RS232 INTERFACE ....................21 RS485 INTERFACE ....................21 INPUTS & OUTPUT ....................22 GSM CONNECTION ....................23 Checking the GSM reception signal level..........23 Antenna......................23 Installing the SIM card ................. 24 ../.. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 3...
Page 4
CONTENT SETUP SET UP STEPS......................25 CONFIGURING THE IPL-G12 ROUTER ..............26 Overview ....................... 26 First configuration ..................28 Modifying the configuration................ 29 REBOOTING THE ROUTER AFTER PARAMETERS CHANGES ......29 RECOVERING THE IP ADDRESS OF THE ROUTER..........30 RECOVERING THE FACTORY CONFIGURATION ..........30 RESTRICTING ACCESS TO THE ADMINISTRATION SERVER ......
Page 5
20.1 Overview ....................... 71 20.2 Remote user filter..................72 SERIAL TO IP GATEWAY..................77 21.1 Modbus gateway ..................78 21.2 RAW TCP gateway ..................81 21.3 RAW UDP gateway..................83 ../.. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 5...
Page 6
Configuring the DNS server ................ 88 DIAGNOSTIC AND MAINTENANCE DIAGNOSTIC ......................91 SAVING THE PARAMETERS TO A FILE ..............92 FIRMWARE UPDATE ....................93 APPENDIX 1 : HTML configuration server APPENDIX 2 : VPN technology overview User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 6...
• • means the function is provided - means the function is not provided Important notice : In the manual hereafter, when we speak of “IPL-G12”, it means both the IPL-G12B and IPL-G12B-3G references 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02...
1980 MHz UMTS 850 Band V 869 MHz 894 MHz Downlink (Node B to UE) UMTS 1900 Band II 1930 MHz 1990 MHz UMTS 2100 Band I 2110 MHz 2170 MHz User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 8...
Page 9
VPN PPTP / L2TP-IPSec / TLS Open VPN Connection Login & password Certificate X509 VPN Compliant with the M2Me_Secure VPN client M2Me Compliant with the M2Me_Connect mediation service Alarms 3 inputs : emails 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 9...
Page 10
1200 - 115200 b/s parity N / E / O Serial gateway : RAW UDP client & server multi-unicast, Raw TCP client & server, Serial to IP gateways Modbus client and server, Telnet server, unitelway User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 10...
UMTS 3G or the GPRS-EDGE service. The connection is permanent. IPL-G12B router The IPL-G12B router provides the same function but over the GPRS-EDGE service (and not over the UMTS 3G service). 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 11...
Page 12
If the VPN is established between a remote user PC and an IPL-G12 router, the remote user can access to the devices connected to the router. The IPL-G12 router is able to establish up to 25 IPSec or TLS – SSL VPNs.
Page 13
DynDNS client The IPL-G12 router is compatible with the Dyn DNS service. DHCP client or server Over the Ethernet LAN interface, the IPL-G12 can be a DHCP client or server. Emails – sms An email (or SMS) can be sent each time one of the three digital inputs are opened or closed.
Page 14
OVERVIEW Remote access server The IPL-G12 provides to authorized users a remote access to the devices connected either to the LAN or to a serial RS232-RS485 interface, as if his PC was directly connected to the LAN or to the RS232.
The IPL-G12 can behave like a VPN client or a VPN server. Outgoing VPN connections to the Internet or to a private network are generally easy to set.. The IPL-G12 can also behaves like a VPN server to accept ingoing VPN connections from the Internet for instance. 3G-GPRS-EDGE router IPL-G12 User manual ref.
Page 16
OVERVIEW However, ingoing VPN connections from the Internet towards the IPL-G12 may not be possible if the IP address assigned to the router’s “antenna” interface by the provider is a private IP address. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12...
Data activity DATA Bytes transmitted to the RS232 (from the IPL) Bytes received from the RS232 (to the IPL) Blinks if the SIM cart has not been insterted Lit otherwise Operation 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 17...
