Page 2
LANCOM Systems shall be liable only to the degree specified in the terms of sale and delivery. The reproduction and distribution of the documentation and software included with this product is subject to written per- mission by LANCOM Systems. We reserve the right to make any alterations that arise as the result of technical develop- ment.
Page 3
LANCOM 7111 VPN – LANCOM 8011 VPN Preface Preface Thank you for placing your trust in this LANCOM Systems product. The top models of the LANCOM router series serve as extremely powerful Dynamic VPN gateways for medium-sized and large locations.
Page 4
LANCOM 7111 VPN – LANCOM 8011 VPN Preface We ask you additionally to inform you about technical developments and actual hints to your product on our Web page www.lancom.de, and to down- load new software versions if necessary. User manual and reference manual The documentation of your device consists of two parts: the user manual and the reference manual.
Page 5
In addition support from LANCOM Systems is also available to you. Telephone numbers and contact information for LANCOM Systems support can be found on a separate insert, or at the LANCOM Systems website.
LANCOM 7111 VPN – LANCOM 8011 VPN Contents Contents 1 Introduction 1.1 Which use does VPN offer? 1.2 Firewall 1.3 What does a router do? 1.3.1 Bridgehead to the WAN 1.3.2 Areas of deployment for routers 1.4 What can your LANCOM router do? 2 Installation 2.1 Package contents...
Page 7
LANCOM 7111 VPN – LANCOM 8011 VPN Contents 5 Linking two networks 5.1 What information is necessary? 5.1.1 General information 5.1.2 Settings for the TCP/IP router 5.1.3 Settings for the IPX router 5.1.4 Settings for NetBIOS routing 5.2 Instructions for LANconfig 5.3 Instructions for WEBconfig...
Page 8
LANCOM 7111 VPN – LANCOM 8011 VPN Contents 9 Troubleshooting 9.1 No WAN connection is established 9.2 DSL data transfer is slow 9.3 Unwanted connections under Windows XP 9.4 Cable testing 10 Appendix 10.1 Performance data and specifications 10.2 Contact assignment 10.2.1 DSL interface...
A VPN (Virtual Private Network) can be used to set up cost-effective, public IP networks, for example via the ultimate network: the Internet. The model LANCOM 7111 VPN is equipped with 100 VPN channels by default, the LANCOM 8011 VPN with 200 channels. With the addi- tional LANCOM VPN Option the LANCOM 8011 VPN can be upgraded to 500 or 1000 channels.
Page 10
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 1: Introduction Conventional network infrastructure First, let's have a look at a typical network structure that can be found in this form or similar forms in many companies: Head Office ISDN ISDN...
Page 11
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 1: Introduction to the original investment costs, ongoing costs are also incurred for the administration and maintenance of this equipment. Networking via the Internet The following structure results when using the Internet instead of direct con-...
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 1: Introduction technologies such as DSL (Digital Subscriber Line) or G.703 (2-Mbit leased lines). But also a conventional ISDN line can be used. The technologies of the individual participants do not have to be compatible to one another, as would be the case for conventional direct connections.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 1: Introduction Denial-of-Service Protection Attacks from the Internet can be break-in attempts as well as attacks with the aim of blocking the accessibility and functionality of individual services. Therefore a LANCOM Wireless DSL is equipped with appropriate protective mechanisms, which recognize well-known hacker attacks and which guarantee the functionality.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 1: Introduction Connecting a LAN to the Internet does not technically differ from coupling two LANs. The only difference is that it is not just a handful of computers behind the Internet provider's router. Instead, it is the net of the networks - the public Internet.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 1: Introduction access to the Internet is required on either side of the network inter- connection. VPN tunnel via the Internet VPN gateways Conventional via ISDN Without VPN, a LAN to LAN interconnection can alternatively be real- ized via ISDN.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 1: Introduction LANCOM 7111 LANCOM 8011 RAS server (via VPN) 100 tunnel 200 tunnel, optional 500 or 1000 RAS server (via ISDN) IP router IPX router (via ISDN), e.g. for coupling of Novell networks or dialling...
Page 17
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 1: Introduction LANCOM 7111 LANCOM 8011 Quality of Service Dynamic bandwidth management / IP-Traffic Shaping Bandwidth limiting with absolute or per connection transfer limits, separated from send or receive site TOS or DiffServ priority queuing Automatic packet size adaption incl.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 2: Installation 2 Installation This chapter will assist you to quickly install hardware and software. First, check the package contents and system requirements. The device can be installed and configured quickly and easily if all prerequisites are fulfilled.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 2: Installation Operating system that supports TCP/IP, e.g. Windows XP, Windows Mil- lennium Edition (Me), Windows 2000, Windows 98, Windows 95, Win- dows NT, Linux, BSD Unix, Apple Mac OS, OS/2, BeOS.
