Page 4
Proroute GEM 2M 4G Router 3.2.1.4.3 Web Content Filter Configuration ......................70 3.2.1.5 MAC Control ..........................70 3.2.1.5.1 Configuration ............................71 3.2.1.5.2 MAC Control Rule List ..........................71 3.2.1.5.3 MAC Control Rule Configuration ......................72 ...
Page 5
Proroute GEM 2M 4G Router 3.2.3.4.1 L2TP Server Configuration ........................97 3.2.3.4.2 L2TP Server Status ........................... 98 3.2.3.4.3 User Account List ............................. 98 3.2.3.4.4 User Account Configuration ........................98 3.2.3.4.5 L2TP Client .............................. 99 ...
Page 6
Proroute GEM 2M 4G Router ............................136 YSTEM 3.4.1 System Related ........................137 3.4.1.1 Change Password ........................138 3.4.1.2 System Information ........................138 3.4.1.3 System Status ..........................139 3.4.1.4 System Tools ..........................140 3.4.2...
Page 7
Proroute GEM 2M 4G Router Copyright The contents of this publication may not be reproduced in any part or as a whole, stored, transcribed in an information retrieval system, translated into any language, or transmitted in any form or by any means, mechanical, magnetic, electronic, optical, photocopying, manual, or otherwise, without the prior written permission.
Proroute GEM-2M Cellular Gateway products are based on modular design. This GEM 2M series product is loaded with superb security features including VPN, firewall, NAT, port forwarding, DHCP server and many other powerful features for complex and demanding business and M2M (Machine-to-Machine) applications. The redundancy design in fallback 9-48 VDC power terminal, dual SIM cards and VRRP function makes the device as a back-up in power, network connection and data transmission without lost.
Proroute GEM 2M 4G Router 1.2 Hardware Installation 1.2.1 WARNING Do not use the product in high humidity or high temperatures. Only use the power adapter that comes with the package. Using a different voltage rating power adaptor is dangerous and may damage the product.
Proroute GEM 2M 4G Router 1.2.3 Hardware Configuration Front View Reset LED Indicators Button 3G / LTE Auto MDI/MDIX RJ45 Ports Antenna 1x FE LAN to connect local devices ※Reset Button The RESET button provides user with a quick and easy way to resort the default setting. Press the RESET button continuously for 6 seconds, and then release it. The device will restore to factory default settings.
Page 12
Proroute GEM 2M 4G Router Left View 3G / LTE Power Terminal Antenna Block Right View Serial SD DI/DO Port Card Terminal Block 12 GEM-2M series User Manual...
Proroute GEM 2M 4G Router 1.2.4 LED Indication LED Icon Indication LED Color Description Steady ON: Device is powered on by power Power Source 1 Green source 1 Power Source 2 Steady ON: Device is powered on by power...
Proroute GEM 2M 4G Router Chapter 2 Getting Started This chapter describes how to install and configure the hardware and how to use the setup wizard to configure the network with the web GUI of GEM-2M series. 2.1 Hardware Installation 2.1.1 Mount the Unit The GEM-2M series can be placed on a desktop, mounted on the wall or mounted on a DIN-rail.
Proroute GEM 2M 4G Router Step 1: Step 2: Step 3: Follow red arrow to Lift up SIM holder, Put back SIM holder, unlock SIM socket and insert SIM card and follow red arrow to lock SIM socket 2.1.3 Connecting Power The GEM-2M series can be powered by connecting one or two power sources to the terminal block. It supports dual 9 to 48VDC power inputs . Following picture is the power terminal block pin assignments and it is located at the right side of device.
Proroute GEM 2M 4G Router 2.1.4 Connecting DI/DO Devices There are a DI and a DO ports together with locating at the left side of device. Please refer to following specification to connect DI and DO devices. Mode Specification Trigger Voltage (high) Logic level 1: 5V~30V Digital Input Normal Voltage (low) Logic level 0: 0V~2.0V ...
Proroute GEM 2M 4G Router Pin1 Pin2 Pin3 Pin4 Pin5 Pin6 Pin7 Pin8 Pin9 RS-232 RS-485 DATA- DATA+ 2.1.6 Connecting to the Network or a Host The GEM-2M series provides one RJ45 port to connect 10/100Mbps Ethernet. It can auto detect the transmission speed on the network and configure itself automatically. Connect one Ethernet cable to the RJ45 port (LAN) of the device on the front panel and plug another end of the Ethernet cable into your computer’s network port.
Proroute GEM 2M 4G Router 2.2 Easy Setup by Configuring WEB UI You can browse web UI to configure the device. Browse to Activate the Setup Wizard Type in the IP Address (http://192.168.123.254) When you see the login page, type the password ‘admin’ and then click ‘Login’ button.
Proroute GEM 2M 4G Router 2.2.1.1 Configure with the Network Setup Wizard Step 1: Guideline The network setup wizard will guide you to finish some basic settings, including login password, time zone, WAN interface and Ethernet LAN interface. One “EXIT” button at the upper-right corner of each window is provided for you to quit the setup process.
Page 20
Proroute GEM 2M 4G Router Step 3: Time Zone Time Zone Configuration: It will detect your time zone automatically. If the result of auto detection is not correct, you can press “Detect Again” button or select manually. Press “Next” to continue. Step 4: WAN Interface...
Proroute GEM 2M 4G Router Step 5: Ethernet LAN Interface LAN Interface Configuration: Change the LAN IP address and subnet mask of this gateway for the Intranet. You can keep the default setting and go to next step. Press “Next” to continue. Step 6: Confirm and Apply Check the new settings again.
