Important Note to Users of Peplink Balance 30 (Classic Edition) Firmware 5.0 or above is NOT applicable to Peplink Balance 30 (Classic Edition). For more information of identifying the generation of your Peplink Balance 30, please visit our knowledge base at <http://www.peplink.com/index.php?view=faq&id=231&path=16>.
SpeedFusion Throughput, Ping and Traceroute Test Built-in PPTP VPN Server Authenticate PPTP clients by RADIUS and LDAP servers (Available on Peplink Balance 210+) IPsec VPN for Network-to-Network connection (Works with Cisco, Juniper only) PPTP and IPsecpassthrough 4.1.4 Inbound Traffic Management...
Hardware High Availability via VRRP, with automatic configuration synchronization(Available on Peplink Balance 210+) Real-Time, Hourly, Daily and Monthly Bandwidth Usage reports and charts Hardware backup via LAN bypass (Available on Peplink Balance 580, 710, 1350 and 2500) Built-in WINS server Time server synchronization ...
USER MANUAL Peplink Balance Series Peplink Balance Overview Peplink Balance 20 6.1.1 Front Panel Appearance USB Port WAN Ports Status LED Reset Button LAN Ports Power LED 6.1.2 LED Indicators The statuses indicated by the Front Panel LEDs are as follows: Power and Status Indicators OFF –...
USER MANUAL Peplink Balance Series 6.10 Peplink Balance 2500 6.10.1 Front Panel Appearance Console Port BPL-2500 USB Ports WAN Ports Power LED LCD Display LAN Port LCD Controls Console Port BPL-2500-SFP USB Ports WAN Ports Power LED LCD Display LAN Port LCD Controls http://www.peplink.com...
At the high level, construct the network according to the following steps: With anEthernetcable, connect a computer to one of the LAN ports on the Peplink Balance. For Peplink Balance 20, 30, 210 and 310, repeat with different cables for up to 4computers to be connected.
USER MANUAL Peplink Balance Series Configuring the Network Environment To ensure that Peplink Balance works properly in the LAN environment and can access the Internet via the WAN connections, please refer to the following setup procedures: LAN Configuration For basic configuration, refer to Section 8, Basic Configuration.
Connecting to Web Admin Interface Start a web browser on a computer that is connected with Peplink Balance through LAN. To connect to Web Adminof Peplink Balance, enter the following LAN IP address in the address field of the web browser: http://192.168.1.1...
USER MANUAL Peplink Balance Series Configuration with Setup Wizard The Setup Wizard of Peplink Balance simplifies the task of configuring WAN connection(s) by guiding the configuration process step by step. To begin, click Setup Wizard after connecting to Web Admin Interface.
Page 51
Advertise Speed checkbox. Drop-in Mode Settings (Available on Peplink Balance 210+) Drop-in Mode eases the installation of Peplink Balance on a live network between the existing Firewall and Router, such that no configuration changes are required on existing Enable equipment.
Page 53
This table is for defining custom local DNS records. A static local DNS record consists of a Host Name and an IP Address. When looking up the Local DNS Host Name from the LAN to LAN IP of Peplink Balance, the corresponding IP Address will Records be returned.
Otherwise, hosts on one side may not be able to reach hosts on the other side of Peplink Balance until the old ARP records expire. Units without enabling Drop-in Mode are not affected.
Page 55
Enable box, most network settings for WAN1 will be hidden from Web Administration Interface.) Put the IP address of the WAN1 router in the WAN Default Gateway field. Ensure that the Peplink Balance IP subnet is the same as the Firewall’s WAN port and the Router’s LAN port.
Page 62
This setting applies to 3G / LTE / EDGE / GPRS modem only. It does not apply to EVDO / EVDO Rev. A modem. Operator This allows you to configure the APN settings of your connection. If Auto is selected, Peplink Settings Balance will automatically detect the APN, configure the modem, and make connection. You may change the APN settings by selecting Custom Mobile Operator Settings.
