OvisLink Corp. 5F., NO.6, Lane 130, Min-Chuan Rd., Hsin-Tien City, Taipei County, Taiwan Declare that the product Five-WAN Internet Gateway IGR-2500 is in conformity with In accordance with 89/336 EEC-EMC Directive and 1999/5 EC-R & TTE Directive Clause Description EN 55022:1998/A1 Limits and methods of measurement of radio disturbance ■...
Page 3
Directiva 1999/5/CE. disposiciones aplicables o exigibles de la Directiva 1999/5/CE. ΜΕ ΤΗΝ ΠΑΡΟΥΣΑ OvisLink Corp. ΔΗΛΩΝΕΙ OvisLink Corp izjavlja, da je ta AirLive IGR-2500 v Ελληνική [Greek] ΟΤΙ AirLive IGR-2500 ΣΥΜΜΟΡΦΩΝΕΤΑΙ ΠΡΟΣ Slovensko skladu z bistvenimi zahtevami in ostalimi relevantnimi ΤΙΣ...
FCC Interference Statement The IGR-2500 has been tested and found to comply with the limits for a Class B digital device pursuant to Part 15 of the FCC Rules. These limits are designed to provide reasonable protection against radio interference in a commercial environment.
Table of Contents Chapter 1 Introduction......................... 4 1.1 Functions and Features ........................4 1.2 Front Panel and Rear Panel ....................... 5 1.3 Packing List............................6 Chapter 2 Deployment ......................... 7 Chapter 3 Configure Router ......................8 3.1 How to start out to configure router ....................8 3.2 System Status ...........................
Page 6
3.11.3 DMZ Host ..........................46 3.11.4 Multi-NAT ..........................50 3.11.5 IP Binding ..........................51 3.11.6 DDNS ..........................53 3.11.7 Proxy............................ 54 3.11.8 Mail Alert..........................55 3.11.9 Time ............................. 56 3.11.10 System Log........................57 3.11.11 MAC Address Clone ......................58 3.12 Administrator ........................... 59 3.12.1 Password..........................
IGR-2500 features with four 10/100 Mbps Ethernet ports (WAN port), eight 10/100 Mbps Ethernet ports (LAN port), and one 10/100 Mbps Ethernet port for DMZ. WAN port is using to connect to broadband transmission equipments such as ADSL modem or CABLE modem for user and far end to download or upload data in high speed;...
1.2 Front Panel and Rear Panel Figure 1-1 Front Panel Status Indicator Color Flashing ● Green Initialize Active Stage Power ● Linked Data Transmission WAN 1~4 ● Green Linked Data Transmission LAN 1~8 ● Linked Figure 1-2 Rear Panel...
When you finish defining the Default Button Option, just pressing Factory Reset button 2 seconds and releasing it, the router will load the default settings or back to latest configuration. 1.3 Packing List IGR-2500 Five-WAN Internet Gateway Installation CD-ROM Quick Installation Guide...
IGR-2500 provides one LAN port connecting to your network devices such as PC, HUB and SWITCH via RJ45 cable. Using a HUB/SWITCH will allow more PC connecting to IGR-2500. WAN ports are using to connect your ADSL or CABLE Modem to the broadband ISP.
3.1 How to start out to configure router Connect the MIS engineer’s PC and IGR-2500’s LAN port to the same Hub / Switch, and launch Step1. the browser (IE or Netscape) to link the IGR-2500 appliance. The default IP address is http: //192.168.1.1...
Page 12
Configure each WAN port separately, and the other function you would like to use, such as Load Step3. Balance, Bandwidth Management, or else. (Figure 3-2) Figure 3-2 Configure WAN port setting You can refer to the manual for more understanding of else router’s feature.
3.2 System Status 3.2.1 Link Status You can get the following information in Link Status window: (Figure 3-3) LAN Status WAN Status DMZ Status Firmware Version DHCP Table Figure 3-3 Link Status...