Page 22
Proroute GEM 2M 4G Router Step 1: Guideline The VPN setup wizard will guide you to finish profiles of IPSec, PPTP, L2TP and GRE VPN connection quickly. Press “Next” to start the wizard. Step 2: VPN Type Select type of VPN connection you want to create.
Page 23
Proroute GEM 2M 4G Router For Dynamic VPN, you don’t need to input network information of remote subnet and remote gateway. Press “Next” to continue. Step 3-2: PPTP If choosing PPTP, there are two options of mode can be chosen. Choose “Client” if you want this device to connect to another PPTP server.
Page 24
Proroute GEM 2M 4G Router If choosing PPTP Server, please choose options authentication protocol and key length of MPPE encryption. You also need to create a set of username and password for PPTP clients. In this wizard, you can only create one user account. If you want to create more user accounts, please go to [Advanced Network]-[VPN]-[PPTP] to add more users.
Proroute GEM 2M 4G Router If choosing L2TP Server, please choose options authentication protocol and key length of MPPE encryption. You also need to create a set of username and password for L2TP clients. In this wizard, you can only create one user account. If you want to create more user accounts, please go to [Advanced Network]-[VPN]-[L2TP] to add more users.
Proroute GEM 2M 4G Router LAN Client List, Firewall Status, VPN Status and System Management Status. 2.2.2.1 Network Status In Network Status page, you can review lots information of network status, including a connection diagram, WAN IPv4 status, WAN IPv6 status, LAN status, and 3G/4G modem status.
Proroute GEM 2M 4G Router LAN Interface Status Display IPv4 and IPv6 information of local network. Press “Edit” button if you want to change settings. 3G/4G Modem Status Display modem information, link status, signal strength, and network (carrier) name of 3G/4G connection. Internet Traffic Statistics Display number of transmitted packets and received packets of 3G/4G WAN interface.
Proroute GEM 2M 4G Router 2.2.2.3 Firewall Status In Firewall Status page, you can review lots information of filter status, including Packet Filters, URL Blocking, Web Content Filters, MAC Control, Application Filters, IPS and other options of firewall. Packet Filters This window displays all detected contents of firing activated packet filter rules. One "Edit" button in the Packet Filters caption can let you change its settings. Another "[+]" or "[‐]" button at the upper‐right corner can unfold or fold the detected contents. ...
Proroute GEM 2M 4G Router This window displays all filtered applications of firing activated application filter rules. One "Edit" button in the Application Filters caption can let you change its settings. Another "[+]" or "[‐]" button at the upper‐right corner can unfold or fold the filtered applications. This window displays all events of firing activated rules of IPS. One "Edit" button in the IPS caption can let you change its settings. Another "[+]" or "[‐]" button at the upper‐right corner can unfold or fold the intrusion events. ...
Proroute GEM 2M 4G Router caption can let you change its settings. L2TP Server Status Display the status of all activated accounts of L2TP server. One "Edit" button in the L2TP Server Status caption can let you change its settings. L2TP Client Status Display the status of all activated L2TP clients. One "Edit" button in the L2TP Client Status ...
Proroute GEM 2M 4G Router Chapter 3 Making Configurations Whenever you want to configure your network or this device, you can access the Configuration Menu by opening the web browser and typing in the IP Address of the device. The default IP Address is: 192.168.123.254. In the configuration section you may want to do Basic Network setup, Advanced Network setup, Applications setup or system-related setup and operations.
Proroute GEM 2M 4G Router You can see the first screen is located at [Status]-[Network Status] after you Note: logged in and the screen shows the Network Connection Status below. You can also check status of connected clients at LAN Client List page, and other advanced function status at Firewall Status page, VPN Status page and System Management Status page.
Proroute GEM 2M 4G Router 3.1.1 WAN Setup This device is equipped with one WAN Interface to support Internet connection. You can configure it to get proper connection setup. 3G/4G WAN: The gateway has one 3G/4G modem built-in, please plug in SIM card and follow UI setting to setup.
Proroute GEM 2M 4G Router 1. WAN-1: The operation mode of first interface is forced to “Always on” mode, and operates as the primary Internet connection. You can click on the respective “Edit” button and configure the rest items for this interface. Physical Interface: Select the WAN interface from the available list. For this gateway, there is only “3G/4G”...
Proroute GEM 2M 4G Router 3G/4G: If you have subscribed 3G/LTE data services from mobile operators. This gateway can support LTE/3G/2G depends on respective specifications. However, if your 3G data plan is not with a flat rate, it’s recommended to set Connection Control mode to Connect-on-demand or Manually.
Page 36
Proroute GEM 2M 4G Router Internet by using SIM-B card first if choosing “SIM-B First”. However, when “SIM-A Only” or “SIM-B Only” is used, that means the specified SIM slot of card is the ONLY one to be used for negotiation parameters between gateway device and mobile base station.
Page 37
Proroute GEM 2M 4G Router select country and service provider. If you choose “SIM-A First” or “SIM-A Only” for Preferred SIM Card, you need to input dial-up profile for SIM-A. Similarly, you need to input dial-up profile for SIM-B when you choose “SIM-B First” or “SIM-B Only” as your preferred one.
Page 38
Proroute GEM 2M 4G Router choose this scheme if for mission critical applications to ensure Internet connection is available all the time. If choosing “Dial-on-demand”, this gateway won’t start to establish Internet connection until local data is going to be sent to WAN side. During normal operation, this gateway will disconnect WAN connection if idle time reaches the value of "Maximum Idle Time".
Proroute GEM 2M 4G Router gateway will record this keep alive is failed. Latency Threshold: Set acceptance of response time. This gateway will record this keep-alive check is failed if the response time of replied packet is longer than this setting. Fail Threshold: Times of failed checking. This WAN connection will be recognized as broken if the times of continuous failed keep-alive checking equals to this value.