Peplink Balance Series 11.3 WAN Health Check To ensure traffic is routed to healthy WAN connections only, Peplink Balance provides the functionality to periodically check the health of each WAN connection. The Health Check settings for each WAN connection can be independently configured via Network >...
Page 69
For example, with the default Health Retries setting of 3, after consecutive 3 timeouts, the corresponding WAN connection will be treated as down. This setting specifies the number of consecutive successful ping/DNS lookup responses that must be received before Peplink Balance treats a previously down WAN connection to be up again. Recovery Retries By default, Recover Times is set to 3.
Disclaimer Due to different network protocol overheads and conversions, the amount of data as reported by this Peplink device is not representative of actual billable data usage as metered by your network provider. Peplink disclaims any obligation or responsibility for any events arising out of the use of the numbers shown here.
IP of each WAN will be automatically reported to the DNS service provider. Either upon a change in IP addresses or every 23 days without link reconnection, Peplink Balance will connect to the dynamic DNS service provider to perform an IP address update within the provider’s records.
Peplink Balance is specifically designed for multi-WAN environment. The Peplink Balance canbond all WAN connections’ bandwidth for routingSpeedFusion traffic. Unless all the WAN connections of one site are down, the Peplink Balance can still maintain VPN up and running.Bandwidth Bonding is enabled by default.
Page 75
Connection profiles and Link Failure Detection Time option will be shown. Click the New Profile button to create a new VPN connection profile for making VPN connection to a remote Peplink Balance via the available WAN connections.Each profile is for making VPN connection with one remote Peplink Balance http://www.peplink.com...
Page 76
Peer IP Addresses This field is optional. With this field filled, the Peplink Balance will initiate connection to each / Host Names of the remote IP addressesuntil success. If the field is empty, the Peplink Balance will wait (Optional) for connection from the remote peer.
Page 77
TCP port 32015 and UDP port 4500 for establishing VPN connections. If you have a firewall in front of the Peplink Balance devices, you will need to add firewall rules for these port and protocols which will allow inbound and outbound traffic pass-through the firewall.
NAT (Network Address Translation) router. To be able for a WAN connection behind a NAT router to accept VPN connections, you can configure the NAT router in front of the WAN connection to inbound port forward TCP port 32015 to the Peplink Balance.
Status is shown in the Dashboard. The connection status of each connection profile is shownas below. SpeedFusion connection status is also shown on the LCD panel of Peplink Balance 380, 580, 710, 1350 and 2500. By clicking the Details button at the top-right hand corner of SpeedFusion table, you will be forwarded to Status >SpeedFusion...
WAN2 and WAN3 accordingly, as failover purposes. 13.1 IPsec VPN Settings All of our Peplink products can makemultiple IPsec VPN connections with Peplink as well as Cisco or Juniper Routers. Note that all LAN subnet and subnets behind it have to be unique. Otherwise, VPN members will not be able to access each other.
IPsec Status shows the current connection status ofeach connection profile and is displayed in Status > IPsec. Management of Outbound Traffic to WAN Peplink Balance provides the functionality to flexibly manage and load balance outbound traffic among the WAN connections. 1. Important Note Outbound Policy is applied only when more than one WAN connection is active.
Page 87
This setting specifies the IP Protocol and Port of traffic that matches this rule. You may Protocol and Port select some common protocol from the Protocol Selection Tool drop-down menu. This setting specifies the behavior of Peplink Balance for the custom rule. One of the following values can be selected: ...
Page 88
Internet IP depends on the WAN connections over which communication actually takes place. As a result, a LAN client computer behind Peplink Balance may communicate using multiple Internet IP addresses. For example, a LAN client computer behind a Peplink Balance 310 with three WAN connections may communicate on the Internet using three different IP addresses.
Page 89
Starting from firmware 5.2, outbound traffic can be prioritized to go through SpeedFusion connection(s). By default, VPN connections are not included in the priority list. (Available on Peplink Balance 210+) Configure multiple distribution rules to accommodate different kinds of services.
