Operation Guide 6.1 Status 6.1.1 Overview System Information Item Description Model Show the model name of gateway. Region Show the Wi-Fi HaLow frequency region of gateway. Serial Number Show the serial number of gateway. Firmware Version Show the currently firmware version of gateway.
running. CPU Load Show the current CPU utilization of the gateway. RAM (Capacity/Available) Show the RAM capacity and the available RAM memory. eMMC (Capacity/Available) Show the eMMC capacity and the available eMMC memory. 6.1.2 Cellular (Cellular Version Only) You can view the cellular network status of gateway on this page. Modem Information Item Description...
PLMN ID Show the current PLMN ID, including MCC, MNC, LAC and Cell ID. Show the location area code of the SIM card. Cell ID Show the Cell ID of the SIM card location. Network Status Item Description Status Show the connection status of cellular network. IP Address Show the IP address of cellular network.
Show the DNS of the Ethernet port. Show the information about how long the Ethernet cable has been Duration connected to the Ethernet port when the port is enabled. Once the port is disabled or Ethernet cable is disconnected, the duration will stop. 6.1.4 WLAN You can check the Wi-Fi status on this page, including the information of the access point and client.
Name Show the name of the VPN tunnel. Status Show the status of the VPN tunnel. Local IP Show the local tunnel IP of VPN tunnel. Remote IP Show the remote tunnel IP of VPN tunnel. 6.1.6 Routing You can check routing status on this page, including the routing table and ARP cache. Item Description Routing Table...
Host List Item Description DHCP Leases Interface Show the interface: Wi-Fi HaLow or Wi-Fi 2.4G. Show IP address of DHCP client MAC Address Show MAC address of DHCP client Lease Time Remaining Show the remaining lease time of DHCP client. MAC Binding Interface Show the interface: Wi-Fi HaLow or Wi-Fi 2.4G.
Page 27
Item Description Default Port The port that is fixed as eth0 port and enabled. eth 0 Select from Static IP, DHCP Client and PPPoE. Static IP: configure IP address, netmask and gateway for Ethernet WAN interface. Connection DHCP Client: configure Ethernet WAN interface as Static IP Type DHCP Client to obtain IP address automatically.
Page 28
2. DHCP Client If the external network has DHCP server enabled and has assigned IP addresses to the Ethernet WAN interface, select this mode to obtain IP address automatically. DHCP Client Item Description Obtain peer DNS automatically during PPP dialing. DNS is Use Peer DNS necessary when user visits domain name.
6.2.1.2 WLAN This section explains how to set the related parameters for Wi-Fi 2.4G and Wi-Fi HaLow network. HL31 can work as Wi-Fi 2.4G or Wi-Fi HaLow access point to allow connections. Wi-Fi HaLow Settings Item Description Select working bandwidth.
Page 30
Select encryption mode. The options are “No Encryption", and Encryption Mode “WPA3-SAE". Fill in the pre-shared key of WPA3 encryption. Advanced Settings The region of the frequency. This parameter should be the same as Region Wi-Fi HaLow clients. Beacon Interval The interval to broadcast the beacons to Wi-Fi HaLow clients.
(2.4 GHz)", “802.11n (2.4 GHz)”. Select the wireless channel. The options are "Auto", "1", Channel "2".."13". The MAC address of the access point. Either SSID or BSSID can BSSID be filled to join the network. Fill in the SSID of the access point. Default: SSID Gateway_XXXXXX_2.4G (XXXXXX=last 6 digits of MAC address) Select encryption mode.
Page 32
General Settings Item Description Enable Enable or disable the device to register to cellular network. Select from Auto, Auto 3G/4G, 4G Only and 3G Only. Auto: connect to the network with the strongest signal automatically. Network Type 4G Only: connect to 4G network only. And so on.
Page 33
by local ISP. Enter the username for cellular dial-up connection provided by local Username ISP. Enter the password for cellular dial-up connection provided by local Password ISP. Enter the dial-up center NO. For cellular dial-up connection provided Access Number by local ISP. PIN Code Enter a 4-8 characters PIN code to unlock the SIM.