Proroute GEM 2M 4G Router LAN IP Address: The local IP address of this device. The computers on your network must use the LAN IP address of this device as their Default Gateway. You can change it if necessary. It’s also the IP address of web UI. If you change it, you need to type new IP address in the browser to see web UI.
Proroute GEM 2M 4G Router In Port-based VLAN, all client hosts belong to the same group by transferring data via some physical ports that are tagged with same VLAN ID in the device. The ports of a VLAN form an independent traffic domain in which the traffic generated by the nodes remains within the VLAN.
Page 42
Proroute GEM 2M 4G Router A port-based VLAN is a group of ports on an Ethernet of Wired Gateway that form a logical Ethernet segment. Following is an example. In SMB or a company, administrator schemes out 4 segments, Lobby, Lab & Servers, Office and VoIP &...
Page 43
Proroute GEM 2M 4G Router Above is the general case for 4 Ethernet LAN ports in the gateway. But the device has only one Ethernet LAN port and two different kinds of application for the Port-based VLAN tagging, NAT or Bridge. Tag-based VLAN Tagging for Location-free Departments Tag-based VLAN function can specify some groups with different VLAN tags for deploying department subnets in Intranet.
Page 44
Proroute GEM 2M 4G Router VLAN Group Access Control Administrator can specify the Internet access right for all VLAN groups. He also can configure which VLAN groups can communicate each other. VLAN Group Internet Access Administrator can specify members of one VLAN group to be able to access Internet or not.
Proroute GEM 2M 4G Router In Port-based tagging, administrator can specify member hosts of one VLAN group to be able to communicate with the ones of another VLAN group or not. This is a communication pair, and one VLAN group can join many communication pairs. But communication pair has not the transitive property.
Proroute GEM 2M 4G Router 1. Type: Select “NAT” or “Bridge” to identify if the packets are directly bridged to the WAN port or processed by NAT mechanism. 2. LAN VID: Specify a VLAN identifier for this port. The ports with the same VID are in the same VLAN group.
Proroute GEM 2M 4G Router By default, all the LAN ports belong to one VLAN group, and this VLAN ID is forced to denoted as “None”. It is a special tag-based VLAN for device to operated, there is no tag required to be carried in the packets for this default VLAN group.
Proroute GEM 2M 4G Router intended to succeed IPv4, which is the protocol currently used to direct almost all Internet traffic. IPv6 also implements additional features not present in IPv4. It simplifies aspects of address assignment (stateless address auto-configuration), network renumbering and router announcements when changing Internet connectivity providers.
Proroute GEM 2M 4G Router manually for Primary DNS address and secondary DNS address. 2. Primary / Secondary DNS: Please enter IPv6 primary DNS address and secondary DNS address. 3. MLD Snooping: MLD snooping, IPv6 multicast data is selectively forwarded to a list of ports that want to receive the data, instead of being flooded to all ports in a VLAN.
Page 50
Proroute GEM 2M 4G Router When “6 in 4” is selected for the WAN Connection Type, you need to do the following settings: 6in4 WAN Type Configuration 1. Remote / Local IPv4 and IPv6 Address: you may add remote / local IPv4 address and local IPv6 address, then set DNS address manually for Primary DNS address and secondary DNS address.
Proroute GEM 2M 4G Router 1. Auto-configuration: Disable or enable this auto configuration setting. 2. Auto-configuration Type: You may set stateless or stateful (Dynamic IPv6). 3. Router Advertisement Lifetime: You can set the time for the period that the router send (broadcast) its router advertisement. Each router periodically multicasts a Router Advertisement from each of its multicast interfaces, announcing the IP address of that interface.
Proroute GEM 2M 4G Router example, if you set a mail server at LAN side, your local devices can access this mail server through gateway’s WAN IP address. You don’t need to change IP address of mail server no matter you are at local side or go out. This is useful when you run a server inside your network.
Proroute GEM 2M 4G Router 3.1.4.2.2 Virtual Computer Virtual Computer enables you to use the original NAT feature, and allows you to setup the one-to-one mapping of multiple global IP address and local IP address. Press “Add” button to add new rule for Virtual Computer.
Proroute GEM 2M 4G Router Press “Add” button to add new rule for Special AP. This device provides some predefined settings. Select your application item, and all related settings will be filled up automatically. Trigger Port: The outbound port number issued by the application.
Proroute GEM 2M 4G Router you need this feature in the environment, please enable it. NOTE: This feature should be used only when needed. 3.1.5 Routing Setup If you have more than one router and subnet, you will need to enable routing function to allow packets to find proper routing path and allow different subnets to communicate with each other.
Proroute GEM 2M 4G Router 1. Destination IP: Enter the subnet network of routed destination. 2. Subnet Mask: Input your subnet mask. Subnet mask defines the range of IP address in destination network. 3. Gateway: The IP address of gateway that you want to route for this destination subnet network.
Proroute GEM 2M 4G Router 3.1.5.2.1 RIP 1. RIP: Routing Information Protocol (RIP) will exchange information about destinations for computing routes throughout the network. Please select RIPv2 only if you have different subnets in your network. Otherwise, please select RIPv1 if you need this protocol.
Proroute GEM 2M 4G Router You can enable the OSPF routing function by click on the “Enable” button for OSPF item. There are 8 area subnets can be defined in the OSPF network and enable them individually. When you finished setting, click on “Save” to store your settings. Above settings are just for examples.
Proroute GEM 2M 4G Router 3.1.5.3 Routing Information A routing table, or routing information base (RIB), is a data table stored in a router or a networked computer that lists the routes to particular network destinations, and in some cases, metrics (distances) associated with those routes. The routing table contains information about the topology of the network immediately around it.
