background image

 

 

32  

NTC-8000 – M2M Multi-Port Network Gateway 

 

UM-00006 v1.1 

www.netcommwireless.com 

VPN 

A Virtual Private Network (VPN) is a tunnel providing a private link between two networks or devices over a public network. Data to 
be sent via a VPN tunnel needs to be encapsulated and as such is generally not visible to public networks. 
The advantages of a VPN connection include: 

 

Data Protection 

 

Access Control 

 

Data Origin Authentication 

 

Data Integrity 

 
The following pages detail how to configure a VPN connection using IPsec, OpenVPN, PPTP-Client and GRE protocols. 
 

IPSec 

IPSec operates on Layer 3 of the OSI model and as such can protect higher layer protocols. IPSec is used for both Site to Site VPN 
and Remote Access VPN. The NTC-8000-01 M2M Multi-Port Network Gateway supports IPsec end points and can be configured 
with Site to Site VPN tunnels with third party VPN routers. 
 
How to configure an IPSec VPN connection 
 
From the menu at the top of the screen, click Internet Settings then VPN and IPSec. A list of configured IPSec VPN connections is 
displayed. 
 

 

Figure 28 - IPSec VPN List 

 
Click the Add button to begin configuring an IPSec VPN connection. 
 

 

 

Summary of Contents for NTC-8000-01

Page 1: ...NTC 8000 User Guide NTC 8000 01 M2M Multi Port Network Gateway...

Page 2: ...n to a recycling centre and processed separately from domestic waste The cardboard box the plastic contained in the packaging and the parts that make up this device can be recycled in accordance with...

Page 3: ...10 Restoring factory default settings 11 Resetting to factory default condition 11 Installation and Configuration of the NTC 8000 01 12 Connecting via an Ethernet cable 12 Accessing the Web based User...

Page 4: ...based networking and have an understanding of wireless technologies Prerequisites Before continuing with the installation of your NTC 8000 01 please confirm that you meet the minimum system requiremen...

Page 5: ...tents The NTC 8000 01 series package consists of 1 x M2M Multi Port Network Gateway 2 x 3G antennas 2 x WiFi antennas 1 x 1 5m yellow Ethernet cable 8P8C 1 x Power and ignition cable 1 x WiFi Security...

Page 6: ...al strength LEDs will stay off ITEM ICON DEFINITION Power Indicates the gateway is powered correctly WLAN Indicates the ON OFF status of the wireless WLAN radio Mobile Broadband Indicates when Interne...

Page 7: ...mount DIMENSIONS WITHOUT MOUNTING BRACKET Length 187 mm Depth 122 mm Height 39 5 mm Weight 550 g Table 3 Device Dimensions DIMENSIONS WITH MOUNTING BRACKET Length 193 7 mm Depth 122 mm Height 57 9 mm...

Page 8: ...for the reverse polarity SMA female WiFi antennas 3 Ethernet Ports 8 x 10 100 Base TX Ethernet RJ 45 ports 4 Reset Press the reset button once to reboot the gateway Press and hold the reset button fo...

Page 9: ...rect wiring of the 4 way mini fit connector The diagram below illustrates the correct wiring of the 4 way mini fit connector Figure 3 Correct wiring of the 4 way mini fit connector PIN NUMBER WIRE 1 P...

Page 10: ...agement Default Settings WIFI DOES NOT APPLY IN CLIENT MODE SSID Remote AP Name Security WPA2 PSK Security Key a1b2c3d4e5 Table 8 WiFi Default Settings WEB INTERFACE ACCESS Username admin or root Pass...

Page 11: ...default settings on your NTC 8000 01 Using the web based user interface To restore your NTC 8000C to its factory default settings please follow these steps 1 Log in to the gateway s web interface as...

Page 12: ...way s software Device Configuration Backup the option of saving the gateway s current settings useful for configuring multiple NTC 8000 01 gateways Upload Uploading previously saved settings to the ga...

Page 13: ...r assigned to the NTC 8000 01 Mobile Broadband MBB The current connection profile Interface status APN local and remote addresses of the WWAN connection WLAN The current wireless network clients or wi...

Page 14: ...tatus Page PPTP Details ITEM DEFINITION No The number of the PPTP connection Profile Name The user created Profile name of the PPTP connection Remote Server Address The PPTP Remote Gateway Address P t...

Page 15: ...C 8000 M2M Multi Port Network Gateway 15 Advanced Status To view further information regarding the phone module on board the NTC 8000 01 and the mobile broadband configuration press the Advanced Statu...

Page 16: ...l Quality Ec Io A measurement of the portion of the received signal that is usable This is basically the signal strength minus the signal noise level Received Signal Code Power RSCP The power level of...

Page 17: ...field enter the APN Access Point Name 4 For the Mobile Broadband Connection option select Enable 5 In the Username and Password fields enter the username and password if required 6 Use the Authentica...