Page 14
LAN Status: Shows the information of MAC Address, IP Address, Subnet Mask and DHCP Status (Enable/Disable). WAN Status: Shows the information of MAC Address, IP Address, Subnet Mask and WAN Status on each or all WAN ports. DMZ Status: Shows the information of MAC Address, IP Address, and Subnet Mask. Firmware version: version of software and its released date.
3.2.2 Data Monitor Differ with Link Status window, Data Monitor window provides detail packet transfer status. It includes 2 kinds of real time data per each WAN port. (Figure 3-4) Figure 3-4 Data Monitor Current Session: TCP Session: UDP Session: ICMP Session: Total Session: Current Bandwidth:...
Page 16
Figure 3-5 NAT Table The packets start to accumulate from: Router powers on Clear counter Counter reaches upper the limitation (4294967K), and then the counter will reset to 0 automatically.
3.3 WAN Configure There are several WAN function can be made in this display, you can configure functions to each WAN port separately. Connect to: Internet: WAN port is connected to Internet through ADSL/Cable modem Intranet: WAN port is connected to another router LAN port, work together with “Static Route” function, can restrict specific IP packet to a dedicate route path.
100Mbps Full Duplex 3.3.1 WAN Type – Dynamic IP Usually it's used to connect CABLE modem. You won't need to assign IP address, and the IGR-2500 will get the IP address from ISP automatically. (Figure 3-7) When you choose Dynamic IP, you only need to save this selection, and reboot router when you finish configuring all parameter.
3.3.2 WAN Type – PPPoE Connect to ISP via dial-up connecting, ISP will assign a legal IP to you after the user Id and password had been passed. (The user Id and password here are provided by your ISP.) (Figure 3-8) Figure 3-8 PPPoE Account: The user name provided by ISP, the character can be entered up to 60.
About “Always-on” function, normally you need to combine "Healthy Check" function together, then "Always-on" can work more perfectly because there is an ADSL modem between router & ISP equipment. In physical layer, if ADSL line fails but ADSL modem is still alive, and router can not detect the line status unless ISP sends a disconnected packet to router.
3.3.4 WAN Type – WAN5/DMZ The hardware DMZ can be defined as DMZ function or 5 WAN port. If you select to define the interface as 5 WAN port, its setting is the same as else WAN interface. When you select to define the interface as DMZ port, the default IP address of DMZ interface is 192.168.15.100.
Page 22
For example: In following display, FTP, HTTP & Mail bandwidth will be limited in certain percentage. This router provides 3 most often use protocol in the table, and you just need to fill in port number and % usage for each application: Select WAN Port: Select the WAN interface for the bandwidth definition WAN Speed: Enter the upload and download speed provided by ISP Upload (kbits/s)
3.5 Configure LAN & DHCP This function configures the LAN ports IP address, Subnet Mask, and DHCP server. You can choose using DHCP server or disable it, the Dynamic Host Configuration Protocol (DHCP) allows the Broadband Router to dynamically assign IP addresses to network devices. Dynamic IP assignment alleviates the need for the network administrator to maintain and monitor IP address assignments and simplifies IP use because the IP addresses are automatically and dynamically assigned when a station powers-on.
Page 24
Figure 3-13 Add Reserved IP Address When enable DHCP Server in “From”, ”TO” field, you can reserve up to 253 IP address to DHCP server. Fill in local DNS Server IP address in “DNS Address” field, the DNS IP information will also assign to DHCP client.
Static Routing There have one pc with two interfaces in this area, one interface is connected to IGR-2500 (domain A), and the other connected to another Server (domain B). Users need to set the static routing path in IGR-2500 in order to recognize another domain in this area.
Page 26
Figure 3-15 Static Routing Dynamic Routing Dynamic Routing allows router learning the path to destination by receiving periodic updates from others. The protocol used in communication between routers is RIP v1 and v2. (Routing Information Protocol). RIP1 supports only to broadcast mode while RIP2 supports broadcast and multicast mode. (Figure 3-16) Figure 3-16 Dynamic Routing...