Proroute GEM 2M 4G Router DDNS: Check the Enable box if you would like to activate this function. Provider: The DDNS provider supports service for you to bind your IP (even private IP) with a certain Domain name. You could choose your favorite provider.
Proroute GEM 2M 4G Router MAC address and IP address of local client hosts as following diagram. 3.1.6.2.2 DHCP Server Configuration 1. DHCP Server: Choose DHCP Server to Enable. If you enable the DHCP Server function, this gateway will assign IP address to LAN computers or devices through DHCP protocol.
Proroute GEM 2M 4G Router this gateway, so there are maximum 253 clients allowed in LAN network. Hereafter are the available options for subnet mask. 4. IP Pool Starting / Ending Address: Whenever there is a request, the DHCP server will automatically allocate an unused IP address from the IP address pool to the requesting computer.
Proroute GEM 2M 4G Router For internal servers, you can use this feature to ensure each of them receives same IP address all the time. 3.2 Advanced Network This device also supports many advanced network features, such as Firewall, QoS & Bandwidth Management, VPN Security, Redundancy, System Management, Certificate and Communication Bus.
Proroute GEM 2M 4G Router 3.2.1.1 Configuration One Firewall Enable check box lets you activate some firewall functions that you want. 3.2.1.2 Packet Filters Packet Filters function can let you define both outbound filter and inbound filter rules by specifying the source IP and destination IP in a rule. It enables you to control what packets are allowed or blocked to pass the router.
Proroute GEM 2M 4G Router allow the packets to pass the gateway, which match the active filter rules. Allow all to pass except those match the specified rules. (Black List) Deny all to pass except those match the specified rules. (White List) Besides, you also can enable the log alerting so that system will record packet blocking events when filter rules are fired.
Page 66
Proroute GEM 2M 4G Router 1. Rule Name: The name of packet filter rule. 2. From Interface: Any interface or someone LAN interface or someone WAN interface. 3. To Interface: Any interface or someone LAN interface or someone WAN interface. 4. Source IP: Specify the Source IP address of packets that want to be filtered out in the packet filter rule.
Proroute GEM 2M 4G Router Afterwards, click on “Save” to store your settings or click “Undo” to give up the changes. 3.2.1.3 URL Blocking URL Blocking will block the webs containing pre-defined key words. This feature can filter both domain input suffix (like .com or .org, etc) and a keyword “bct” or “mpe”.
Proroute GEM 2M 4G Router command button. But also you can modify some existed URL blocking rules by clicking corresponding “Edit” command buttons at the end of each blocking rule in the URL Blocking Rule List. Besides, unnecessary rules can be removed by checking the “Select”...
Proroute GEM 2M 4G Router Afterwards, click on “Save” to store your settings or click “Undo” to give up the changes. 3.2.1.4 Web Content Filters Web Content Filters can block HTML requests with the specific extension file name, like ".exe", ".bat" (applications), "mpeg” (video), and block HTML requests with some script types, like Java Applet, Java Scripts, cookies and Active X.
Proroute GEM 2M 4G Router rule in the Web Content Filter List. Besides, unnecessary rules can be removed by checking the “Select” box for those rules and then clicking on the “Delete” command button at the Web Content Filter List caption. 3.2.1.4.3 Web Content Filter Configuration It supports the adding of one new rule or the editing of one existed rule.
Proroute GEM 2M 4G Router 3.2.1.5.1 Configuration 1. MAC Control: Check the “Enable” box to activate the MAC Control function. All of the settings in this page will take effect only when “Enable” is checked. 2. Black List / White List: Select one of the two filtering policies for the defined rules.
Proroute GEM 2M 4G Router 3.2.1.5.3 MAC Control Rule Configuration It supports the adding of one new rule or the editing of one existed rule. There are some parameters need to be specified in one MAC Control rule. They are Rule Name, MAC Address, Time Schedule and finally, the rule enable.
Proroute GEM 2M 4G Router 3.2.1.6.1 Configuration 1. Application Filters: Check the “Enable” box to activate the Application Filters function. All of the settings in this page will take effect only when “Enable” is checked. 2. Log Alert: Enable the log alerting so that system will record Application Filter events when filtering rules are fired.
Proroute GEM 2M 4G Router 3.2.1.8 Options 1. Stealth Mode: Enable this feature, this device will not respond to port scans from the WAN so that makes it less susceptible to discovery and attacks on the Internet. 2. SPI: When this feature is enabled, the router will record the outgoing packet information pass through the router like IP address, port address, ACK, SEQ number and so on.
It is indeed required that an access gateway satisfies the requirements of latency-critical applications, minimum access right guarantee, fair bandwidth usage for same subscribed condition and flexible bandwidth management. Proroute Security Gateway provides a Rule-based QoS to carry out the requirements.
Proroute GEM 2M 4G Router 3.2.2.1 Configuration QoS on Multiple WAN Interfaces QoS on all WAN interfaces satisfies the requirements of latency-critical applications, minimum access right guarantee, fair bandwidth usage for same subscribed condition and flexible bandwidth management in a more flexible approach.
Proroute GEM 2M 4G Router Before QoS & BWM function can work correctly, this gateway needs to define the resource for QoS & BWM function to utilize. They include the maximum number of priority queues that the device supports and some kinds of resources for each WAN interface.
Proroute GEM 2M 4G Router Well-known services include FTP(21), SSH(TCP:22), Telnet(23), SMTP(25), DNS(53), TFTP(UDP:69), HTTP(TCP:80), POP3(110), Auth(113), SFTP(TCP:115), SNMP&Traps(UDP:161-162), LDAP(TCP:389), HTTPS(TCP:443), SMTPs(TCP:465), ISAKMP(500), RTSP(TCP:554), POP3s(TCP:995), NetMeeting(1720), L2TP(UDP:1701) and PPTP(TCP:1723). Available Control Functions There are 4 resources can be applied in a QoS rule: bandwidth, connection sessions, priority queues and DiffServ Code Point (DSCP).