Page 90
14.2.6 Algorithm: Least Used (Available on Peplink Balance 210+) The traffic matching this rule will be routed through the healthy WAN connection that is selected in the field Connectionand has the most available download bandwidth. The available download bandwidth of a WAN connection is calculated from the total download bandwidth specified in the WAN settings page and the current download usage.
Enable are taken by Peplink Balance based on the other parameters of the rule. With an Enable value of No, the inbound service does not take effect: Peplink Balance disregards the other parameters of the rule. This setting identifies the service to the System Administrator.
Page 93
Any Port, Single Port, Port Range, Port Map and Range Mapping Any Port: all traffic that is received by Peplink Balance via the specified protocol is forwarded to the servers specified by the Servers setting.
USER MANUAL Peplink Balance Series 15.2 Definition of Servers on LAN (Available on Peplink Balance 210+) The settings to configure servers on the LAN are located at the following location: Network> Inbound Access > Servers Inbound connections from the Internet will be forwarded to the specified Inbound IP Address(es) base on the protocol and port number .
This setting specifies whether the inbound service rule takes effect. When Yes is selected, the inbound service rule takes effect. If the inbound traffic matches the specified IP Protocol and Port, action will be taken by Peplink Balance based on the other Enable parameters of the rule.
Page 96
Any Port, Single Port, Port Range, Port Map and Range Mapping Any Port: all traffic that is received by Peplink Balance via the specified protocol is forwarded to the servers specified by the Servers setting.
Page 97
NS/SOA DNS records for a domain name can be delegated to Internet IP address(es) of Peplink Balance. Upon receiving a DNS query, Peplink Balance supports returning, as an “A” record, the corresponding IP address for the domain name on the most appropriate healthy WAN connection.It also supports acting as a generic DNS server for hosting “A”, “CNAME”, “MX”, “TXT”...
Page 98
USER MANUAL Peplink Balance Series DNS Settings This setting specifies the WAN IP addresses on which the DNS server of Peplink Balance should listen. If no addressesare selected, the Inbound Link Load Balancing feature will be disabled;Peplink Balance will not respond to DNS requests.
Page 99
Each WAN connection is associated with a priority number. Click Save to save the settings when configuration is complete. This section shows a list of domain names to be hosted by the Peplink Balance. Each domain can have its “NS”, “MX” and “TXT” records, andits sub-domains’ “A” and Domain name “CNAME”records.Add a new record by clicking the New Domain Name button.
Page 104
A record may be automatically added for the SOA records with a Name Server IP Address provided. A Record Editing This field specifies the A record of this sub-domain to be served by the Peplink Balance. *.domain.name The wildcard character “*” is supported. The IP addresses of "...
Page 105
For example, if the IP address range 11.22.33.0 to 11.22.33.255is delegated to the DNS server on the Peplink Balance, you will also have to create a domain 33.22.11.in-addr.arpa and have its NS records pointing to your DNS server’s (the Peplink Balance) public IP addresses.
Page 107
Domain Delegation These are the steps to be used when you host your domain at your ISP or a domain registrar and want to delegate a sub-domain to be resolved and managed at Peplink Balance. • Click New Domain Name button to add a domain name.e.g.www.mycompany.com. Click the corresponding domain name to view and edit record details.
Page 108
Testing the DNS Configuration The following steps can be used to test the DNS configuration: From a host on the Internet, use an IP address of Peplink Balance and nslookupto lookup the corresponding hostname. Check the information that is returned for the expected results.
To configure, navigate to Network >WLAN Controller and the following options will be shown. Special Note 10 and 20Pepwave AP One / AP One Mini devices can be controlled by a Peplink Balance305/380/580 and 710/1350/2500 respectively without extra costs.To manage more, a Full Edition license is required. Please contact our Authorized Reseller or Peplink Sales Team to obtain more information and price details.
Page 119
Device’s Name, Location and Channel can be changed here. A customized Captive Portal page can be configured for each Peplink Balance device. Tostart, click the link Captive Portal Settingsand you will be forwarded to the configuration page.For details, please refer to section 17.4.