3.6.2 Current Table This display shows the valid routing paths in IGR-2500. Users can view the information about current routing paths. (Figure 3-17) Figure 3-17 Current Table...
3.7 AP Management AirLive IGR-2500 supports to block several Instant Message programs, such as QQ, MSN, and Yahoo Messenger. User can also define the supervisor IP address to be the privilege user who will not be restricted the access of IM program. (Figure 3-18) Type: Select to enable QQ, MSN, and Yahoo Messenger IM program inhibiting.
3.8 Access Control 3.8.1 Local IP Filtering AirLive IGR-2500 allows you to define the accessed restriction about to block or allow outgoing IP packets per protocol (port number). You may restrict specific IP to perform limited protocols or allow them to execute partial protocols. And the first thing you have to know is the port numbers and their usages.
Page 30
Figure 3-19 Local IP Filtering Example Setting Protocol Port Number List Protocol Service Port no. Protocol Service Port no. LADP HTTPS TELNET SMTP RLOGIN SYSLOG TFTP TALK 517,518 GOTHER FINGER AFPOWERTCP HTTP Net-Meeting 1503,1702 POP3 L2TP 1701 PPTP 1723 NNTP 5190~5194 PC Anywhere 5631~5632...
3.8.2 Intrusion Security AirLive IGR-2500 features Intrusion Security, to allow user setting as “BLOCK” or “PASS” function following by the table content. The restricted user can be defined with its IP and MAC address. (Figure 3-20) Figure 3-20 Intrusion Security Intrusion Security: select Enable to enable Intrusion Security function.
3.8.3 DoS Defense AirLive IGR-2500 also provides DoS (Denial of Service Defense) function to protect your network servers, hosts, routers and other devices from the attacking of villain using mass data transmission. (Figure 3-22) The default value in the display is the optimize parameter for Router. (Figure 3-23)
Page 33
Some virus are using “PING” command to attack network, AirLive IGR-2500 can be defined as accept or reject “PING” command from WAN or LAN. (Figure 3-24) Figure 3-24 Disable Ping respond Function Description Checking the IP fragments. When it finds someone from WAN side tries...
3.8.4 URL Filtering Besides restrict users by local/destination IP, AirLive IGR-2500 provides you to do accessed restriction for user by URL as well. You may restrict some URL address that are not allowed to reach Enable URL Filter On Http Port: You can define the port number for URL Filtering, and select to enable the rule.
3.8.5 Session Limit AirLive IGR-2500 features Session Limit to restrict each IP connection’s session. This feature can assure the network performance from being attacked by infected PC, which can create and spread out lots of session in a short time.
3.9 QoS With QoS function, you can set up user bandwidth with Maximum & Minimum bandwidth value. Configure WAN Speed: The WAN speeds must be configured for the QoS configuration to take effect. IP MAX/MIN Limit: Allocate bandwidth to users: IP: IP address of specified user MAX: Bandwidth limitation to this user MIN: Minimal Bandwidth keeps for this user before allocating any bandwidth from this user to...
3.10 Load Balance 3.10.1 Outbound Load Balance AirLive IGR-2500 provides three kinds of work mode for Outbound Load Balance, and Ultra Smart Sharing feature to offer intelligent connection solution for banking system and Internet on-line game server. The load balance types include Session, Weight round robin, and Dynamic Traffic.
Page 38
Figure 3-29 Outbound Load Balance – Weight round robin Traffic: Router will find the lowest loading WAN port to transmit and receive data automatically. You need to enter correct ADSL/CABLE WAN speed in here. (Figure 3-30) Figure 3-30 Outbound Load Balance – Dynamic Traffic...