Proroute GEM 2M 4G Router rules and then clicking on the “Delete” command button at the QoS Rule List caption. One “Clear” command button can let you clear all rules and “Restart” command button can let you restart the operation of all QoS rules.
Page 80
Proroute GEM 2M 4G Router By default, it is “All”. It defines “what” kinds of service packets need to be managed. When “DSCP” is selected, another “DiffServ CodePoint” value must be specified. DSCP means DiffServ Code Point, as known as advanced TOS. You can choose this option if your local service gateway supports DSCP tags. The DSCP categories that this gateway can detect are as below.
Page 81
Proroute GEM 2M 4G Router 4. Resource: There are 4 resources can be chosen to control in the QoS rule. They are “Bandwidth”, “Connection Sessions”, “Priority Queues” and “DiffServ Code Points”. 5. Control Function: It depends on the chosen resource. For “Bandwidth” resource, the control function is “Set MINR & MAXR”. For “Connection Sessions”, the control function is “Set Session Limitation”.
Page 82
Proroute GEM 2M 4G Router 9. Enable: Check the box if you want to enable the rule. Each rule can be enabled or disabled individually. Afterwards, click on “Save” to store your settings or click “Undo” to give up the changes. Example #1 for adding a “DSCP” type QoS rule ...
Proroute GEM 2M 4G Router Service: Select “ALL”. Resource: Select “Connection Sessions”. Control Function: Select “Set Session Limitation”, and set session number to 20000. QoS Direction: Select “Outbound” for outbound traffic only. It is for the client devices under the gateway to establish multiple sessions with servers in the Internet.
Proroute GEM 2M 4G Router 3.2.3.2 IPSec Internet Protocol Security (IPSec) is a protocol suite for securing Internet Protocol (IP) communications by authenticating and encrypting each IP packet of a communication session. IPSec includes protocols for establishing mutual authentication between agents at the beginning of the session and negotiation of cryptographic keys to be used during the session.
Proroute GEM 2M 4G Router is. It must be noted that the remote peer has to initiate the tunnel establishing process first in this application scenario. There is one more advanced IPSec VPN application: Site to Site – Support Full Tunnel Application When Full Tunnel function of remote Business Security Gateway is enabled, all data traffic from remote clients behind remote Business Security Gateway will goes over the VPN tunnel.
Proroute GEM 2M 4G Router IPSec: You could trigger the function of IPSec VPN if you check “Enable” box. NetBIOS over IPSec: If you would like two Intranets behind two Business Security Gateways to receive the NetBIOS packets from Network Neighborhood, you have to check “Enable” box.
Proroute GEM 2M 4G Router Tunnel Name: Enter the name of tunnel. Interface: Decide the WAN Interface to establish the tunnel. Tunnel Scenario: Support “Site to Site”, “Site to Host”, “Host to Site”, “Host to Host” and “Dynamic VPN”. Select one from them. Operation Mode: Default is “Always on” and other options depend on product models.
Proroute GEM 2M 4G Router There are 5 entries for Local Subnet. Local Netmask: The local netmask and associated local subnet can define a subnet domain for the local devices connected via the VPN tunnel. There are 5 entries for Local Netmask. Full Tunnel: All traffic from Intranet of Business Security Gateway goes over the IPSec VPN tunnel if these packets don’t match the Remote Subnet of other...
Proroute GEM 2M 4G Router Negotiation Mode: Choose Main Mode or Aggressive Mode: Main Mode provides identity protection by authenticating peer identities when pre-shared keys are used. The IKE SA’s are used to protect the security negotiations. Aggressive mode will accelerate the establishing speed of VPN tunnel, but the device will suffer from less security in the meanwhile.
Proroute GEM 2M 4G Router There are 4 IKE proposals can be defined by you and used in IKE phase of negotiation between two VPN peers. Encryption: There are six algorithms can be selected: DES, 3DES, AES-auto, AES-128, AES-192, and AES-256. Authentication: There are five algorithms can be selected: None, MD5, SHA1, SHA2-256 and SHA2-512.
Proroute GEM 2M 4G Router Group 2 (MODP1024), Group 5 (MODP1536) and Group14 ~ 18. Once the PFS Group is selected in one IPSec proposal, the one in other 3 IPSec proposals uses the same choice. Enable: Check this box to enable the IKE Proposal during tunnel establishing.
Proroute GEM 2M 4G Router implement security functionality. However, the most common PPTP implementation shipping with the Microsoft Windows product families implements various levels of authentication and encryption natively as standard features of the Windows PPTP stack. The intended use of this protocol is to provide security levels and remote access levels comparable with typical VPN products.
Proroute GEM 2M 4G Router PPTP: Check the “Enable” box to activate PPTP client and server functions. Client/Server: Choose Server or Client to configure corresponding role of PPTP VPN tunnels for the Business Security Gateway beneath the choosing screen 3.2.3.3.2 PPTP Server Configuration The Business Security Gateway can behave as a PPTP server, and it allows remote hosts to access LAN servers behind the PPTP server.
Proroute GEM 2M 4G Router The user name and connection information for each connected PPTP client to the PPTP server of the Business Security Gateway will be shown in this table. Refresh: To refresh the PPTP Server Status each 2 seconds by clicking on the “Refresh”...
Proroute GEM 2M 4G Router PPTP Client: Enable or disable PPTP client function. 3.2.3.3.7 PPTP Client List & Status You can add new up to 22 different PPTP client tunnels by clicking on the “Add” button, and modify each tunnel configuration by clicking on the corresponding “Edit”...