Page 18
… briefly blinks 1 time The quality of the reception signal is poor No reception … is turned off Is a GSM voice communication possible ? has the SIM card been correctly inserted ? User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 18...
GSM RF transmitter. Ethernet interface The Ethernet interface is a 10 Mb/s interface. To connect a PC directly to the IPL, use the cross wired red cable provided with the product. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 20...
INSTALLATION RS232 interface The IPL-G12 router provides an RS232 and an RS485 interface. Asynchronous products can thus be integrated to the IP network. The RS232 cable must not be longer than 10 meters. RS485 interface The RS485 serial interface is provided on the bottom on a 2 pins screw-block.
The product features three digital inputs ; they are not isolated. if the input 1 is opened, an SNMP trap will be sent to the SNMP server if that function has been enabled. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 22...
The antenna must be ordered separately; the models below are available ANT200 ANT200 ANT200 0 db gain - magnetic 0 db gain 3 db gain 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 23...
Is a GSM voice communication possible ? has the sim card been correctly inserted ? Remark : The GSM signal level is also displayed in the administration server (menu “System” and then “Modem”). User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 24...
Case of 3G GPRS EDGE service using the M2Me_Connect connection service Case of GSM data connections • Setting up the remote users list • Setting up the firewall • Setting up alarm e-mails 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 25...
CONFIGURATION Configuring the IPL-G12 router Overview Administration server address : The administration html server is located at the LAN IP address of the router (The default address is192.168.0.128). Html browser : We advise to use Internet Explorer version 8. First configuration : For the first configuration, we advise to connect the PC directly to the LAN interface of the IPL-G12 router.
Page 27
A parameters file can only be downloaded to a product having the same firmware version. It is why, we advise to assign a name to a parameter file including the product name and the software version like for instance “myrouterfile_iplg12_V241.bin”. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 27...
192.168.0.128. Step 2 : Create or modify the PC IP connection. Assign to the PC an IP @ in accordance with the IPL-G12 IP address. For the first configuration, assign or instance 192.168.0.127 to the PC. Step 3 : Connect the PC directly to the LAN interface of the IPL-G12 router using a cross wired Ethernet cable.
To save the configuration file to a hard disk : • Select the “maintenance” menu and then the “Save / restore” menu. • Click the “Save current configuration to disk” button. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 29...
To restore the IPL-G12 factory configuration, • Switch OFF the power supply of IPL-G12 router. • Press the push-button on the top part of the IPL-G12 router and switch ON the power supply. • Keep the push-button pressed until the Operation led turns red.
That parameters define the pool of addresses which will be assigned automatically to remote user’s PCs when they will connect to the router. Enter the start address and the end address. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 31...
“Authentication” parameter : Unless particular difficulties, leave the default value “PAP/CHAP”. “Outgoing mail server” and “account email address” parameters : If emails have to be transmitted, enter the parameters. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 32...
CONFIGURATION Internet connection control The IPL-G12 can be connected on demand to the 3G GPRS EDGE network either by a local action or remotely. • Select the « Internet » menu and then click « Remote control ». «Connect to Internet after a phone call from » parameter : When a call comes in from the phone number entered in this field, the IPL-G12 connects to the Internet.
Select the “Internet” and “Modem” menu and check the 3G-GPRS checkbox is not selected. • Select the “System” and then click “Modem” menu. • The “Use default initialisation string” option must be selected unless particular communication difficulties. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 34...
Each time a device wishes to connect to the IPL-G12, it will use its host name and get its temporary IP address from the DYNDNS server. It will then connect to the IPL-G12 as if its address was fixed. To configure that function, • go to www.dyndns.org...
To get more explanations about how VPNs work, refer to appendix 2. 25 VPNs can be set on the WAN interface of the IPL-G12 router. Two types of VPN can be set : TLS VPN and IPSec VPN.
