Contemporary Controls CTRLink EIAR-10T User Manual

Internet access router
Table of Contents

Advertisement

Quick Links

CTRLink-
Router
EIAR-10T
Internet Access Router
Contemporary Controls GmbH
Fuggerstraße 1 B
04158 Leipzig
Tel.: 341-520359-0
Fax: 341-520359-16
Version 2.4.1, Oktober 2005

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CTRLink EIAR-10T and is the answer not in the manual?

Questions and answers

Summary of Contents for Contemporary Controls CTRLink EIAR-10T

  • Page 1 CTRLink- Router EIAR-10T Internet Access Router Contemporary Controls GmbH Fuggerstraße 1 B 04158 Leipzig Tel.: 341-520359-0 Fax: 341-520359-16 Version 2.4.1, Oktober 2005...
  • Page 2 All products mentioned herein may be trademarks or registered trademarks of their respective owners. TM® CTRLink are trademarks registrated by Contemporary Controls GmbH and Contemporary Control Systems Inc. ® HEYFRA registrated trademark by HEYFRA ELECTRONIC GmbH Handbuch: Manual CTRLink Router EIAR-10T Datei: manualrouter en 11-1-05.doc 26.10.2005 Revision c11-1/05...
  • Page 3: Table Of Contents

    Contents Safety Notes Graduated safety notes Definitions Hazards resulting from use other than as described Hazards resulting from modifications and upgrades Admitted personnel 1.5.1 Operator 1.5.2 Start-up engineer 1.5.3 Service engineer Electrical connections Safety regulations Service and maintenance Waste disposal 1.10 Liability Use as Prescribed...
  • Page 4 Contents 4.1.4 Configuring via the RS 232 interface 4-19 4.1.4.1 Available configuration services for different connections 4-19 Configuring via the Ethernet 4-19 4.2.1 Adaptation of the IP address 4-19 4.2.1.1 Windows 2000 4-20 4.2.1.2 Setting up the network card under Linux 4-22 4.2.2 Configuring via a null-modem cable...
  • Page 5 Contents 4.3.2.5 SSH configuration 4-53 4.3.2.6 HTTP configuration 4-54 4.3.2.7 Firewall configuration 4-54 4.3.2.8 Modem configuration 4-55 4.3.2.9 DynDNS configuration 4-57 4.3.2.10 VPN configuration 4-58 4.3.2.11 Logging configuration 4-59 4.3.3 Configuring using the SSH server 4-60 Configuring the client computers 4-62 4.4.1 Configuring the computers in the Routers Ethernet...
  • Page 6 Contents Standards and Certifications 7-74 Harmonised standards 7-74 Certification to DIN EN ISO 9001 7-74 Approbations 7-74 CE marking 7-74 Symbols Used 8-75...
  • Page 7: Safety Notes

    Safety Notes Safety Notes Graduated safety notes In this Instruction Manual, safety notes are marked with a symbol and the keyword CAUTION or NOTE at the page margin. Safety notes are printed in bold letters and are marked with an outside border. 1.2 Definitions The keyword CAUTION is used to warn you of a possibly hazardous situation.
  • Page 8: Admitted Personnel

    Safety Notes Unauthorised modifications and amendments are not permissible. Such unauthorised modifications or amendments may impair the proper operation of the remote diagnosis unit, resulting in personal injuries, material damage or environmental impairments and will render all liability on our part null and void. CAUTION 1.5 Admitted personnel Only sufficiently qualified and instructed personnel are allowed to...
  • Page 9: Electrical Connections

    Safety Notes Electrical connections The Internet Access Router must be connected to an electrical supply system. Power supply connection The Internet Access Router must only be connected to the electrical supply system by an electrical expert. The power supply of the Internet Access Router must be provided CAUTION exclusively by a power pack which complies with DIN EN 60 742 (VDE 0551).
  • Page 10: Service And Maintenance

    Safety Notes Service and maintenance Service and maintenance work Improper service and maintenance may result in loss of life, personal injuries, material damage or environmental impairments. Service and maintenance work, as well as troubleshooting, must CAUTION only be carried out by qualified expert personnel. Before performing service or maintenance work, always switch off the power supply of the Internet Access Router first! Reinstall all panelling, protective covering and safety devices...
  • Page 11: Liability