6.2.1.5 VLAN Trunk HL31 gateway supports the Ethernet port working as VLAN Trunk client and be assigned a VLAN ID, which easy to traffic classification. When VLAN ID is set, port on Network > Interface > Port can be chosen as eth0.x with x being VLAN ID. VLAN Setting is blank by...
VLAN Trunk Item Description Interface Select the VLAN interface, it’s fixed as eth0. Set the label ID of the VLAN. Range: 1-4094. 6.2.2 Firewall This section describes how to set the firewall parameters, including website block, ACL, DMZ, Port Mapping and MAC Binding. The firewall implements corresponding control of data flow at entry direction (from Internet to local area network) and exit direction (from local area network to Internet) according to the content features of packets, such as protocol style, source/destination IP...
Page 36
the field will be analyzed according to the ACL rule applied to the current interface. After the special packet is identified, the permission or prohibition of corresponding packet will be implemented according to preset strategy. The data package matching rules defined by ACL can also be used by other functions requiring flow distinction.
Source Port Set source port number. Range: 1-65535. Start Source Port Set start source port number. Range: 1-65535. End Source Port Set end source port number. Range: 1-65535. Destination Port Select destination port type, such as specified port, port range, Type etc.
Port Mapping Item Description Specify the host or network which can access local IP address. Source IP 0.0.0.0/0 means all. Enter the TCP or UDP port from which incoming packets are Source Port forwarded. Range: 1-65535. Enter the IP address that packets are forwarded to after receiving Destination IP from the incoming interface.
6.2.3 DHCP HL31 can be set as a DHCP server to distribute IP address to Wi-Fi clients. Wi-Fi HaLow and Wi-Fi 2.4G uses the same DHCP IP address range. DHCP Server Item Description Default Enable Enable or disable DHCP server.
6.2.4 DDNS Dynamic DNS (DDNS) is a method that automatically updates a name server in the Domain Name System, which allows user to alias a dynamic IP address to a static domain name. DDNS serves as a client tool and needs to coordinate with DDNS server. Before starting configuration, user shall register on a website of proper domain name provider and apply for a domain name.
ICMP-ECHO is the default type to detect if the Type icmp-echo link is alive. Destination Address The detected IP address. 8.8.8.8 Secondary The secondary detected IP address. 223.5.5.5 Destination Address Data Size User-defined data size. Range: 0-1000. Interval (s) User-defined detection interval. Range: 1-608400. 30 User-defined timeout for response to determine Timeout (ms) 5000...
Item Description Default Track index. Up to 10 track settings can be Index configured. Range: 1-10. Type The options are "sla" and "interface". SLA ID Defined SLA ID. Interface Select the interface whose status will be detected. ---- When interface is down or SLA probing fails, it will wait according to the time set here before actually Negative Delay (s) changing its status to Down.
Virtual Private Networks, also called VPNs, are used to securely connect two private networks together so that devices can connect from one network to the other network via secure channels. HL31 supports DMVPN, IPsec, GRE, L2TP, PPTP, OpenVPN, as well as GRE over IPsec and L2TP over IPsec. 6.2.6.1 DMVPN...
Page 44
DMVPN Item Description Enable Enable or disable DMVPN. Hub Address The IP address or domain name of DMVPN Hub. Local IP address DMVPN local tunnel IP address. GRE Hub IP Address GRE Hub tunnel IP address. GRE Local IP Address GRE local tunnel IP address.
IKE is used for cipher code exchange. All of them can protect one and more data flows between hosts, between host and gateway, and between gateways. HL31 supports running at most 3 IPsec clients at the same time.
Page 46
IPsec Item Description Enable or disable IPsec tunnel. A maximum of 3 tunnels is Enable allowed. IPsec Gateway Address Enter the IP address of remote IPsec server. IPsec Mode Select Tunnel or Transport. IPsec Protocol Select ESP or AH. Local Subnet Enter the local LAN subnet IP address on the IPsec tunnel.