Select ESP to encrypt the data flow; select AH, if no encryption is required or if NAT traversal is required. “Authentication” & “encryption key” parameters : Authentication and encryption can be carried-out with a pre-shared key or a certificate. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 37...
Page 38
The same preshared key value will be used for remote users L2TP / IPSec connections. “Certificate” value The IPL-G12 router is delivered with a certificate stored into the product in our factory. To add a certificate, refer to the “Security” menu.
Page 39
To set an ioutgoing IPSec VPN connection, • Select the “Routing” and then the “Remote nodes” menu. • Click the “add a node” button. • Give a name to the connection and select the “Outgoing” option. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 39...
Page 40
“My subjectAlt name” & “Remote subjectAlt name” parameters : Paste the field "SubjectAltName" of the active certificate of the router you are configuring and the one the remote router. Attention : For ETIC certificates, this field is the Email field User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12...
Page 41
• Select the “Routing” and then the “Remote nodes” menu. • Click the “add a node” button. • Give a name to the connection and select the “ingoing” connection direction option. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 41...
Page 42
If that option is selected, enter the specific key. “My WAN address” & “Remote WAN address” parameters : Enter the WAN IP address of the IPL-G12 router (public IP address over Internet) and the WAN IP address of the remote router.
Select the “Remote nodes connections VPN type” value “TLS” and then click “Properties” . “Port number” & “protocol” parameters : Select the port Nr and the type of protocol used to transport the TLS VPN; UDP will be preferred. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 43...
Page 44
This parameters sets the amount of time (in seconds) the server will wait for the response before repeating it. “Encryption algorithm” & “Message digest algorithm” parameter : That parameters allow to define the encryption and hash algorithms in use. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 44...
Page 45
• Select the “Routing” and then the “Remote nodes” menu. • Click the “add a node” button. • Give a name to the connection and select the “Outgoing” connection direction option. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 45...
Page 46
Enter the IP address of the remote router or its DNS name. “Remote WAN IP address” parameter : Enter the network IP address and netmask assigned to the remote router over the Internet (public IP address over Internet). User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 46...
Page 47
Give a name to the connection and select the “ingoing” connection direction option. “Remote router Login” & “Remote router password” parameter : Enter the login and password of the remote router 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 47...
Enter the network IP address and netmask assigned to the remote LAN. “Common name” parameter : Enter the remote router certificate common name. Attention : For ETIC certificates, this field is the Email field Configuring connections between routers (9600 b/s GSM data) That function is provided only by the IPL-G12B router.
Page 49
“Idle time-out” parameter (5 s to 60 mn) : Set the time duration of the silence before the router will clear the call. “First packet time-out” parameter (5 s to 60 mn) : 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 49...
Page 50
“Router PPP IP address ” and “Remote router PPP IP address” parameters : Enter the IP address assigned to the PPP interface. If no IP address is entered, the address of the Ethernet interface is assigned automatically. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 50...
Remark 1 : Firewall rules must be set to authorize WAN to LAN transfer. Remark 2 : A default gateway address must be entered in each device of the different networks. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 51...
It is not necessary to enter the static route to the WAN network nor to the remote LAN network, that routes have been automatically created by the router respectively when the WAN IP address has been entered and when the VPN has been configured. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 52...
Each router updates its own table using the tables received from the other ones. To enable RIP, • Select the “Routing” menu and then “Static routes”. • Select the ‘ Enable RIP on LAN interface” and the “Enable RIP on WAN interface” options. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 53...
The transfer criteria is the port number used as an additional address field. When a frame is addressed to the IPL-G12 router on a particular port, it is transferred to a particular device connected to the LAN interface. Example : Suppose a remote device has to communicate with the devices PLC1 with TCP port 102, PLC2 with TCP port 502 and a PC port PLC1 192.168.0.15...
Page 55
CONFIGURATION • Click “Add a DNAT rule”. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 55...