    Safety Notes 1.10 Liability The contents of the present Instruction Manual are subject to technical modifications, which may result, in particular, from the continuous further development of the products made by Contemporary Controls. Contemporary Controls will not assume any liability for printing errors or any other inaccuracies contained in the present Instruction Manual, unless these are serious errors which are evidently known to Contemporary Controls.
  • Page 12: Use As Prescribed

    Use as Prescribed Use as Prescribed Range of application The Internet Access Router grants an industrial IP network access to the Internet via its integrated analog or ISDN modem. It provides the transport of IP packets between IP-based industrial network and another network (e.g. Internet). The Internet access is activated automatically as necessary.
  • Page 13: Description Of Functions

    Description of Functions Description of Functions General Description of Functions The Internet Access Router provides a local Ethernet based on TCP/IP the transition to another IP network via a PPP connection (long-distance data transmission). This transition is normally provided via the internal modem integrated into the router (56k Analog Modem or ISDN Modem, see Chapter 6).
  • Page 14: Functioning Of "Dial-In Server

    Description of Functions Depending on the modem type you are using (analog or ISDN) and depending on the quality of the telephone line, this process may take up to 60 seconds. During this time, some applications trigger a timeout and will treat your query to the Internet as failed. It may therefore be necessary to adapt the timeout times of your NOTE programs.
  • Page 15: Call-Back Functionality

    Description of Functions The connection is only cleared if this is specified manually by the remote computer. Please note that dialling during an existing modem connection is not possible, since the telephone line is already busy. NOTE Call-back functionality The router can be configured such that it will not work as a dial-in server (see Section 4.3.1.15).
  • Page 16 Description of Functions With this device, it is also possible to use an external modem (analog, ISDN, GSM), alternatively to the internal modem integrated into the router. To do so, connect the modem to the RS232 interface of the router NOTE labelled EXTERNAL using an RS232 connection cable.
  • Page 17: The Boot Process

    Description of Functions The boot process During the boot process, all services and programs required are started automatically. This process will take approx. 2 minutes. Starting the boot process: States of the LEDs: ACTIVE MODEM: ACTIVE ETHERNET: ERROR: green POWER: The settings are loaded.
  • Page 18: Configuration

    Configuration Configuration Before the router can be started up, it must be configured. The individual steps for starting up will be explained in the present chapter. Configuring options 4.1.1 Configuring via the Ethernet interface With this configuring option, a computer integrated into your Ethernet may be used for configuring.
  • Page 19 Configuration Then click on the icon in the toolbar to start the connection. The connection is established. A log-in window will appear on the router. If not, press ENTER. Enter the password (default: ctr) To set the IP address, type the command "setip" followed by the address and the subnet mask of the local network using the following format.
  • Page 20: Configuring Via A Null-Modem Cable

    Configuration The current IP address of the router can be interrogated in the terminal using the command "ifconfig". If you use the parameter "ifconfig eth0", only the IP address is displayed. The commands "setip", "save" and "ifconfig" are additional scripts and are therefore not shown in the list of "build-in commands".
  • Page 21: Configuring Via The Rs 232 Interface

    Configuration 4.1.4 Configuring via the RS 232 interface The router is connected to a PC via the RS 232 interface "Console" using a null-modem cable. The RS232 protocol is used directly so that no IP communication is possible. The difference to configuration using a zero-modem cable connected to the external modem connection is that no full PPP connection is created;...
  • Page 22: Windows 2000

    Configuration If your Ethernet network address is also 192.168.1.0, you may skip the following instructions. In this case, you can proceed with Section 4.1 Configuring options. In the operating systems Windows NT-SP6, Windows 2000, Windows XP or Linux/Unix, you may assign the network card of the appropriate computer more than one IP address (see Section 4.2.1.1 and Section 4.2.1.2).
  • Page 23 Configuration The basic network settings are already entered here. To add a second IP address to your network card, click on "Add" in the upper field "IP addresses" and type 192.168.1.120 for the IP address and 255.255.255.0 for the subnet mask. Then click on OK; the result should look as follows: The computer you have just configured can now be seen both in the network 192.168.101.0 and in the network 192.168.1.0.
  • Page 24: Setting Up The Network Card Under Linux