Page 20
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 2: Installation Flashing means, that the LED lights up very briefly in the respective col- our and stay then clearly longer (approximately 10x longer) switched off. Inverse flashing means the opposite. The LED lights permanently in the respective colour and is only briefly interrupted.
Page 21
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 2: Installation Flashing Power LED but no connection? LANCOM There's no need to worry if the Power LED blinks red and you can no Systems longer connect to the WAN. This simply indicates that a preset time or connect-charge limit has been reached.
Page 22
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 2: Installation ETH 1 to ETH 4 Connection status and data traffic of the four LAN ports with integrated switch:. No network device connected green constantly on Connection to network device, no data traffic...
Page 23
ISDN status LED will once again light up green. ISDN Chan 1 Data traffic on the ISDN B channels (separate per B channel with LANCOM ISDN Chan 2 7111 VPN, for both ISDN B channels with LANCOM 8011 VPN): No connection established green blinking Dialling...
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 2: Installation 2.3.2 The back of the unit Ports and switches of the router are placed on the front and back: LANCOM 8011 VPN ISDN ETH4 ETH3 ETH2 ETH1 The following ports can be found on the front side:...
Page 25
With the LANCOM 7111 VPN only use the included power supply unit! Using an unsuitable power supply unit may cause damage or injury. Operational? – After a short device self-test the Power LED will be per- manently lit.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 2: Installation Example for LANCOM 8011 VPN Configuration PC with serial port ISDN-(NTBA) Network terminator, e.g. SDSL modem Software installation This section covers the installation of the included system software LANtools for Windows.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 2: Installation In Setup select Install LANCOM Software. The following selection menus will appear on the screen: 2.5.2 Which software should you install? LANconfig is the configuration program for all LANCOM routers and Wireless LAN access points.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 3: Basic configuration 3 Basic configuration The basic configuration can be performed on a step-by-step basis using a convenient setup wizard to guide you through the setup process and prompt you for the required information.
Page 29
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 3: Basic configuration New LAN—fully automatic configuration possible If all connected network devices are still unconfigured, the setup wizard will suggest fully automatic TCP/IP configuration. This may be the case in the fol-...
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 3: Basic configuration Enable DHCP server? Disable the DHCP server function in the LANCOM router if you would like to have a different DHCP server assign the IP addresses in your LAN.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 3: Basic configuration 3.1.5 Connect charge protection Connect charge protection blocks connections that go beyond a previously set amount, protecting you from unexpectedly high connection costs. In a LANCOM router, there are three independent budgets: For DSL access, you can set a maximum connection time in minutes.
Page 32
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 3: Basic configuration hosts (netmask > '255.255.255.0'), please ensure that the IP address 'x.x.x.254' is located in your own subnet. If you have chosen automatic TCP/IP configuration, please continue with Step If you would like to configure the TCP/IP settings manually, assign an available address from a suitable address range to the LANCOM router.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 3: Basic configuration Section ’TCP/IP settings to workstation PCs’ on page 37 will describe the settings required for the individual workstations in the LAN. Instructions for WEBconfig To configure the router with WEBconfig you must know how to address it in the LAN.
Page 34
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 3: Basic configuration address x.x.x.254 ( “x” stands for the first three blocks in the IP address of the configuration PC). Network with DHCP server If a DHCP server is active in the LAN to assign IP addresses, an unconfigured LANCOM device will turn off its own DHCP server.
Page 35
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 3: Basic configuration If you cannot access an unconfigured LANCOM router, the problem may be due to the netmask of the LAN: with less than 254 possible hosts (netmask > '255.255.255.0'), please ensure that the IP address 'x.x.x.254' is located in your own subnet.
Page 36
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 3: Basic configuration In the following 'Security settings' window, specify a password for config- uration access. Note that the password is case-sensitive and ensure that it is sufficiently long (at least 6 characters).
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 3: Basic configuration Connect charge protection can limit the cost of DSL and ISDN connections to a predetermined amount if desired. Confirm your choice with Apply. If your devices does not feature an ISDN port, you may now close the setup wizard.
Page 38
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 3: Basic configuration IP address assignment via a separate DHCP server The workstation PCs must be configured so that they automatically obtain their own IP address and the IP addresses of the standard gateway and DNS server (via DHCP).