SNAT function which consists in replacing the source IP address. Because the DNAT and SNAT functions modify the IP addresses of the IP packets processed by the IPL-G12 router, and because the firewall filters that frames, it is very important to understand in which order that different...
Page 57
CONFIGURATION 15.2.2 Configuration To set the advanced address translation functions • select the “Routing” , and then the “Advanced NAT” menu. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 57...
Page 58
• Enter the replacement criterion : Source IP address & Destination IP address. Protocol (TCP, UDP, …) Source port & Destination port • Enter the new destination port number and IP address. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 58...
Page 59
• Select “Yes” to enable the rule. • Enter the replacement criterions : Source & Destination IP address. Protocol (TCP, UDP, …) Source & Destination port • Enter the new source IP address. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 59...
A remote user connection (RAS connection) is a tunnel set between a remote PC and the IPL-G12 router. A remote user can set a RAS connection to the IPL-G12 router through the Internet. The RAS connection gives access to all the devices connected the router.
Page 61
CONFIGURATION RAS connection types The IPL-G12 manages PPTP and TLS or L2TP remote connections. Only one type can be selected. It will apply to all the remote users connections. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 61...
In that case, the PC certificate must be stored in the user list. «Encryption algorithm» & «Message digest algorithm» parameters: Leave the default values Step 2 : Configure the M2Me_Secure software User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 62...
Page 63
Select the « Advanced tab » ; select theprotocol (UDP or TCP), the port number and the encryption algorithm. The same values of that parameters must be assigned to the PC and to the router. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 63...
• select the “Security” menu, click “VPN connections” and then “VPN parameters”; • select the “Remote users connection VPN type” value : PPTP Step 2 : Set a PPTP connection on the PC side. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 64...
The M2Me_Connect service solves that difficulty : The PC does not connect directly to the IPL-G12; both the PC and the router connect to the “M2Me_Connect” service. Once both parties have been authenticated by the M2Me_Connect service with their own certificate, a TLS VPN is set from end to end from the PC to the IPL-G12 router.
Enter the product key of the router; it can be pasted from the “About” menu of the router. Attention : if you paste the product key, delete the last character and enter it again. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 66...
18.1 Principe If the GSM data service has been enabled, a remote PC, running a modem, can set a PPP switched connection to the IPL-G12 router. The PPP remote connection can be set through the GSM network if the PC is equipped with a GSM data modem.
• select the “Remote users connection VPN type” value : None • Select the “Modem” menu • Select the “external modem activate” checkbox. • Enter the initialisation string of the modem connected to the RS232 port of the router. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 68...
It is the name displayed in the user list. “Login” & “password” parameters : The login and the password will have to be entered by each user at the beginning of the remote connection. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 69...
Page 70
CONFIGURATION “E-mail” parameter The IPL-G12 router will send an email to that address in two situations : Alarm email : the router sends an alarm email to the user’s email address If the status of one of the three inputs is closed or opened (if that option has been set).
Configuring the firewall 20.1 Overview The firewall of the IPL-G12 router is a stateful packet inspection firewall; • it inspects the state of TCP or UDP or ICMP packet, to avoid spoofing. • It includes a “deny of service” filter able to resist to saturation attacks;...
Filter name : Access to the device PLC1 (html and modbus) Filter policy : All is forbidden except what we specify Rules list Action Device Service Allow PLC1 192.168.0.12 Allow PLC1 192.168.0.12 Modbus 502 User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 72...
Page 73
The list of the devices of the LAN network is displayed. • Click « add a device ». • Assign a label and an IP address to the device and click OK. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 73...
Page 74
CONFIGURATION • Step 3 : Build a filter • Select the « security» menu, then « firewall» and then «Filter list» The list of the stored filters is displayed. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 74...
Page 75
• Select a host (also called machine or IP address) among the ones which have been stored and a service (also called TCP port). • Add other rules if necessary. • Click OK when the filter is complete ; the updated filters list is displayed 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 75...