    Configuration The welcoming text of the embedded web server will appear. To configure the router, proceed as described in Section 4.3.1. 4.2.1.2 Setting up the network card under Linux To assign a network card two IP addresses under Linux, you must possess root rights.
  • Page 25: Configuring Via A Null-Modem Cable

    Configuration Thereafter, you will be prompted to enter your user name and your password (default: user: admin, pass: ctr). The welcoming text of the embedded web server will appear. Now you can proceed with Section 4.3.1. 4.2.2 Configuring via a null-modem cable Prerequisites: A PC with web browser and a free 9-pin serial interface, as well as a zero-modem cable are required.
  • Page 26 Configuration Set the role you want to choose for this computer in the next tab to "Host": Now select the connection to which your zero-modem cable is connected: Answer the next question with "Use connection exclusively": 4-24...
  • Page 27 Configuration Enter a name for your connection (e.g.: "Zero modem"): Click on "Finish". If your PC attempts to establish a new connection immediately, this should first be cancelled. To process the connection just established, choose "Properties" from the context menu: On the "General"...
  • Page 28 Configuration Now you can establish a connection. If you double-click on the zero- modem connection, the following screen should appear: 4-26...
  • Page 29: Configuring Via The Telephone Network

    Configuration Enter ’extern’ as the user name for yourself, too, and ’ctr’ for the password (default values). Call a browser and type the address 192.168.7.1 Thereafter, you will be prompted to enter your user name and your password (default: user: admin pass: ctr). The welcoming text of the embedded web server will appear.
  • Page 30 Configuration Choose "Connect directly to another computer" for the type of connection: Enter the number of the telephone connection to which the router is connected: If you are prompted to specify the availability of the connection, choose the option "Use connection exclusively": 4-28...
  • Page 31 Configuration Enter a name for your connection (e.g.: "Zero modem"): If you are connected to a private telecommunications switching system, please note that no dialling tone is to be heart in the telephone. In this case, you must configure the modem such that it does not wait for the dialling tone.
  • Page 32: Configuring Via The Rs 232 Interface

    Configuration Thereafter, you will be prompted to enter your user name and your password (default: user: admin, pass: ctr). The welcoming text of the embedded web server will appear. Now you can proceed with Section 4.3.1 . 4.2.4 Configuring via the RS 232 interface It is not recommended to use this type of configuration.
  • Page 33: Configuration Services

    Configuration Configuration services 4.3.1 Web browser You may use any browser which is able to handle frames as the configuration tool. The configuration has been tested successfully using Internet Explorer 5.x, Mozilla 1.x, Opera 7.x and Konquerer 3.x. If the factory default settings have not been changed, the integrated web server of the router is started if you enter the IP address 192.168.6.1 (for modem) or 192.168.7.1 (for direct serial line) or 192.168.1.100 (for Ethernet) as the URL.
  • Page 34: Menu Option "General

    Configuration The screen is divided into four areas. The "Navigation" area can be found on the left-hand side. Here you can choose the functionalities. The meaning of the individual elements is explained in the following sections. The home page is called by clicking on the house in the top right window (see illustration above).
  • Page 35 Configuration TCP/IP configuration Enter the host and the domain name, as well as the IP address and the subnet mask of your router here. To activate the online help for the individual items, simply click on the appropriate menu option. Brief info IP addresses: An IP address consists of the number of the IP network and of the number of a host in this network.
  • Page 36: Menu Option "Date & Time

    Configuration It is strongly recommended to replace the default password ’ctr’ by your own password with 8 characters. Keeping the default password constitutes a significant breach in security. CAUTION Configuring the serial console Here you can set the velocity of the serial console. If you connect the serial console to an IBM/PC (i386 or higher), you may keep the default value 115,200.
  • Page 37: General Modem Settings

    Configuration If switching between daylight saving time and standard time is required in the country where the router is used, select the relevant field. You may configure the rules applying in this country. In the European Union, daylight saving time always starts on the last Sunday in March, which can be set as the 5th Sunday in March.
  • Page 38 Configuration Always ensure that the modem has been assigned the correct country code; otherwise, you will not be allowed to dial in. Please save your configuration immediately after changing the country code. Otherwise, all your settings are lost after a cold restart of your router.
  • Page 39: Menu Option "Dns