Ultra Smart Sharing: When user enables this function, IGR-2500 will lock user packet at dedicated WAN port, the dedicated WAN port will be selected base on 1st user packet (This feature is suitable for Game, VoIP, banking system …etc). (Figure 3-31) Time out Timer: Default is 60 second, range from 30 ~255.
Some Internet WEB server do not allow access with multi WAN address, also these WEB server was using dynamic IP address, in this case, AirLive IGR-2500 can let you just define dedicated port number allocated with dedicated WAN port, and the dedicated port was used to access these special WEB Server. (Figure 3-33) Figure 3-33 Special Application 3.10.4 Special IP Assignment...
3.10.5 TOS TOS function can let you setting the priority for dedicated packet. (Figure 3-35) User can specify the Source IP, Destination IP, Protocol type, Source port number, Destination port number and Priority for TOS feature. (Figure 3-36) Figure 3-35 TOS Figure 3-36 TOS Configuration...
3.11 Advance 3.11.1 ARP Protection To prevent the ARP cheating from virus, AirLive IGR-2500 offers you a feature named ARP protection; it will spread out router’s IP and MAC address to LAN user in every specific time. Frequency times/sec: User can define the time for ARP protection service. For example, if you define the Frequency to 2, IGR-2500 will broadcast its MAC address twice to LAN users in every second.
Remote port is 80 (default is 80, can be different port number) Remote IP is blank. ROUTER WAN port IP is 110.111.112.1 When the user of remote side wants to access IGR-2500 web configure, the remote user only needs to enter http:// 110.111.112.1 Figure 3-38 Remote Configure...
Local IP: local server IP address Specify A Global IP: You can select to define one IP address from IGR-2500 several WAN ports setting. If you specify Global IP address with 0.0.0.0, the Internet user will be able to access virtual server from all the WAN port IP addresses.
Page 45
Figure 3-40 Virtual Server Group Virtual Server: If you would like to define more than one service port number into a virtual server rule, you can use Group Virtual Server. (Figure 3-41) Figure 3-41 Group Virtual Server...
Page 46
End port: The end port number of the port range. Specify A Global IP: User can select to define one IP address from IGR-2500 several WAN ports setting. If you specify Global IP address with 0.0.0.0, the Internet user will be able to access virtual server from all the WAN port IP addresses.
Page 47
Figure 3-43 Example Topology Example 1: Define Virtual server to allow FTP service (TCP 21) packets from Internet to LAN FTP server via WAN1. (Figure 3-44) Figure 3-44 Example1 setting...
Page 48
Example 2: Define Virtual server to allow VNC service (TCP 5800, TCP 5900) packets from Internet to LAN VNC client via WAN2. (Figure 3-45) Figure 3-45 Example2 setting Example 3: Define Virtual server to allow packets TCP 1394 ~ 1400 from Internet to ERP server via all the WAN interfaces.
If you would like to grant remote users the right to access one of your computers on LAN to perform some actions such as Internet games, you must enable the function of DMZ. When remote users access your legal IP(s), IGR-2500 will transmit these packets to the corresponding virtual IP(s). (Figure 3-47)
Page 50
DMZ host disregarding the exact WAN IP address. Tick the WAN port option and fill in the IP address of the DMZ host inside the network, the IGR-2500 will map the corresponding WAN IP to the internal DMZ host automatically. When a remote computer wants to access the internal LAN through this WAN, if the accessed port number is not specified by Virtual Server Host, it will be mapped into this internal DMZ host.
Page 51
Public DMZ: Public IP Mapping This AirLive IGR-2500 provides “Public IP Mapping” function. With this function you can map legal IP between ROUTER WAN & LAN interface. This application will be very useful to let you connect GAME Server or VOIP gateway inside the LAN, because most GAME SERVER or VOIP gateway needs legal IP address to operation.
Page 52
Figure 3-50 Public DMZ If user configures “Public IP Mapping” function, the GAME SERVER & VOIP gateway will not have DoS function protected by IGR-2500. When hardware DMZ is enabled, the entire DMZ rule will be re-directed to the device that is connected...
Multi-NAT function allows you to configure multiple LAN IP domain to each WAN port (total 10 LAN IP can be defined), after configure multiple NAT function it will act like virtual router, all traffic between each LAN IP domain will be accessed through IGR-2500. It will provide following benefit: Restrict broadcast storm in single IP domain.
3.11.5 IP Binding In Internet world, there have some Game Server, SSL protocol user or Personal Server have special request for connection, these special request include: Use special port number to perform specific function Not allow user connect with multiple WAN IP address For Example, if user uses load Balance function provided by router to connect Server, Server might respond with many login requests back to user, because each session comes different WAN port with different IP address, Server treats it like different request...
Page 55
IP Address Start port End Port Blank WAN1 Packet type belong to protocol 21 (FTP) that goes to any of Internet Host will be restricted to dedicated WAN1. (Figure 3-52) Figure 3-52 IP Binding...
AirLive IGR-2500 will update the WAN IP address to DDNS database once the WAN port was connected to Internet if DDNS function is enabled. And the users in Internet can find out the IGR-2500 via this domain name. (Figure 3-53)
3.11.7 Proxy This function works together with Mail Alert function, if there have Proxy Server in your local LAN, please fill in necessary Proxy information in this display. (Figure 3-54) Figure 3-54 Proxy...
Sender mail address: The mail address that send out alert mail, you should fill in a legal format address Alert Condition: IGR-2500 provides four condition selections: System will send the mail, once WAN port(s) is connected to Internet. WAN Up System will send the mail, once WAN port(s) is disconnected from Internet.
3.11.9 Time AirLive IGR-2500 will obtain the GMT (Greenwich Mean Time) after connected to Internet. You need to indicate the local time so that the system could operate with the correct time. For example, Taiwan’s local time is GMT + 8 hours.
3.11.10 System Log Show all the records after IGR-2500 Power on, such as WAN port up/down, WAN IP address, the obtained time, DDNS current corresponding WAN IP address and so forth. You can also save these data to files. (Figure 3-57)
If your ISP blocked the MAC address of a network card, you may use MAC Address Clone to duplicate the MAC address to the Mac address in each WAN port. Remove all Ethernet cable on IGR-2500 LAN port except for the PC you want to clone. Then press Ok when you ready. (Figure 3-58) User Self-Define WAN Port MAC Address: type in a MAC Address to define WAN MAC Address.
3.12 Administrator 3.12.1 Password Use this function to change the Password that is used for access the web configuration. Type in the Old Password, New Password and Retype Password in their respective fields and then click Ok, the password will be changed to new one after re-boot. (Figure 3-59) Password length can be up to 30 alphanumeric characters with case sensitive.
3.12.2 Backup & Restore Use Backup & Restore function to save all the settings parameters to PC for safety issue, in order to avoid all parameter lose when system crushes. (Figure 3-60) Figure 3-60 Backup & Restore...
User can use this function to define the feature of reset button, or load the latest configuration file back to device. Click OK after the selection, the IGR-2500 will restart automatically. (Figure 3-61) Reset Button Option: This option is used to define Default button on the back penal of the router.
3.12.4 Display You can use this function to check all the parameter setting in this router, in order to save time to check every display. (Figure 3-62) Figure 3-62 Display...
Double click the executable file (the file with exe extension file name) you downloaded. Here we take v105.exe as the example of new version file. Step 1: Click Search to find the IP of router. Step 2: The IP address of IGR-2500 is 192.168.1.1 (default value).
Page 67
Step 3: Click Update to update the firmware. Method 2: Step 1: Run a TFTP server program such as TFTPD32. (TFTPD32 is a shareware and you may download it or other TFTP server programs from Internet.)
Page 68
Step2: Make a base directory in this server Step 3: Save the image file of firmware to the directory of TFTPD32...
Page 69
Step 4: Enter the Server Name and File Name in the new folder fields of Firmware Update window and then click Ok. Step 5: You will see the updating processing. After finishing update procedure, you must reboot IGR-2500 to run new code.
3.14 Save & Reset In order to save the configuration changes that have been made to the IGR-2500, you must save them to the IGR-2500’s Flash memory. If you do not save the changes, the configuration settings will be lost in the event of a power loss or system reboot to the IGR-2500.
Authorities DNS is just a fancy term for the official IP address keeper/provider of particular Domain (or Internet) name, such as www.example.com is analogous to a telephone book where a person’s name is associated with his telephone number. Wikipedia, the free encyclopedia has a good general discussion of DNS: http://en.wikipedia.org/wiki/Domain_Name_System.
A.1 Simple Load Balance (2 WAN lines; Session 1:1) Let us assume that the upload speed of WAN1 and WAN2 are the same; so we will use inbound load-balancing setting: Session with a load-balancing ratio of 1:1. In the IN-BOUND ROUTER configuration Load Balance Inbound: Step 1: Click on Add new item...
Page 73
Step 2: Enter host1.example.com two times, once for WAN1 and once for WAN2 with Address Type. This display show the 1st time for WAN1, after clicking Ok. Repeat the previous configuration with the same name for WAN2 at this time. You don’t need to explicitly enter any IP address.
Page 74
Step 4: This time we are adding the DNS record with the real name for web server. Select DNS Type with Canonical Name. Name: www.example.com Host: host1.example.com Step 5: The simplest case for the configuration of IN-BOUND ROUTER DNS server is done.
Page 75
Now the Inbound Load-balancing DNS Server is configured to redirect the Internet requests of www.example.com to the IP address of either WAN1 or WAN2. But we’ll still need to configure the virtual server. In the IN-BOUND ROUTER configuration: Advance Virtual Server Step 1: The port for www.example.com is 80 and the IP address is:...
A.2 Advanced Load Balancing We will describe Inbound Load Balancing using “Weighted round robin” algorithm for three Internet servers: 1. Web server, www.example.com, using WAN1 – WAN2, with ratio of 1:2 FTP server, ftp.example.com, using WAN1 –WAN4, with ration of 1:2:3:4 3.
Page 77
Define www.example.com in Inbound Option In Load Balance Inbound, select Weight round robin for the inbound load balance mode. Now you can enter the ratio for each WAN port into their respective fields. Add the appropriate entries into the Inbound Option table. The entries are similar to the entries for www.example.com in previous section A.1.
Page 78
The mail server requires some additional steps. Define mail.example.com in Inbound Option Step 1: In Load Balance Inbound page, click Add new item, select DNS Type as Address, and configure host name for the Mail server address entry: Enter: Name: mail.example.com rather than Name:...
Page 79
Step 3: Load Balance Inbound Add new item Configure Inbound (CName): Select Canonical Name and enter the name as smtp.example.com, select Host with mail.example.com Step 4: Load Balance Inbound Add new item Configure Inbound (CName): Similarly, do the previous step again for pop3.example.com.
Page 80
Step 6: Load Balance Inbound: The Mail Server is configured by the last 5 entries of the DNS Name table. Step 7: Advance Virtual Server: Now we finish the IN-BOUND ROUTER DNS server setting, and we still have to link the WAN IP addresses with the Internal &...
Page 81
The ratio was specified: WAN1, WAN2, WAN3, WAN4 = 1:2:3:4 www.example.com uses WAN1 and WAN2 with a ratio of 1:2. The IP addresses return to the queries for the Web Server accesses are: WAN1, WAN2, WAN2, WAN1, WAN2, WAN2…, etc. ftp.example.com uses WAN1 –...
Need help?
Do you have a question about the IGR-2500 and is the answer not in the manual?
Questions and answers