Page 76
Select the user to which you want to assign a filter ; and click modify ; the user window is displayed. • Assign a filter to the user ; click OK and save. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 76...
IP network, using a table of IP addresses. Telnet : To connect a Telnet terminal to the IPL_G12 router. Unitelway slave : To connect a serial unitelway master to an IP network. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 77...
Set up the timeout the gateway has to wait for the answer of the modbus slave answer. Local retry : Set up the number of times the gateway will repeat a request before declaring a failure. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 78...
Page 79
TCP inactivity Timeout : Set the time the gateway will wait before disconnecting the TCP link if no characters are detected. TCP port number : Set the port number the gateway has to use. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 79...
Page 80
This gateway allows to connect a serial modbus master to the serial interface of the IPL-G12. • Select the modbus menu and then “modbus client” menu; enable the “modbus client” gateway and set up the parameters as follows : ASCII / RTU protocol...
Set up the delay the gateway will wait before declaring complete a string received from the asynchronous device. Once declared complete, the gateway will transmit the string to the IP network. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 81...
Page 82
Set up the delay the gateway will wait before declaring complete a string received from the asynchronous device. Once declared complete, the gateway will transmit the string to the IP network. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 82...
Serial data transmitted by each device is transmitted to all other serial devices through the IP network. A table of IP destination gateways is stored in each IPL-G12 belonging to the group. The serial data is encapsulated in the UDP protocol.
Page 84
This table stores the IP addresses of the gateways to which the serial data, encapsulated inside UDP, have to be sent. A different UDP port number can be entered for each destination IP address. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 84...
ETIC TELECOM acting as a certification authority. That certificate can be used to set a VPN between two routers. Two IPL-G12 routers can set a VPN with one another using certificates only if the certificates have been provided by the same authority.
Page 86
Select the time the input has to stay in its alarm state to be taken into account. “Alarm destination“ parameter Select the user to whom the email must be sent. “Text to send” Enter the email text. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 86...
If the we portal option has been selected (see below), the web portal page is displayed when the remote user launches the navigator and enters the Ip address assigned to the IPL-G12 router. In that case, the administration server, usually can be displayed at the same address but at the port number 8080 instead of 80 when the web portal page option is not selected.
Signal to noise margin (SNR margin), G821 error rates indicators. • VPN sub-menu That menu displays the table of the VPN (remote user connections and remote routers connections) which are established. 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 91...
Attention : A parameters file can only be restored towards a product having the same firmware version. It is why, we advise to assign a name to a parameter file including the product name and the software version like for instance “myrouterfile_iplg12_V241.bin”. User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 92...
Step 4 : Update the firmware Launch the web browser Enter the IP address of the ETIC product ; the home page of the ETIC configuration server is displayed. Select the "System" menu and then " firmware Update". In the field "IP address of the TFTP server", enter the IP address of your PC.
To restrict access to devices of the LAN To set the VPNs parameters and register certificates Internet To register the Internet subscription parameters Account To set the conditions the router will connect to the Internet Remote control 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 95...
Page 96
To display the IOs status IO control To display the connections Resume Alarms To enter the conditions an email is transmitted to a user About To display the firmware and hardware identification User manual ref. 9017009-02 3G-GPRS-EDGE router IPL-G12 Page 96...
Page 97
The VPN ensures that the party with which the communication is set is actually the one it claims to be. Data integrity The VPN mechanism ensures that information being transmitted over the public Internet is not altered in any way during transit 3G-GPRS-EDGE router IPL-G12 User manual ref. 9017009-02 Page 97...
Page 98
During the initial phase, the two end-point exchange their codes; each party checks that the other party code is valid. User level authentication The IPL-G12 router holds a user list; once a VPN has been set with the remote user PC, the remote user identification code and password is checked.
Need help?
Do you have a question about the IPL-G12 and is the answer not in the manual?
Questions and answers