Page 47
IKE Parameter Item Description IKE Version Select the method of key exchange of IKEv1 or IKEv2. Negotiation Mode Select from Main and Aggressive. Encryption Algorithm Select DES, 3DES, AES128, AES192 or AES256. Authentication Select from MD5 and SHA1. Algorithm DH Group Select MODP768_1, MODP1024_2 or MODP1536_5.
Single use of IPSec cannot achieve the encryption of multicast. A certain protocol adopted cannot be routed. A network of different IP addresses shall be required to connect other two similar networks. HL31 supports running at most 3 GRE clients at the same time.
Item Description Check to enable GRE function. A maximum of 3 tunnels is Enable allowed. Remote IP Address Enter the real remote IP address of GRE tunnel. Local IP Address Set the local IP address. Local Virtual IP Set the local tunnel IP address of GRE tunnel. Address Netmask Set the local netmask.
Page 50
L2TP Item Description Enable or disable L2TP client. A maximum of 3 tunnels is Enable allowed. Remote IP Address Enter remote L2TP server's IP address or domain name. Username Enter the username that L2TP server provides. Password Enter the password that L2TP server provides. Authentication Select authentication type used to secure data sessions.
Advanced Settings Item Description Set tunnel IP address of L2TP client. Client will obtain tunnel Local IP Address IP address automatically from the server when it's null. Peer IP Address Enter tunnel IP address of L2TP server. Enable NAT Enable NAT traversal function. Enable MPPE Enable or disable MPPE(Microsoft Point to Point Encryption) .
Page 52
PPTP Item Description Enable or disable PPTP client. A maximum of 3 tunnels is Enable allowed. Remote IP Address Enter remote PPTP server's IP address or domain name. Username Enter the username that PPTP server provides. Password Enter the password that PPTP server provides. Authentication Select authentication type used to secure data sessions.
6.2.6.6 OpenVPN Client OpenVPN is an open source virtual private network (VPN) product that offers a simplified security framework, modular network design, and cross-platform portability. HL31 supports running at most 3 OpenVPN clients at the same time.
Page 54
OpenVPN Client Item Description Enable Enable OpenVPN client. A maximum of 3 tunnels is allowed. Select a transport protocol used by connecting UDP and Protocol TCP. Remote IP Address Enter remote OpenVPN server's IP address or domain name. Enter the TCP/UCP service number of remote OpenVPN Port server.
Example: auth SHA256; key direction 1 Local Route Subnet Set the local route's IP address. Subnet Mask Set the local route's netmask. 6.2.6.7 OpenVPN Server HL31 supports OpenVPN server to create secure point-to-point or site-to-site connections in routed or bridged configurations and remote access facilities.
Page 56
OpenVPN Server Item Description Enable Enable/disable OpenVPN server. Select a transport protocol used by connection from UDP Protocol and TCP. Enter the TCP/UCP service number for OpenVPN client Port connection. Range: 1-65535. Enter the local hostname or IP address for bind. If left Listening IP blank, OpenVPN server will bind to all interfaces.
Page 57
Certifications page to import a static.key to PSK field. Username/Password: use username/password which is preset in server side to complete the authentication. X.509 cert: use X.509 type certificate to complete the authentication. After selecting, go to Network > VPN > Certifications page to import CA certificate, client certificate and client private key to corresponding fields.
separate the strings with semicolon. Example: auth SHA256; key direction 1 Local Route Subnet The real local IP address of OpenVPN client. Netmask The real local netmask of OpenVPN client. Account Set username and password for OpenVPN client when Username & Password authentication type is username/password.
6.3 System This section describes how to configure general settings, such as administration account, access service, system time, common user management, SNMP, event alarms, etc. 6.3.1 General Settings 6.3.1.1 General General settings include system info, access service and HTTPS certificates.