Proroute GEM 2M 4G Router Peer IP/Domain: The IP address or Domain name of remote PPTP server. User Name: The user name which can be validated by remote PPTP server. Password: The password which can be validated by remote PPTP server. Default Gateway/Peer Subnet: You can choose “Default Gateway” option or “Peer Subnet”...
Proroute GEM 2M 4G Router The Business Security Gateway can behave as a L2TP server and a L2TP client at the same time. L2TP: Check the “Enable” box to activate L2TP client and server functions. Client/Server: Choose Server or Client to configure corresponding role of L2TP VPN tunnels for the Business Security Gateway beneath the choosing screen.
Proroute GEM 2M 4G Router 7. MPPE Encryption: Check the “Enable” box to activate MPPE encryption. Please note that MPPE needs to work with MS-CHAP or MS-CHAP v2 authentication method. In the meantime, you also can choose encryption length of MPPE encryption, 40 bits, 56 bits or 128 bits.
Proroute GEM 2M 4G Router 3.2.3.4.5 L2TP Client The Business Security Gateway also can behave as a L2TP client except L2TP server, and L2TP client tries to establish a L2TP tunnel to remote L2TP server. All client hosts in the Intranet of Business Security Gateway can access LAN servers behind the L2TP server.
Page 100
Proroute GEM 2M 4G Router L2TP Client Name: The name of this tunnel. Operation Mode: Default is “Always on” and other options depend on product models. Peer IP/Domain: The IP address or Domain name of remote L2TP server. User Name: The user name which can be validated by remote L2TP server.
Proroute GEM 2M 4G Router Business Security Gateway can go to access Internet via remote PPTP server. By default, it is enabled. However, if you want the remote PPTP Server to monitor the Intranet of local Business Security Gateway, the option can’t be enabled.
Proroute GEM 2M 4G Router GRE Tunnel: Check the “Enable” box to activate the GRE tunnel function. 3.2.3.5.3 GRE Tunnel Definitions Add: You can add one new GRE tunnel by clicking on the “Add” button. Delete: Delete selected tunnels by checking the “Select” box at the end of each tunnel list and then clicking on the “Delete”...
Proroute GEM 2M 4G Router “Peer Subnet” option here. When “Default Gateway” is chosen, all traffic from Intranet of Business Security Gateway goes over this GRE tunnel if these packets don’t match the Peer Subnet of other GRE tunnels. There is only one GRE tunnel to own the “Default Gateway” property. However, when “Peer Subnet”...
Proroute GEM 2M 4G Router 1. VRRP: Enable or disable the VRRP function. 2. Virtual Server ID: Means Group ID. Specify the ID number of the virtual server. Its value ranges from 1 to 255. 3. Priority of Virtual Server: Specify the priority to use in VRRP negotiations. Valid values are from 1 to 254, and a larger value has higher priority.
Proroute GEM 2M 4G Router TR-069 is a customized feature for ISP; it is not recommend that you change the configuration for this. If you have any problem in using this feature for device management, please contact with your ISP or the ACS provider for help. At the right upper corner of TR-069 Setting screen, one “[Help]”...
Page 106
SMIv1 and SMIv2 SNMPv2-TM and SNMPv2-MIB AMIB (Proroute Private MIB) 1. SNMP Enable: You can check “Local (LAN)”, “Remote (WAN)” or both to enable SNMP function. If “Local (LAN)” is checked, this device will respond to the request from LAN.
Proroute GEM 2M 4G Router 1. User Name: Input the name for a user. 2. Password & Authentication: Input the password for a user and choose the hashing algorithm for authentication. However, they will not be necessary when you choose the privacy mode to be "noAuthPriv" for the user account.
Proroute GEM 2M 4G Router 3.2.5.4 UPnP UPnP Internet Gateway Device (IGD) Standardized Device Control Protocol is a NAT port mapping protocol and is supported by some NAT routers. It is a common communication protocol of automatically configuring port forwarding. Applications using peer-to-peer networks, multiplayer gaming, and remote assistance programs need a way to communicate through home and business gateways.
Proroute GEM 2M 4G Router In a typical public-key infrastructure (PKI) scheme, the signer is a certificate authority (CA), usually a company such as VeriSign which charges customers to issue certificates for them. In a web of trust scheme, the signer is either the key's owner (a self-signed certificate) or other users ("endorsements") whom the person examining the certificate...
Page 110
Proroute GEM 2M 4G Router Name: Enter the name of root CA. Key: Key Type is RSA. Key length: The size of the private key in bits. There are five key length can be selected: 512-bits, 765-bits, 1024-bits, 1536-bits, 2048-bits. Subject Name: The Subject Name include seven information. Country(C): The two character country code of the certificate authority is located.
Proroute GEM 2M 4G Router 3.2.6.1.2 Local Certificate List This feature can show the list of all certificates which contain information identifying the applicant. Each certificate involves field of the certificate name, subject, issuer and valid to. You can generate one certificate by clicking on the "Generate" button.
Proroute GEM 2M 4G Router Certainly, you also can delete one local certificate by checking corresponding Select box and clicking on the "Delete" button. You can view its PEM codes by checking the "View" button. You can download the local certificate file by clicking on the "Download" button.
Proroute GEM 2M 4G Router 3.2.6.2.1 Trusted CA Certificate List The device can let you import the certificate of trusted external CA by clicking on the "Import" button. There are two approaches to import it. One is from a file and another is copy-paste the PEM codes in Web UI, and then click on the "Apply"...