When this option is enabled, web redirection will be applied to all unauthenticated Wi-Fi clients associated with this wireless network. Requests by unauthenticated Wi-Fi clients will be redirected to this Peplink Balance's built-in captive portal site. To configure the captive portal site, click the link “configure your Captive Portal”...
Click the link configure your Captive Portal to start configuration. Once the configuration is complete, click the button Save to save settings. Important Note Only one portal page customization is available for each Peplink Balance device, multiple wireless networks with captive portal enabled will be redirected to the same portal page. 17.4.1 General...
Page 136
This setting is only available when the protocol is selected as 802.11bgn or 802.11n Only. Channel Bonding There are three options: 20 MHz, 20/40 MHz and 40 MHz With this feature enabled, it allows the Wi-Fi system to use two channels at once. Using two channels improves the performance of the Wi-Fi connection •...
Page 137
Frame Length length for frame aggregation. By default, it is set as 50000. Web Administration Settings Check the box to allow Peplink Balance to manage the web admin access information of Enable the Pepwave AP One. This option specifies the web access protocol used for accessing the web admin of Web Access Protocol Pepwave AP One.
Peplink Balance Series 18.1 User Groups (Available on Peplink Balance 305 and380+) LAN and PPTP clients can be categorized into three user groups - Manager, Staff, and Guest.This table allows you to define rules and assign client IP addresses or subnets to a user group. You can apply different bandwidth and traffic prioritization policies on each user group in the Bandwidth Control and Application sections.
By default, 50% of bandwidth has been reserved for Manager, 30% for Staff, and 20% for Guest. You can define a maximum download speed (over all WAN connections) and upload speed (for each WAN connection) that each individual Staff and Guest member can consume.
Three priority levels can be set for application prioritization: Normal, and↓Low. Peplink Balance can detectvarious application traffics by inspecting the packets' content. Select an application by choosing a supported application, or by defining a custom application manually. The priority preference of supported applications is placed at the top of the table. Custom applications are at the bottom.
Page 141
Action column to delete the custom application in the corresponding row. WhenSupported Applications is selected, the Peplink Balance will inspect network traffic and prioritize the selected application. Alternatively, select Custom Applicationsand define the application by providingthe protocol, scope, port number, and DSCP value.
LAN side of the network.It can protect the local network from potential hacker attacks, offensive Web sites, and/or other inappropriate uses. The firewall functionality of Peplink Balance supports the selective filtering of data traffic in both directions: Outbound (LAN to WAN) ...
Page 144
Protocol/IP/Port, actions will be taken by Peplink Balance based on the other parameters of Enable the rule. When No is selected, the firewall rule does not take effect. Peplink Balance will disregard the other parameters of the rule. This setting is applicable to Inbound Firewall Rules only.
Page 145
Destination IP & Port Action With the value of Allow for the Action setting, the matching traffic passes through Peplink Balance (to be routed to the destination). If the value of the Action setting is set to Deny, the matching traffic does not pass through Peplink Balance (and is discarded).
For example, If you enter "foobar.*," then "www.foobar.com," "www.foobar.co.jp," or "foobar.co.uk" will be blocked. Placing the wild card in any other position is not supported. The Peplink Balance will inspect and look for blocked domain names on all HTTP traffic. Secure web (HTTPS) traffic is not supported. 19.2.2 Exempted User Group Check and select pre-defined user group(s) who can exempt from the access blocking rules.
Peplink Balance supports High Availability (HA) configurations via an open standard Virtual Router Redundancy Protocol (VRRP, RFC 3768). In an HA configuration, two same-model Peplink Balance units (e.g. a pair of Peplink Balance 210 units, or a pair of Peplink Balance 710 units) provide redundancy and failover in a master-slave arrangement.
Page 151
Checking this box specifies that the Peplink Balance unit is part of a High Availability High Availability configuration. This setting specifies a number that identifies a pair of Peplink Balance units that operate in a Group Number High Availability configuration.