Page 18: ...atus menu item at the top of the page to return to the Status page In the Mobile Broadband section the connected profile is displayed with the Status field showing as Up and the IP Address field shows...

Page 19: ...Destination and Second Address to verify whether the internet connection is online and functioning The Fail Count specifies how many successive ping attempts can fail before the NTC 8000 01 fails over...

Page 20: ...tem 2 Uncheck Automatically configure my mobile broadband then use the Profile Name drop down list to select the currently enabled profile you can see it in the Profile list at the bottom of the scree...

Page 21: ...gure the gateway to only connect on the network frequencies that suit your requirements Make your selection from the Change Band drop down list In most cases the default setting of All bands is approp...

Page 22: ...ively you can also disable SIM PIN protection by selecting to Disable PIN from the PIN Protection drop down menu c Click the Save button Entering a PUK code After three incorrect attempts at entering...

Page 23: ...button You can also assign a Hostname to the gateway to identify it on the network and for easy access Note If the IP address has changed you will have to re enter the new IP address configured in yo...

Page 24: ...ns settings Note The DHCP Lease Time must not be less than 120 seconds Figure 20 DHCP Settings After entering the applicable details click the Save button You can also assign a particular IP address t...

Page 25: ...device on the Ethernet subnet A PPP route is also added upon obtaining a WAN PPP connection Adding Static Routes 1 Enter the required values in the fields as shown above for the route being added 2 Cl...

Page 26: ...ised to a Gateway on the PPP interface side so that a Gateway on this network will know how to route to a device on the gateway s Ethernet subnet Add the routes as appropriate in the Static Routes sec...

Page 27: ...5E 00 01 XX as its MAC address The last byte of the address XX is the Virtual Router Identifier VRID which is different for each virtual router in the network This address is used by only one physical...

Page 28: ...Network Port s to forward connections to Must be a value between 1 and 65535 Table 17 NAT Configuration Items Creating a Port Forwarding rule 1 Use the Protocol drop down list to select the protocol f...

Page 29: ...incoming connections are forwarded directly to this device The DMZ page is used to specify the IP Address of the device to allow direct incoming connections Figure 26 DMZ Settings To configure a devi...

Page 30: ...ings MAC IP Port Filter Note When enabling MAC IP Port filtering and setting the default rule to Dropped you should ensure that you have first added a filtering rule which allows at least one known MA...

Page 31: ...ubnet mask of the device for which you are creating a filtering rule Source Port Range The range of ports on the source side LAN WAN for which the rule will apply To use a single port enter the port n...

Page 32: ...ow to configure a VPN connection using IPsec OpenVPN PPTP Client and GRE protocols IPSec IPSec operates on Layer 3 of the OSI model and as such can protect higher layer protocols IPSec is used for bot...

Page 33: ...1 www netcommwireless com NTC 8000 M2M Multi Port Network Gateway 33 Figure 29 VPN Connection Settings IPSec The table on the following page describes each of the fields of the IPSec VPN Connection Se...

Page 34: ...not to use PFS for the VPN connection IKE Encryption Select the IKE encryption type to use with the VPN connection IKE Hash Select the IKE Hash type to use for the VPN connection IPSec Encryption Sele...

Page 35: ...ertificate pre shared key or username and password OpenVPN works well through proxy servers and can run over TCP and UDP transports Support for OpenVPN is available on several operating systems includ...

Page 36: ...nection VPN Network Mask Enter the network mask for use on the VPN connection Diffie Hellman parameters Generate the server and client keys used by the VPN connection Server Certificates Enter the app...

Page 37: ...model and is included on Windows computers Configuring PPTP Client VPN connection From the menu at the top of the screen click Internet Settings then VPN and PPTP Client A list of configured PPTP Cli...

Page 38: ...or not NAT Masquerading Select whether to use NAT Masquerading for the VPN connection Set Default Route to PPTP Make the VPN connection the default route for traffic to use Enable MPPE Select to enab...

Page 39: ...GRE is used to encapsulate the data or payload Configuring a GRE VPN connection From the menu at the top of the screen click Internet Settings then VPN and GRE A list of configured GRE VPN connection...

Page 40: ...c across the internet The default value of 255 is the upper limit on the time that an IP datagram can exist The value is reduced by at least one for each hop the data packet takes to the next router o...

Page 41: ...mode If you are not sure which protocol to use set this option to 11 b g n mixed mode Frequency Channel The frequency or wireless channel that the gateway is broadcasting with Recommended channels ar...

Page 42: ...tings WPA1 WPA2 WPA PSK WPA2 PSK A newer type of security is WPA PSK TKIP and WPA2 PSK AES This type of security gives a more secure network compare to WEP Use TKIP Encryption Type for WPA PSK and AES...

Page 43: ...that the gateway is broadcasting with Recommended channels are 1 6 or 11 Data Beacon Rate DTIM Interval of time in which the wireless gateway broadcasts a beacon which is used to synchronize the wirel...