General Item Description Default System Hostname User-defined gateway name, needs to start with a letter. GATEWAY Web Login You need to log in again if it times out. Range: 100-3600. 1800 Timeout (s) Access Service Port Set port number of the services. Range: 1-65535. Users can log in the device locally via HTTP to access HTTP and control it through Web after the option is checked.
System Time Item Description Current Time Show the current system time. Time Zone Click the drop down list to select the time zone you are in. Click the drop down list to select the time synchronization type. Sync Type Sync with Browser: Synchronize time with browser. Sync with NTP Server: Synchronize time with NTP Server.
SMTP Item Description SMTP Client Settings Enable Enable or disable SMTP client function. Email Address Enter the sender's email account. Password Enter the sender's email password. SMTP Server Address Enter SMTP server's domain name. Port Enter SMTP server port. Range: 1-65535. Enable TLS Enable or disable TLS encryption.
Phone Number List Name Set phone group name. Enter the telephone number. Digits, "+" and "-" are allowed. Number You can divide multiple numbers by “;”. Related Topic Connect on Demand 6.3.1.5 Email Email settings involve email alarm for events. Email Item Description...
Account Item Description Enter a new username. You can use characters such as a-z, Username 0-9, "_", "-", "$". The first character can't be a digit. Old Password Enter the old password. New Password Enter a new password. Confirm New Password Enter the new password again.
Configure VCAM. 6.3.3.1 SNMP HL31 supports SNMPv1, SNMPv2c and SNMPv3 version. SNMPv1 and SNMPv2c employ community name authentication. SNMPv3 employs authentication encryption by username and password. SNMP Settings Item Description Enable Enable or disable SNMP function. Port Set SNMP listened port. Range: 1-65535. The default port is 161.
MIB View Item Description View Name Set MIB view's name. View Filter Select from "Included" and "Excluded". View OID Enter the OID number. Included You can query all nodes within the specified MIB node. Excluded You can query all nodes except for the specified MIB node. 6.3.3.3 VACM This section describes how to configure VCAM parameters.
Select an MIB view to set permission as "Read-only" from the MIB view Read-Only View list. Select an MIB view to set permission as "Read-write" from the MIB view Read-Write View list. Inform View Select an MIB view to set permission as "Inform" from the MIB view list. 6.3.3.4 Trap This section explains how to enable network monitoring by SNMP trap.
6.3.5 Events Event feature is capable of sending alerts by Email when certain system events occur. 6.3.5.1 Events You can view alarm messages on this page. Events Item Description Mark as Read Mark the selected event alarm as read. Delete Delete the selected event alarm.
Event Settings Item Description Enable Check to enable events settings. Phone for Select phone group to receive SMS alarm. Notification Email for Select Email group to receive Email alarm. Notification Events Event type the gateway supports to record. The relevant content of event alarm will be recorded on "Event" Record page if this option is checked.
6.4.1.3 Qxdmlog This section allow collecting diagnostic logs of cellular module via QXDM tool. 6.4.2 Schedule This section explains how to configure scheduled reboot on the gateway. Schedule Item Description Select schedule event: Schedule Reboot: Reboot the gateway regularly. Frequency Select the frequency to execute the schedule.
processes are loading successfully. Remote log server is feasible, and gateway will upload all system logs to remote log server such as Syslog Watcher. 6.4.3.1 System Log This section describes how to download log file and view the recent log on web. System Log Item Description...
Log Settings Item Description Remote Log Server With “Remote Log Server” enabled, gateway will send all Enable system logs to the remote server. Fill in the remote system log server address (IP/domain Syslog Server Address name). Port Fill in the remote system log server port. Local Log File Storage User can store the log file in memory or TF card.
replicate parts of important configuration only for batch backup, restore the config file to the gateway and reset to factory defaults. Backup and Restore Item Description Click "Browse" button to select configuration file, and then click "Import" Config File button to upload the configuration file to the gateway. Full Backup Click "Full Backup"...
Need help?
Do you have a question about the HL31 and is the answer not in the manual?
Questions and answers