Proroute GEM 2M 4G Router You can view its PEM codes by checking the "View" button. You can download the trusted CA file by clicking on the "Download" button. 3.2.6.2.2 Trusted Client Certificate List This feature can show the list of all certificates information. Each Certificate involve field of certificate name, subject, issuer and valid to.
Page 115
Proroute GEM 2M 4G Router There are two approaches to import it. One is from a file and another is copy-paste the PEM codes in Web UI, and then click on the "Apply" button. You also can delete one trusted client certificate by checking corresponding Select box and clicking on the "Delete"...
Proroute GEM 2M 4G Router 3.2.6.3 Issue Certificates When you have a Certificate Signing Request (CSR) that needs to be certificated by the root CA of the device, you can issue the request here and let Root CA sign it. There are two approaches to issue it. One is from a file and another is copy-paste the CSR codes in Web UI, and then click on the "Sign"...
Proroute GEM 2M 4G Router 3.2.7 Communication Bus The GEM-2M series provides the RJ12 female port for various serial communication use through connecting the RS-232 or RS-485 serial device to an IP-based Ethernet LAN. These communication protocols make user access serial devices anywhere over a local LAN or the Internet easily.
Page 118
Proroute GEM 2M 4G Router connected to serial port on GEMN-2M gateway. Therefore, users can access, control, and manage serial devices through Internet (fixed line, or cellular network) no matter where they are. There are four modes for virtual com connection: TCP Client, TCP Server, UDP, and RFC2217.
Page 119
Proroute GEM 2M 4G Router 3. Connection Idle Timeout: Input the time period of idle timeout. The TCP connection will be terminated if it idles longer than this timeout setting. This option is only available when connection control is set to “ON-Demand”. 4. Alive Check Timeout: Input the time period of alive check timeout. The TCP connection will be terminated if it doesn’t receive response of alive-check longer...
Page 120
Proroute GEM 2M 4G Router 3. Trust Type: You can choose “Allow All” to allow all TCP clients to connect, or choose “Specific IP” to limit to certain TCP clients. 4. Max Connection: Set the maximum number of concurrent TCP connections. Up to 4 TCP connections can be established at the same time.
Page 121
Proroute GEM 2M 4G Router 1. Operation Mode: Choose UDP. 2. Listen Port: Indicate the listening port of UDP connection. 3. Host: Press “Edit” button, and enter IP address range of remote UDP hosts. 4. Remote Port: Indicate the UDP port of peer UDP hosts.
Page 122
Proroute GEM 2M 4G Router 1. Operation Mode: Choose RFC-2217. 2. Listen Port: Indicate the listening port of RFC-2217 connection. 3. Trust Type: You can choose “Allow All” to allow all hosts to connect, or choose “Specific IP” to limit to certain hosts. 4. Connection Idle Timeout: Input the time period of idle timeout. The connection will be terminated if it idles longer than this timeout setting.
Page 123
Proroute GEM 2M 4G Router 123 GEM-2M series User Manual...
Page 124
Proroute GEM 2M 4G Router TCP Test Tools can be configured the following steps: IP Address: setting the GEM-2M Gateway address (ex. 192.168.123.254) Port: should be same as the listen port of GEM-2M Click the “Connect” button The Connecting Status should be shown as “Connected”...
Page 125
Proroute GEM 2M 4G Router In the Edit/Send Data, you can try to text some information, and then click the “Send” button. Then, you can see the same information in the PuTTY. 125 GEM-2M series User Manual...
Proroute GEM 2M 4G Router 3.2.7.3 Modbus Modbus is one of the most popular automation protocols in the world, supporting traditional RS-232/422/485 devices and recently developed Ethernet devices. Many industrial devices, such as PLCs, DCSs, HMIs, instruments, and meters, use Modbus as the communication standard. It is used to establish master-slave/client-server communication between intelligent devices.
Page 127
Proroute GEM 2M 4G Router 1. Operation Mode: the definition of Modbus Gateway is an adapter application enables conversions between Serial and Network Modbus protocols. 2. Serial Protocol: defines the Modbus protocol used on the serial communication. 3. Listen Port: defines the TCP or UDP port that Masters can make connections to.
Proroute GEM 2M 4G Router Function Code can be proceeding in high priority.. 3.3 Applications In this section you can finish the Mobile Application settings. This device is equipped with a 3G/4G module as WAN interface, and it also provide the SMS, USSD, Network Scan and SMS-based Remote Management.
Page 129
Proroute GEM 2M 4G Router gateway. 1. Physical Interface: Indicate which 3G/LTE modem is used for SMS feature. 2. SMS: Indicate which SIM card is used for SMS feature. 3. SMS Storage: Select storage for SMS message. This gateway only supports “SIM Card Only” for SMS storage.
Proroute GEM 2M 4G Router 2. Received SMS: Indicate number of total received SMS message. 3. Remaining SMS: Indicate number of new message can be received because of SMS storage limit. Create New SMS Message You can create a new SMS message on this page. After finishing the content of message, and filling with phone number of receiver(s), you can press the “Send”...
Page 131
Proroute GEM 2M 4G Router USSD Configuration You can compose a USSD message, and sends it to the service provider, where it is received by a computer dedicated to USSD. The answer from this computer is sent back to this device, but it is usually with a very basic presentation.
Proroute GEM 2M 4G Router Send USSD Command You can select USSD command from existed profile or type command manually. Then press “Send” button to send out USSD command. 3.3.1.3 Network Scan This part is for 3G/LTE cellular network scan. Usually, this part would be done automatically.
Page 133
Proroute GEM 2M 4G Router Management Settings 1. Remote Management via SMS: Check this to enable this function. 2. Delete SMS for Remote Management: This device will delete received SMS message that is for remote management purpose if enabling this option. This option can prevent storage space of SIM card from being occupied continuously.