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 4: Setting up Internet access 4 Setting up Internet access All computers in the LAN can take advantage of the central Internet access of the LANCOM router. The connection to the Internet provider can be estab- lished via any WAN connection.
Page 40
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 4: Setting up Internet access ISDN – dial-in number User name and password Additional connection options You may also enable or disable further options in the wizard, depending on whether or not they are supported by your Internet provider: Time-based billing or flat rate –...
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 4: Setting up Internet access Instructions for LANconfig Highlight the LANCOM router in the selection window. From the menu bar, select Tools Setup Wizard. From the menu, select the Setup Internet access wizard and click Next.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 5: Linking two networks 5 Linking two networks With the network interconnection (also known as LAN to LAN coupling) of the LANCOM router, two local networks are linked. The LAN to LAN coupling can...
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 5: Linking two networks The ISDN call back function cannot be configured using the wizard. It can only be set up in the expert configuration. For details, please see the reference manual.
Page 44
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 5: Linking two networks Coupling Entry Gateway 1 Gateway 2 Netmask of the remote network 255.255.255.0 255.255.255.0 Domain name of the remote network 'head' 'branch' Hide local stations for access to remote net-...
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 5: Linking two networks The password for the ISDN connection is an alternative to the use of the ISDN caller ID. It is always used to authenticate callers that do not send an ISDN caller ID. The exact same password must be entered on both sides.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 5: Linking two networks DNS access to the remote LAN Thanks to DNS, it is not only possible to access remote computers in a TCP/IP network via their IP address, but also by using freely defined names.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 5: Linking two networks for the LAN of the head office for the LAN of the branch office for the higher-level WAN The IPX network numbers in the head and branch offices are specified to the respective remote sides.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 5: Linking two networks Remote Windows workgroups do not appear in the Windows Network Neighbourhood, but can only be contacted directly (e.g. via Find Computers). Instructions for LANconfig Perform the configuration on both routers, one at a time.
Page 49
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 5: Linking two networks From the main menu, launch the 'Connect two local area networks' wiz- ard. Follow the wizard's instructions and enter the required information. The wizard will return a message to indicate that it has all the information it needs.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 6: Providing dial- up access 6 Providing dial-up access Your LANCOM router supports dial-up connections to permit individual com- puters full access to your network. This service is also known as RAS (Remote Access Service).
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 6: Providing dial- up access 6.1.1 General information The following entries are required to set up a RAS connection. The first column indicates whether the information is required for a VPN and/or an ISDN con- nection.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 6: Providing dial- up access 6.1.2 Settings for TCP/IP Each active RAS user must be assigned an IP address when using the TCP/IP protocol. LAN of the head office. IP: 10.0.1.0 Remote workstation 10.0.1.101...
Internet access a VPN client LANCOM Systems offers the LANCOM VPN Client on the LANCOM CD. It can be run under Windows 2000 and Windows XP. A detailed description of the LANCOM VPN Client and a description of its installation can also be found on the CD.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 6: Providing dial- up access Select desired network protocols (TCP/IP, IPX) Additional TCP/IP settings: Assignment of IP address and name server address enabled 'IP header compression' disabled These settings will permit a PC to dial into a remote LAN via ISDN and access its resources in the usual manner.
Page 56
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 6: Providing dial- up access From the main menu, launch the 'Connect two local networks' wizard. Follow the wizard's instructions and enter the required information. Configure Dial-Up Networking access on the dial-in PC as described.
Chapter 7: Sending faxes with LANCAPI 7 Sending faxes with LANCAPI LANCAPI from LANCOM Systems is a special version of the popular CAPI inter- face. CAPI (Common ISDN Application Programming Interface) establishes the connection between ISDN adapters and communications programs. For their part, these programs provide the computers with office communications func- tions such as a fax machine or answering machine.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 7: Sending faxes with LANCAPI Installation of the LANCOM CAPI fax modem Select the entry Install LANCOM software in the setup program of your LANCOM CD. Highlight the option CAPI fax modem, click Next and follow the instruc-...
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 7: Sending faxes with LANCAPI When the installation was successful, the LANCOM CAPI fax modem is entered into the Phone and Modem Options of the control panel. Installation of the MS Windows fax service Select the option Printers and Faxes from the control panel.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 7: Sending faxes with LANCAPI For checking the installation, click with the right mouse button on the fax-icon and select Properties. The LANCOM CAPI fax modem should now be entered into register 'devices'.