    Configuration If a GSM modem is connected to the external interface of your router, specify the AT command with which your PIN is transmitted to your modem, and the PIN itself. This PIN is transmitted to the GSM modem automatically upon completion of configuring and with each start. If an error occurs during these processes, check first the status of your GSM modem.
  • Page 40: Menu Option "Ssh

    Configuration The domain name service serves to resolve the names in a network. Resolving names means that each IP address is assigned a name which is easy to remember. This service is offered by the server. In order not to be compelled to enter all hosts of the entire company or even of the entire Internet here, the DNS forwarder concept has been created.
  • Page 41: Menu Option "Http

    Configuration You may create a user for access to the SSH. If not, no additional user will be created, and only access to the administrator is granted via SSH. It is recommended to create an additional user here to provide an additional less privileged access to the system.
  • Page 42: Menu Option "Logging

    Configuration Please observe the port entered here must not be occupied by another service (DNS, SSH, VPN, etc.). CAUTION 4.3.1.7 Menu option "Logging" If the logging service is activated, the router issues status messages regarding its current activities. All these status messages are generally output to the serial console.
  • Page 43 Configuration The type of status messages ranges from very simple information up to critical errors. It is also possible to define that no more messages are received explicitly from certain services: • debug Creates status messages which may signal software errors in the respective service.
  • Page 44: Menu Option "Firewall

    Configuration 4.3.1.8 Menu option "Firewall" The firewall of the router offers two data filtering options: • a packet filter • a port filter The packet filter always considers the IP addresses. It only passes IP packets with permitted IP addresses, and blocks packets of illegal addresses.
  • Page 45: Menu Option "Firewall - Masquerading

    Configuration 4.3.1.9 Menu option "Firewall - Masquerading" Specify the networks to be masked externally here. If you are using unofficial IP addresses, such as 192.168.x.x, and if the router is nevertheless to be used for access to the Internet, it is imperative to specify them here.
  • Page 46: Menu Option "Firewall - Trusted Nets

    Configuration Host filter Certain computers may be granted access specifically to other networks (white list) or else, conversely, it is possible to prohibit some computers access to other networks (black list). In this case, the packet filter will merely pass packets of the specified computers or else it will block precisely these.
  • Page 47: Menu Option "Firewall - Destination Nat

    Configuration 4.3.1.12 Menu option "Firewall – Destination NAT" Destination NAT For various Internet protocols it is imperative to divert a connection established for a computer from the outside to the internal network. If the network is masked externally ("IP masquerading", see 4.3.1.19), i.e. only one official IP address exists for the entire LAN, certain ports or protocols to which access is to be granted from the outside can be diverted to a certain internal computer.
  • Page 48: Menu Option "Dial-Out - Modem

    Configuration 4.3.1.13 Menu option "Dial-out - modem" Dial-out (for example, into the Internet) is possible via the internal or the external modem. This dial-out into the Internet is done once the router receives a request for an IP address which does not belong to "its" network and which it can not assign otherwise to any of its known networks.
  • Page 49: Menu Option "Dial-Out - Dyndns

    Configuration 4.3.1.14 Menu option "Dial-out - DynDNS" With version 2.0 and higher, the router offers the facility to register with a DynDNS provider in the Internet so that it can be addressed using a fixed host name. This possibility can be configured here. To be able to use this capability, you must first register with a DynDNS provider.
  • Page 50: Menu Option "Dial-In

    Configuration Please note that the relevant DynDNS provider must be entered as the first name server on the client side to be able to resolve the host name of the router correctly. 4.3.1.15 Menu option "Dial-in" Dial-in can be performed either via the external or via the internal modem.
  • Page 51: Menu Option "Vpn Server

    Configuration 4.3.1.16 Menu option "VPN server" The VPN server can be used to establish secure (encrypted; 128bit blowfish encryption) connections to the router. To this end, a VPN server must be started on the router which will then assign the router a virtual IP.
  • Page 52: Menu Option "Save Settings

    Configuration 4.3.1.18 Menu option "Save settings" This menu option serves to save all changes made in the configuration permanently. Any changes are only held in the user memory until saving; they are lost when restarting the PC. The error LED of the router is lit in red during the saving process.
  • Page 53: Configuration Via The Serial Console