This setting is for specifying the source of user database for PPTP authentication. There are three sources can be selected: Local User Accounts, LDAP Server, RADIUS Server. Local User Accounts - User accounts are stored in the Peplink Balance locally. You can add/modify/delete the accounts in the User Accounts table below.
Some ISPs require their users to send e-mails via the ISP’s SMTP server.All outgoing SMTP connections are blocked except those connecting to the ISP’s. The Peplink Balance supports to intercept and redirect all outgoing SMTP connections (destined for TCP port 25) via a WAN connection to the WAN’s corresponding SMTP server.
Page 156
Outbound Policy (see Section 14.1). 20.3.2 Web Proxy Forwarding When this feature is enabled, the Peplink Balance will intercept all outgoing connections destined for the proxy server specified in "Web Proxy Server Interception Settings", choose a WAN connection with reference of Outbound Policy, and then forward them to the specified web proxy server and port number.
20.4 Service Passthrough Service Passthrough settings can be found at:Network >Misc. Settings> Service Passthrough Some Internet services required to be specially handled in a multi-WAN environment.The Peplink Balance supports handling such services correctly such that Internet applications do not notice it is behind a multi-WAN router.
Page 159
USER MANUAL Peplink Balance Series Admin Settings This field allows you to define a name for this Peplink Balance unit. Router Name By default, Router Name is set as Balance_XXXX, where XXXX refers to the last 4 digits of the serial number of that balance unit.
Do not disconnect the power during firmware upgrade process. Do not attempt to upload a non-firmware file, or a firmware file that is not qualified,or not supported, by Peplink. Upgrading Peplink Balance with an invalid firmware file will damage the unit, and may void the warranty.
This specifies the time zone (along with the corresponding Daylight Savings Time scheme) in which Peplink Balance operates. Time Zone The Time Zone value affects the time stamps in the Event Log of Peplink Balance and E- mail notifications. Checked the box Show all to show all time zone options.
Email Notification Administrator when the WAN status changes, or when new firmware is available. If the box Enable is not checked, Email Notification is disabled and Peplink Balance will not send email messages. This setting specifies the SMTP server to be used for sending email. If the Server requires SMTP Server authentication, check the box Require authentication.
USER MANUAL Peplink Balance Series 21.6 SNMP SNMPor Simple Network Management Protocolis an open standard that can be used to collect information about the Peplink Balance unit. SNMP configuration is located at:System> SNMP SNMP Settings SNMP Device This field shows the router name defined in System > Admin Security.
21.7 InControl When this check box is checked, the device’s status information, usage data, and configuration will be sent to Peplink’s InControl system. You can sign up for an InControl account athttps://incontrol.peplink.com/ . You can register devices under the account, monitor device status and usage reports, and download backed up configuration files.
In a High Availability (HA) configuration, to quickly load onto the Peplink Balance unit the configuration of its HA counterpart, click theUploadbutton. After loading the settings, configure the LAN IP address of the Peplink Balance unit to be different from the HA counterpart.
This page provides a Reboot button for restarting the system. For highest reliability, Peplink Balance series are equipped with two copies of firmware of different version. You can select the firmware version you would like the device to reboot with.
USER MANUAL Peplink Balance Series 22.2 Traceroute Test The Traceroute Test tool in Peplink Balance traces the routing path to the destination through a particular Ethernet interface or a SpeedFusion connection(VPN connections are available on Peplink Balance 210+). The Traceroute Test utility is located at System> Tools >Traceroute, illustrated as follows: A System Administrator can use the Traceroute utility to analyze the connection path of a LAN/WAN connection.
DB-9 end to a terminal's serial port. The port setting will be 115200,8N1. The serial console connector with the Peplink Balance 305, 380 HW rev 1 to 4, Peplink Balance 710 HW rev 1 is DB-9 male connector. To access the serial console port, connect a null modem cable with a DB-9 connector on both ends to a terminal with the port setting of 115200,8N1.
The second table shows the MAC address of each LAN/WAN interface connected. Important Note If you encounter issues and would like to contact Peplink Support Team (http://www.peplink.com/contact/), please download the diagnostic report file and attach it along with a description of your encountered issue.