Page 134
Proroute GEM 2M 4G Router status. For 3G/LTE WAN, router will send back WAN IP address, network name, network type, and connection time via SMS. For Ethernet WAN, router will send back WAN IP address and connection time via SMS. The content would be similar to following format: WAN IP: [xxx.xx.xxx.xx]...
Proroute GEM 2M 4G Router 1. Access Control: Users can decide which phone number can send commands to this gateway or receive notifications when enable this option. 2. Phone 1~5: For security concern, this gateway won’t deal with the command if that phone number is not in the list even the security key is correct. The phone number must be with the international prefix (i.e.
Proroute GEM 2M 4G Router Then, you can define the handler behavior for None / DO / SMS / Syslog / SNMP Trap / Email Alert / Reboot / Modbus Handler. Some handler categories depend on product models. As for the Time schedule, it is to allow Event/ Handler to active by the Time Schedule Rule.
Proroute GEM 2M 4G Router time schedule object can be defined in the [System]-[Scheduling] section. About External Servers, you can define some external server objects here to be applied at various applications in the device system. Whatever one application needs an external server, like a RADIUS server, the external server object can be defined in the [System]-[External Servers] section.
Proroute GEM 2M 4G Router 3.4.1.1 Change Password You can change the System Password here. We strongly recommend you to change the system password for security reason. Click on “Save” to store your settings or click “Undo” to give up the changes. 1. Old Password: Input the old password of administrator.
Proroute GEM 2M 4G Router 3.4.1.3 System Status You can view the System Logs in Web UI. You also can send the logs to specific email accounts periodically or instantly by clicking on the “Email Now” command button. 1. Web Log: You can select the log types to be collected in the web log area. There are “System”, “Attacks”, “Drop”, and “Debug”...
Proroute GEM 2M 4G Router 3.4.1.4 System Tools The device supports many system tools, including system time configuration, FW upgrading, system rebooting, system resetting to default, waking on LAN and configuration settings backup. 1. System Time: There are three approaches to setup the system time. Before the process, some basic information must be filled by clicking on the “Configure”...
Page 141
Proroute GEM 2M 4G Router The last way is “Sync with my PC”. Click on the button to let system synchronizes its date and time to the ones of the configuration PC. 2. FW Upgrade: If new firmware is available, you can upgrade router firmware through the WEB GUI here.
Proroute GEM 2M 4G Router system will try to trace the specified device to test whether it is alive after clicking on the “Traceroute” button. A test result window will appear beneath it. There is a “Close” command button there can let the test result windows disappear.
Proroute GEM 2M 4G Router 1. Enable: Enable or disable the scheduling function. 2. Add New Rule: To create a schedule rule, click the “Add New” button or the “Add New Rule” button at the bottom. When the next dialog popped out you can edit the Name of Rule, Policy, and set the schedule time (Week day, Start Time, and End Time).
Proroute GEM 2M 4G Router 3.4.3.1 Grouping Configuration 1. Grouping: Check the “Enable” box to activate the grouping function. 3.4.3.2 Host Grouping 3.4.3.2.1 Host Group List Host Group List can show the list of all host groups and their member lists and bound services in this window. You can add one new grouping rule by clicking on the “Add”...
Proroute GEM 2M 4G Router 3.4.3.2.2 Host Group Configuration 1. Group Name: Define the name of group. 2. Member List: Show the list of members that have joined the group. A delete button ‘’ is behind each member and can be used to remove the member from the group.
Proroute GEM 2M 4G Router 1. Group Name: Define the name of group. 2. Member List: Show the list of members that have joined the group. A delete button is behind each member and can be used to remove the member from the group.
Proroute GEM 2M 4G Router 1. Group Name: Define the name of group. 2. Member List: Show the list of members that have joined the group. A delete button is behind each member and can be used to remove the member from the group.
Proroute GEM 2M 4G Router 3.4.4.1 External Server List External Server List can show the list of all defined external server objects and their attributes in this window. You can add one new external server object by clicking on the “Add” command button. But also you can modify some existed external server objects by clicking corresponding “Edit”...
Proroute GEM 2M 4G Router 2. Server IP/FQDN: Specify the IP address or domain name of external server. 3. Server Port: Specify the service port of external server. 4. Server Type: Select one server type from the option list of “Email Server”, “Syslog Server”, “RADIUS Server”, “Active Directory Server”, “LDAP Server” and “UAM Server”.
Proroute GEM 2M 4G Router Appendix A. Licensing Information This product includes copyrighted third-party software licensed under the terms of the GNU General Public License. Please refer to the GNU General Public License below to check the detailed terms of this license. Availability of source code Please visit our web site or contact us to obtain more information.
Page 151
Proroute GEM 2M 4G Router GNU GENERAL PUBLIC LICENSE Version 2, June 1991 Copyright (C) 1989, 1991 Free Software Foundation, Inc. 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed.
Page 152
Proroute GEM 2M 4G Router the Program). Whether that is true depends on what the Program does. 1. You may copy and distribute verbatim copies of the Program's source code as you receive it, in any medium, provided that you conspicuously and appropriately publish on each copy an appropriate copyright notice and disclaimer of warranty;...
Page 153
Proroute GEM 2M 4G Router If distribution of executable or object code is made by offering access to copy from a designated place, then offering equivalent access to copy the source code from the same place counts as distribution of the source code, even though third parties are not compelled to copy the source along with the object code.
Page 154
Proroute GEM 2M 4G Router Foundation, write to the Free Software Foundation; we sometimes make exceptions for this. Our decision will be guided by the two goals of preserving the free status of all derivatives of our free software and of promoting the sharing and reuse of software generally.
Need help?
Do you have a question about the GEM 2M and is the answer not in the manual?
Questions and answers