    Configuration 4.3.2 Configuration via the serial console This configuration method is not recommended. It should only be used if you are absolutely sure with the handling and programming of program commands in the terminal mode. Incorrect inputs or type errors may have the effect that the router does not function any more.
  • Page 54: Basic Configuration

    Configuration 4.3.2.2 Basic configuration HOSTNAME=’heyfra’ ..the host name of the router DOMAIN_NAME='lan.fli4l' ..the domain name of the router PASSWORD='ctr' ..the password of the administrator access of the router IP_ETH_1_IPADDR='192.168.1.100' ..the IP address of the router IP_ETH_1_NETMASK='255.255.255.0' ..
  • Page 55: Dns Configuration

    Configuration • M10.5.0: The daylight saving time ends on the last (5) Sunday (0) of the third (10) month. • In this file, date and time cannot be set. To this end, the commands "date" and "hwclock" which must be used on the console. 4.3.2.4 DNS configuration START_DNS='yes'...
  • Page 56: Http Configuration

    Configuration 4.3.2.6 HTTP configuration HTTPD_PORT='80' ..web server to be used by the SSH server HTTPD_USER_1='admin' ..user name for the web server HTTPD_PASS_1='ctr' ..password for the web server 4.3.2.7 Firewall configuration MASQ_NETWORK='192.168.1.0/24' ..networks to be masked (separate by spaces) ROUTE_NETWORK='192.168.6.0/24 192.168.7.0/24' ..
  • Page 57: Modem Configuration

    Configuration FORWARD_DENY_PORT_N='1' ..number of ports at which the acceptance of data is to be denied FORWARD_DENY_PORT_1='445 reject' ..port whose data are to be denied ("reject" is a keyword and is repeated in each entry). 4.3.2.8 Modem configuration OPT_MODEM='yes' ..
  • Page 58 Configuration INT_IPADDR='192.168.6.1' ..local IP address to be assigned for dial-in INT_PEER='192.168.6.2' ..remote IP address to be assigned for dial-in INT_USER='intern' ..log-in name for dial-in / call-back INT_PASS='ctr' ..password for dial-in / call-back EXT_DIALIN='yes' ..Configure external modem for dial-in? EXT_CALLBACK='no' ..
  • Page 59: Dyndns Configuration

    Configuration 4.3.2.9 DynDNS configuration OPT_DYNDNS='yes' ..Start dynamic DNS? DYNDNS_N='1' ..number of DynDNS providers you are using DYNDNS_1_PROVIDER='FIDOSOFT' ..name of the DynDNS provider; possible entries are: • AFRAID for afraid.org • CJB for cjb.net • COMPANITY for Companity •...
  • Page 60: Vpn Configuration

    Configuration DYNDNS_1_HOSTNAME='heyfra.fidosoft.de' ..host name to be to be registered with the DynDNS provider 4.3.2.10 VPN configuration VTUND_SERVER_1_NAME='tunnel01' ..name of the VPN server session VTUND_SERVER_1_PASS='ctr' ..password for the VPN server session VTUND_SERVER_1_PORT='4326' ..port of the VPN server VTUND_SERVER_1_COMPRESS='z2' ..
  • Page 61: Logging Configuration

    Configuration VTUND_CLIENT_1_SERVERNETMASK='255.255.255.0' ..virtual netmask of the VPN connection 4.3.2.11 Logging configuration OPT_SYSLOGD='yes' ..Activate logging of status messages SYSLOGD_REMOTE='yes' ..Forward status messages of remote hosts SYSLOGD_MARK_INTERVALL='60' ..time interval for the logging time marks in minutes SYSLOGD_DEST_N='1' ..number of logging rules SYSLOGD_DEST_2='*.* @192.168.1.123' ..
  • Page 62: Configuring Using The Ssh Server

    Configuration 4.3.3 Configuring using the SSH server For configuration using the SSH server, you will need an SSH client on your configuration computer. Appropriate tools can be downloaded from the Internet both for Windows and for Linux. A Windows client is also included on the supplied CD ("Putty").
  • Page 63 Configuration All further configuration steps are identical to those for configuring via the "Serial console" (see Section 4.3.2): After configuration, clear the SSH connection using the EXIT command. SSH is a telnet-like access to a remote computer. The only difference is that SSH will encrypt the entire communication.
  • Page 64: Configuring The Client Computers

    Configuration Configuring the client computers To run the client computers with the router, no special software needs to be installed, but some configuring notes must be observed. 4.4.1 Configuring the computers in the Routers Ethernet All IP packets sent from the Ethernet to the outside must always be routed via the router.
  • Page 65: Configuring A Remote Computer

    Configuration 4.4.2 Configuring a remote computer The remote computer has to be connected to an analog modem or ISDN modem, depending from the type of router. Only the same kind of modems can communicate each other. The steps described below refer to a windows system. When a remote computer dials into the router with a direct PPP connection, the modem interface of the computer gets assigned a dynamic IP address.
  • Page 66: Hardware

    Hardware Hardware Dimensions This Chapter provides all relevant information on the dimensions of: • Internet Access Router • Top-hat rail 5.1.1 Internet Access Router The sketch below shows the dimensions of the Internet Access Router: Dimensions [mm] Height Width Depth 5-64...
  • Page 67: Top-Hat Rail

    Hardware 5.1.2 Top-hat rail To fasten the router, a top-hat rail which complies with the standard EN 50022 is required. Fasten this top-hat rail on the control cubicle rear wall such that a conductive connection is provided. Observe the instructions of the manufacturer with reference to fastening.
  • Page 68: Swirl Mounting

    Hardware 5.1.3 Swirl mounting There ary two mounting plates intended for mounting of the device on the swirls. The mounting plates ary fastened with screws on the rear side of the housing and must B mounted ace shown in the illustration. The top-hat rail adapters must B removed if you mount the device on the swirls.
  • Page 69: Installation Notes

    Hardware Installation notes Make sure that at least 30 mm of clearance is left above the module. A space of 35 mm must be provided beneath the module to route the cables for the interfaces and for the power supply. 5.2.1 Mounting the router on the top-hat rail The device is intended for mounting on a top-hat rail to DIN EN 50022.
  • Page 70: Storage And Storage Temperatures

    Hardware • Do not connect or remove the connectors if the supply lines are still live (all-pole disconnection). Storage and storage temperatures The following values apply for storage: • Storage temperature: +60 °C • Humidity: 95 % (non-condensing) Operating temperature, humidity The following values apply for operation: Operating temperature for •...
  • Page 71: Status Display

    Hardware Status display A total of four LEDs are to be found on the front side of the Internet Access Router to display the current operating condition. 5-69...
  • Page 72: Display "Modem Connection Active

    Hardware 5.6.1 Display "Modem connection active" Description Modem not in use. Green steady light The router has activated a modem connection. Red steady light The modem connection was interrupted. 5.6.2 Display "Ethernet Interface active" Description Not connected Green steady light Ethernet interface active Red steady light Connected, but no Ethernet interface found.
  • Page 73: Connections / Interfaces

    Hardware Connections / Interfaces The connection for the power supply and four interfaces are to be found on the front side of the Internet Access Router: 5.7.1 Power supply The router can be powered either with +10 … 36 V DC or 8 … 24 V AC. The power consumption is approx.
  • Page 74: Modem Interface

    Hardware AC power supply Redundant DC power supply from safety battery Power supply connection The Internet Access Router must only be connected to the electrical supply system by an electrical expert. The power supply of the Internet Access Router must be provided CAUTION exclusively by a power pack which complies with DIN EN 60 742 (VDE 0551).
  • Page 75: Technical Data

    Technical Data Technical Data Type designation EIAR-10T/A with integrated Analog Modem EIAR-10T/I with integrated ISDN Modem Design Material of the housing Aluminium Colour RAL 5002 ultramarine, fine structure, dull Degree of protection - housing IP40 Degree of protection - terminals IP20...
  • Page 76: Harmonised Standards

    Standards and Certifications Standards and Certifications Harmonised standards EN 50081-1 Noise emission for residential, commercial and light- industrial environment EN 61000-6-2 Noise immunity for the industrial environment Certification to DIN EN ISO 9001 Contemporary Controls GmbH is certified to ISO 9001. Approbations CE marking EU Low-Voltage Directive...
  • Page 77: Symbols Used

    Symbols Used Symbols Used Connection for the functional earthing Mains transformer d.c. power supply source Battery (emergency power) 8-75...
  • Page 78 Notes 8-76...

Table of Contents