Page 44: ...ines connect via Ethernet cable In Repeater mode the WDS access points communicate with each other and with wireless clients Below is an example of how to configure two NTC 8000 01 gateways to use the...

Page 45: ...Mode Depending on the capability of your wireless device s wireless network card select the network mode to use There are 5 available options They are 11 b g mixed mode 11b only 11g only 11n only 11...

Page 46: ...he MAC address of Access Point 2 Figure 44 Access Point 1 WDS Settings OPTION DEFINITION WDS Mode Selects the WDS Mode to use Available modes are Disabled Bridged Mode and Repeater Mode In this exampl...

Page 47: ...as a repeater for and provide internet access to its clients through Access Point 1 and therefore does not require a Mobile Broadband connection to be established Figure 45 WDS Aceess Point 2 Status...

Page 48: ...igure 47 WDS Access Point 2 DHCP Settings 4 Under Wireless Setup Basic select the same frequency channel as you did for Access Point 1 Enter an SSID to identify Access Point 2 and set Network Authenti...

Page 49: ...Repeater Mode then enter the same Encrypt Key and the MAC address of Access Point 1 in the AP MAC Address1 field The MAC address of Access Point 1 is listed on its Status page When you have entered th...

Page 50: ...iltering To create a MAC filter 1 In the Please select a SSID number to configure drop down list select the wireless network for which you want to configure a rule 2 In the Filtering Policy drop down...

Page 51: ...h the gateway between Access Point and Wireless Client mode In Access Point mode the gateway allows wireless clients to connect to it for network and internet access In Client mode the gateway can con...

Page 52: ...e and wireless security key are correct AP s BSSID The MAC Address of the wireless access point to which the NTC 8000 01 will connect Network Authentication This field determines the type of wireless...

Page 53: ...number of dynamic DNS host providers Figure 54 DDNS Settings To configure dynamic DNS 1 Set the DDNS Configuration option to Enable 2 From the Server Address drop down list select the Dynamic DNS serv...

Page 54: ...time zone settings the gateway s current time can be adjusted according to its global position while the NTP Network Time Protocol settings allow your gateway to synchronise its internal clock with a...

Page 55: ...s fail the gateway sends 3 pings to the second destination address at the Periodic Ping Accelerated Timer interval e If all 3 accelerated pings to the second destination address fail the gateway regis...

Page 56: ...to prevent access to reading and or writing to the gateways configuration It is recommended that you change the Community names to something other than the default settings when using this feature 3...

Page 57: ...ty of the message and shows all messages at the selected level and lower The display levels are described and listed in order of severity below LOG LEVEL DEFINITION All Display all system log messages...

Page 58: ...ay s configuration Enter the root manager password and click the Save button This will download a copy of the current settings from the gateway to your PC Note The following conditions apply It is NOT...

Page 59: ...Web based User Interface section for more details To update the gateway s firmware 1 Click on the System menu select Load Save and then Upload Click the Browse button Locate the recovery firmware ima...

Page 60: ...system recovery mode 5 When the gateway has finished booting into recovery mode navigate to http 192 168 1 1 in your web browser The gateway recovery console is displayed Note The DHCP Server on the g...

Page 61: ...you uploaded and then click OK to confirm that you want to continue with the installation 8 The installation is complete when you see the words Installation successful as per the screenshot below Fig...

Page 62: ...anager Items The Package Name Version Architecture and Installed time are shown and the package content details are available by clicking on the blue Package Details link Alternatively if you want to...

Page 63: ...for the selected user account Confirm Password Re enter the new password for the selected user account Telnet Account User Name The Telnet Account settings are only available when logged into the gat...

Page 64: ...TION IP Hostname PORT The IP address and port of the external syslog server to which logging information should be sent Log to file Enables or disables the logging of system events Keepalive Enable or...

Page 65: ...eway 65 Logoff The logoff item logs you out of your web configuration session Figure 69 Logoff Reboot The reboot item reboots the gateway This can be useful if you have made configuration changes you...

Page 66: ...Details 14 Table 12 Status Page PPPoE Details 14 Table 13 Status Page PPTP Details 14 Table 14 Status Page IPSec Details 14 Table 15 Advanced Status Settings 16 Table 16 WLAN Failover Settings 19 Tabl...

Page 67: ...1 minute to complete its boot procedure 2 Press and hold the physical reset button on the rear interface panel of the gateway for between 3 and 10 seconds and then release the button The gateway boot...

Page 68: ...guarantee that interference will not occur with the installation of this product in your home or office If this equipment does cause some degree of interference to radio or television reception which...

Page 69: ...icable Consumer Protection Laws which cannot be excluded see Section 3 above the Product Warranty is automatically voided if 7 you or someone else use the product or attempt to use it other than as sp...

Page 70: ...1 www netcommwireless com Contact Address NETCOMM WIRELESS LIMITED PO Box 1200 Lane Cove NSW 2066 Australia Phone 61 0 2 9424 2070 Fax 61 0 2 9424 2010 Website www netcommwireless com Email sales net...

Reviews: