Viola Systems M2M User Manual

Hide thumbs Also See for M2M:

Advertisement

Quick Links

Document version 3.0
Modified June 25, 2008
Firmware version 2.4

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the M2M and is the answer not in the manual?

Questions and answers

Summary of Contents for Viola Systems M2M

  • Page 1 Document version 3.0 Modified June 25, 2008 Firmware version 2.4...
  • Page 2: Table Of Contents

    1.1 About Viola M2M Gateway ........
  • Page 3 9.3 Date and time ..........24 9.3.1 Manual configuration .
  • Page 4 Copyright © 2008, Viola Systems Ltd. All rights to this manual are owned solely by Viola Systems Ltd. (referred in this manual as Viola Systems). All rights reserved. No part of the contents of this manual may be transmitted or reproduced in any form or by any means without the written permission of Viola Systems.
  • Page 5 The names of the programs as well as all copyrights relating to the programs are sole property of Viola Systems. Any transfer, licensing to a third party, leasing, renting, transportation, copying, editing, translating, modifying into another programming language or reverse engineering for any intent is forbidden without the written consent of Viola Systems.
  • Page 6 Read these safety instructions carefully before using the product: Warranty will be void, if the product is used in any way, which is in contradiction with the instructions given in this manual, or if the product has been tampered with. The devices mentioned in this manual are to be used only according to the instructions described in this manual.
  • Page 7: About Viola M2M Gateway

    Only a computer with network connection and a HTML browser is required to configure the M2M Gateway. Using the M2M Gateway Web user interface you can configure and view the status of the remote Arctic devices and configure the VPN connection between M2M Gateway and Arctic device. Arctics have a WWW user interface which can be used to configure them using a HTML browser.
  • Page 8: Packaging Information

    firewall and install M2M Gateway behind it. VPN is used to connect remote Arctic devices to local network. Connection is started by Arctic and the M2M Gateway decides based on its configuration does it allow remote Arctic start VPN connection. VPN connection can be disabled from M2M Gateway.
  • Page 9: Back Panel

    M2M Gateway back panel is shown in figure 1.3. Figure 1.3: Back panel Connectors (from left to right): 1. Power plug 2. Mouse and keyboard connector 3. USB connectors 4. Serial connector 5. Parallel connector 6. VGA display connector 7. Ethernet 0 connector (Eth0 / WAN) 8.
  • Page 10: Connection Principle

    Gateway and devices behind it. This means that for example local firewall to router needs to be aware of routes going via the M2M Gateway. Routing can be complex to setup in large networks and it is recommend to consult...
  • Page 11: Other Network Services

    DMZ zone. Services other than SSH are optional. If the M2M Gateway is located in the DMZ and it has a private IP address the firewall has to support port forwarding or destination network address translation (DNAT). For firewall configuration please refer to your firewall documentation or to your local network administrator.
  • Page 12: Setting Ip Address Using Web Browser

    1. Connect the cross-over Ethernet cable between Viola M2M Gateway (Ethernet 0 connector) and your configuration computer. 2. Configure your computer to use the same IP address space than Viola M2M Gateway (laptop IP for example 10.10.10.11 with netmask 255.0.0.0). Check with ping command.
  • Page 13 Note that your existing web browser connection hangs up after you apply the settings, so open a new connection to the new IP address (check your Ethernet cabling) 12. Now you should be able to connect to the M2M Gateway with your new IP address.
  • Page 14: Configuration Screens

    This chapter describes how to configure network interfaces on M2M Gateway. Network configuration screens can be found from main menu and pressing Network Configuration icon. Figure 4.1: Network configuration menu Displays running network configuration on the top on list. This list contains all the interfaces running locally, including VPN interfaces.
  • Page 15: Vpn Requirements

    VPN implementation on M2M Gateway requires ˆ Open port in firewall for selected VPN server port ˆ Fixed IP address for M2M Gateway accessible from public Internet or used APN ˆ Remote client to connect to M2M Gateway (most commonly Viola Arctic product) ˆ...
  • Page 16: Typical Connection Scheme With Routing

    ˆ Network addresses can not overlap, it is always best to use dedicated IP address range for VPN tunnels. Remember that VPN tunnel addresses are only visible between M2M Gateway and remote node. ˆ Netmasks should be strict to prevent network overlapping.
  • Page 17: Introduction To Ssh-Vpn

    This chapter describes how to use SSH-VPN module on Viola M2M Gateway. SSH-VPN uses SSH keys and remote nodes hostname to authenticate and validate remote connections. It is the default VPN for Viola Arctic products. Figure 6.1: SSH-VPN configuration screen Configuration screen can be divided into different regions:...
  • Page 18: Creating New Connection

    Figure 6.3: SSH-VPN peer creation screen After a new peer has been created, it will show up in peer list and its status will be disabled. To enable it, the keys must be exchanged between Viola M2M Gateway and Arctic. To do this...
  • Page 19: Checking Connection

    Please note that the Arctic needs to be restarted before the connection comes up. After the Arctic restarts and connects, the peer status can be checked on the M2M by selecting a checkbox on the peer list and pressing Start check button.
  • Page 20: Finalising Ssh-Vpn Setup

    Default port for SSH is 22. It is recommended to change this to something less common to increase system security. Changing SSH port on M2M Gateway is done by entering new port to a configuration field located in the bottom of the SSH-VPN configuration screen and pressing button.
  • Page 21: Introduction To L2Tp-Vpn

    L2TP-VPN uses username and password to authenticate and validate remote connections. It is available on Viola Arctic products. Configuration screen is shown in figure 7.1. Figure 7.1: L2TP-VPN configuration screen Using action buttons on the peer list, the connections can be managed and monitored easily. See figure 7.2. Possible actions are visible in (link to figure), these are (from left to right): 1.
  • Page 22: Creating New Connection

    5. IP pair assigned to tunnel 6. Routing mode (none or network) 7. Remote IP if routing mode is set to network 8. Netmask if routing mode is set to network 9. L2TP username 10. L2TP password 11. Status (Active or Inactive) 12.
  • Page 23 Please refer to Viola Systems’ OpenVPN application note.
  • Page 24: Changing System Password

    ˆ User can log in only locally, remote root access is restricted. Firewall in an important part of the M2M Gateway product. Firewall should always be turned on and configured as strict as possible to keep out any unauthorized traffic.
  • Page 25: Firewall Configuration Screen

    To reach the firewall configuration screen: 1. Login to M2M Gateway and enter the web user interface main menu 2. From the top icon row on the blue background, select Networking icon 3. From the Networking page select Linux Firewall icon The firewall configuration is divided into sections:...
  • Page 26: Manual Configuration

    The Backup module saves user made settings of the Viola M2M Gateway. It backups configuration files and keys of VPN tunnels and firewall settings. Backup screen can be found from the Web user interface main screen. Press Viola M2M Backup icon to open backup screen.
  • Page 27: Creating Backups

    Figure 9.6: Backup screen From the first page select Viola M2M Backup icon and press create backup button to create a backup file. When the backup is created succesfully, a notification text appears. Figure 9.7: Backup created message Press open button to select the backup you want to restore and press restore backup button to restore the backup.
  • Page 28: Supportlog

    It can generate a log package that can be e-mailed to Viola Systems’ technical support. It is possible to collect all the data or smaller selection. Figure 9.10: Supportlog screen Factory default settings can be restored by selecting factoryBackup from backup restore selection screen.
  • Page 29 These configuration options are targeted for advanced users only. Under normal operation these shoul not be changed. Figure 10.1: System menu ˆ Bootup and Shutdown: change process and system level services on startup ˆ Running Processes: can be used for monitoring current processes and deleting processes ˆ...
  • Page 30 Figure 10.3: Others menu ˆ Command Shell: debugging console for system level commands ˆ Webmin Actions Log: Web user interface access log data...
  • Page 31 A: Check that IP forwarding has been enabled and internal firewall does not block packets. A: Check that IP forwarding has been enabled on Arctic. A: Yes, if firewall connected to public IP can forward incoming SSH connections to the M2M Gateway.
  • Page 32 Processor Intel Celeron 2.5GHz Memory 512Mb Hard Drive 80Gb Input voltage 100-240VAC (5A max) Casing Metal 19in rack mountable Operating temperature 0 to 45 C Storage temperature -20 to +45 C Humidity 10 to 90 % RH non-cond. Network connection 2x Ethernet RJ-45 (10/100/1000 Base-T) Approvals CE, FCC...
  • Page 33 Your sole and exclusive remedy for a covered defect is repair or replacement of the defective product, at Viola Systems’ sole option and expense, and Viola Systems may use new or refurbished parts or products to do so. If Viola Systems is unable to repair or replace a defective product, your alternate exclusive remedy shall be a refund of the original purchase price.
  • Page 34: Contacting Technical Support

    ˆ Phone: +358 20 1226 226 ˆ Fax: +358 20 1226 220 ˆ E-mail: support@violasystems.com ˆ On-line http://www.violasystems.com Before contacting our Technical Support staff, record the following information about your product: ˆ Product name.: ˆ Serial no.: Note the status of your product in the space below before contacting technical support. Include information about error messages, diagnostic test results, and problems with specific applications.
  • Page 35 About, 6 Back panel, 8 Backup, 25 Copyright, 3 Date and time, 24 Disclaimer, 4 Factory defaults, 27 Features, 6 Firewall, 23 Front panel, 7 IP address, 11 L2TP-VPN, 20 Limited warranty, 32 Network requirements, 9 Network services, 10 OpenVPN, 22 Packaging, 7 Password, 23 Product label, 8...

Table of Contents