Page 61
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 7: Sending faxes with LANCAPI The fax client console will open. Select the menu item Send a Fax. A wiz- ard will assist you through the remaining sending process.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 8: Security settings 8 Security settings Your LANCOM router has numerous security functions. You find in this chapter all information you need for an optimal protection. The security settings wizard Access to the configuration of a device permits not only to read out critical information such as WEP key or Internet password.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 8: Security settings In a next step parameters of the configuration lock like number of failed log-in attempts and the duration of the lock can be adjusted. Now activate Stateful Inspection, ping-blocking and Stealth mode in the the firewall configuration.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 8: Security settings Mark your LANCOM router in the selection window. Select from the com- mand bar Extras Setup Wizard. Select in the selection menu the setup wizard Configuring Firewall and confirm your choice with Next.
Page 65
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 8: Security settings Have you assigned a password for the configuration? The simplest option for the protection of the configuration is the estab- lishment of a password. As long as a password hasn't been set, anyone can change the configuration of the device.
Page 66
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 8: Security settings individually for each route in the routing table. The routing table can be found in the LANconfig in the 'IP router' configuration section on the 'Routing' tab. Have you excluded certain stations from access to the router? Access to the internal functions of the devices can be restricted using a special filter list.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 9: Troubleshooting 9 Troubleshooting In this chapter, you will find suggestions and assistance for a few common dif- ficulties. No WAN connection is established After start-up the router automatically attempts to connect to the access pro- vider.
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 9: Troubleshooting Numerous other factors involving the Internet itself can also influence the transfer rate. Increasing the TCP/IP window size under Windows If the actual transfer rate of a DSL connection is significantly below the fastest rate listed by the provider, there are only a few possible causes (apart from the above-mentioned external factors) which may involve one's own equipment.
Page 69
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 9: Troubleshooting tested (e.g. “DSL1” or “LAN-1”). Pay attention to the correct spelling of the interfaces. Start the test for the specified interface by clicking on Execute. Change then to menu item Expert configuration...
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 10: Appendix 10 Appendix 10.1 Performance data and specifications LANCOM 7111 VPN LANCOM 8011 VPN Firewall Stateful inspection, IP packet filter with port ranges; masquerading (NAT/PAT) of TCP, UDP, ICMP, FTP, PPTP, H.323, NetMeeting IRC and IPSec; DNS forwarding; inverse mas- querading for IP services from the Intranet such as web server;...
Page 71
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 10: Appendix LANCOM 7111 VPN LANCOM 8011 VPN Interfaces WAN: 10/100 Mbps Fast Ethernet LAN/DMZ/Switch: 4 ports, 10/100 Mbps Fast Ethernet ISDN (RJ-45): ISDN S0 Bus Serial config (8 pol. Mini DIN) COM port: 9600-11500 baud...
LANCOM 7111 VPN – LANCOM 8011 VPN Chapter 10: Appendix 10.2.3 Ethernet interfaces 10/100Base-T 8-pin RJ45 socket, corresponding to ISO 8877, EN 60603-7 Connector Line – – – – 10.2.4 Configuration interface (Outband) 8-pin mini-DIN socket Connector Line 10.3 CE declaration of conformity The CE declarations of conformity for LANCOM routers are available for down- load on the LANCOM web site (www.lancom.de).
LANCOM 7111 VPN – LANCOM 8011 VPN Index Index Numerics LAN interface 10/100Base-TX Outband 3-DES WAN interface CPU usage Accounting Date Autosensing Declaration of conformity Default gateway Denial-of-Service Protecion Bandwidth limiting Device name bandwidth management DHCP Basic configuration DHCP server...
Page 75
LANCOM 7111 VPN – LANCOM 8011 VPN Index ISDN Hardware installation Basic configuration caller ID Connect charge information ICMP Connector cable Installation D channel ADSL data compression configuration port Dial-in number ISDN dynamic channel bundling LANtools NTBA power adapter password for connection...
Page 76
LANCOM 7111 VPN – LANCOM 8011 VPN Index specify MSN TCP/IP User name NAT – see IP masquerading Remote configuration NetBIOS Remote configuration access NetBIOS proxy Remote configuration via ISDN Netmask Reset connect charge protection. Network segment Reset switch Number of VPN channels...
Page 77
LANCOM 7111 VPN – LANCOM 8011 VPN Index TCP/IP check connection Settings Settings to PCs in the LAN Virtual Private Network (VPN) Windows size Voltage switch TCP/IP configuration VPN client Automatic fully automatic manual TCP/IP filter Connector cable TCP/IP router...
Need help?
Do you have a question about the 7111 VPN and is the answer not in the manual?
Questions and answers