(retrieved from DHCP reservation table or defined by users), current Download and Upload rate and MAC address that the Peplink Balance has offered IP addressesto since it is powered up. Clients can be imported into DHCP Reservation table by clicking the button on the right-most column.
Peplink Balance Series 23.4 Access Point (Available on Peplink Balance 305 and 380+) The Status of connected access point devices can be found at Status > Access Point. It lists all connected or detected Pepwave access point devices and their IP address, firmware version, assigned AP profile, number of connected clients and broadcasting channel.
23.7.1 Device Event Log The log section displays a list of events that has taken place on the Peplink Balance unit.Click the Refresh button to retrieve log entries again. Click the Clear Log button to clear the log. Select 50, 100, or allto show the corresponding number of events in the log.
Peplink Balance Series 23.7.2 AP Event Log (Available on Peplink Balance 305,380+) This section displays a list of events that has taken place on the connected/detected Pepwave AP devices. Select 50 or 100 to show the corresponding number of events in the log. Check the box next to Auto Refresh and the log will be refreshed automatically.
USER MANUAL Peplink Balance Series Appendix A. Restoration of Factory Defaults To restore the factory default settings on a Peplink Balance unit, perform the following: For Balance 20/30/210/310: Locate the reset button on the Peplink Balance unit. With a paper clip, press and keep the reset button pressed for at least 10 seconds, until the unit reboots itself.
Peplink Balance Series Appendix B. Routing under DHCP, Static IP, and PPPoE The information in this appendix applies only to situations where Peplink Balance operates with to a WAN connection under DHCP, Static IP, and PPPoE. Routing via Network Address Translation (NAT) When Peplink Balance is operating under NAT mode, the source IP addresses of outgoing IP packets are translated to the WAN IP address of Peplink Balance.
USER MANUAL Peplink Balance Series Routing via IP Forwarding When Peplink Balance is operating under IP Forwarding mode, the IP addresses of IP packets are unchanged; Peplink Balance forwards both inbound and outbound IP packets without changing their IP addresses.
WAN connection for source-destination pairs of IP addresses,and prevents sessions from being dropped. With Persistence is configured and the option By Sourceis selected, Peplink Balance uses a consistent WAN connection for same source IP addresses. This option offers even higher application compatibility but the outbound traffic load will be distributed more evenly only if more users use the Internet.
C.4.2 Solution Firewall functionality is builtinto Peplink Balance. By default, inbound access is unrestricted. Enabling a basic level of protection involves setting up firewall rules. For example, to set up a firewall rule between the Internet and the private network that monitors Web...
For security reasons, it may be appropriate to disallow LAN usersto use ftp to transfer files to and from the Internet, or otherwise restrict outbound access. This can easily be achieved by setting up an outbound firewall rule with Peplink Balance. C.5.2 Solution...
Try to test with a web site that does not enable Keep Alive. For example, tryhttp://private.dnsstuff.com/tools/aboutyou.ch(This third-party web site is provided only for reference.Peplink has no association with the site and does not guarantee the site's validity or availability.) Problem 4...
Page 196
You can test the WAN connection by Ping, which is similar to problem 4. As we want to isolate the problems from the LAN, Ping will be performed from Peplink Balance. By using the Ping/Tracerouteunder the tab Status of the Peplink Balance, you may able to find out the source of problem.
Rules-based Stateful Firewall, with IP, Protocol, and Port filtering • Intrusion Detection System Physical Interface • Two (Balance 20) / Three (Balance 30) RJ-45 for an IEEE 802.3u 10/100/1000M WAN • Four RJ-45 for an IEEE 802.3ab 10/100/1000M LAN Power Specification ...
USER MANUAL Peplink Balance Series Peplink Balance 210 and 310 Routing Drop-in Mode and NAT Flexible Custom Outbound Routing Policy WAN Support DHCP, PPPoE and Static IP Inbound and Outbound Link Load Balance Device Management ...
Need help?
Do you have a question about the 20 and is the answer not in the manual?
Questions and answers