Home
User Guide - Maingate Manager
Contents
1. SECURITY ASPECTS When using IP based communication special attention must always be paid to providing adequate security to protect systems and information Since use of IP Connect GPRS effectively expands the customer s LAN to a multitude of connection points that potentially can be used by unauthorised persons special attention to security in this case 8 1 ACCESSIBLE NETWORK DESTINATIONS When a terminal is connected via IP Connect GPRS this terminal can address and communicate with the following network destinations 1 Customer LAN 2 Maingate s Network Time Server Figure 8 illustrates the accessible network destinations 89470 a pwears I I I I I NA I 80087 920000 I 0483 I I I I I I I Network Time Server Machine with GSM terminal Wireless Maingate Customer 1 Customer LAN 2 Maingate s Network Time Server Figure 8 Accessible network destinations direction of arrow illustrates what party may initiate communications Copyright Wireless Maingate Nordic AB 2007 15 19 W MAINGATE 8 2 TERMINAL AND APPLICATION SECURITY Control of a SIM card that is used together with IP Connect GPRS and knowledge of the correct APN gives a malicious attacker the possibility to address the customer s LAN To prevent attacks on the customer s network from a terminal the customer must use a firewall that blocks malicious IP traffic from reaching his systems Copyright Wireless Mainga
2. e g 46730140102 e P address shall be presented with 12 numbers using 0 where necessary and with as delimiter e g 100 100 002 009 NOTE If the Excel file does not conform to the above description it will be returned to the customer without being registered Should errors occur during registration of terminals from Excel file that are caused by incorrect or conflicting data in the file the file will be returned to the customer In this case data that has been party registered will not be modified in RADIUS When the terminals have been successfully registered Maingate will send a confirmation email to the customer to the email address that sent the Excel file After this the terminals are ready to communicate A B Customer Test Customer AB IP Connect GPRS Domain IPCG test IP Connect GPRS login testadmin Password G56hdge hr MSISDN IP 46710140113 203 012 060 002 46710140119 46710140120 46710140121 46710140122 46710140123 46710140124 46710140125 46710140126 46710140127 46710140123 46710140129 46710140130 46710140131 46710140132 46710140133 46710140134 46710140135 Copyright Wireless Maingate Nordic AB 2007 203 012 060 003 203 012 060 004 203 012 060 005 203 012 060 006 203 012 060 007 203 012 060 008 203 012 060 009 203 012 060 010 203 012 060 011 203 012 060 012 203 012 060 013 203 012 060 014 203 012 060 015 203 012 060 016 203 012 060 017 203 012
3. 060 016 203 012 060 019 TEN Figure 5 Example of Excel file structure 12 19 W MAINGATE 7 COMMUNICATION After a terminal has been registered in RADIUS it is possible to initiate connection to IP Connect GPRS and thereafter communicate to and from that terminal 7 1 PDP CONTEXT ACTIVATION Before IP packets can be exchanged between terminal and application the terminal must connect to IP Connect GPRS This is accomplished by performing a PDP Context activation to the APN provided for IP Connect GPRS from the terminal The APN is found in the IP Connect GPRS Configuration Form see section 3 The supplier of the GSM modem in the terminal should be consulted regarding how to perform PDP Context activation After PDP Context activation has been completed successfully IP communications can be initiated Should the PDP Context be lost for any reason it must be re activated by the terminal before communication can take place again 7 2 ADDRESSING TERMINALS During PDP Context activation the terminal s IP client will be assigned the IP address that this terminal was assigned during registration see section 6 The MSISDN parameter uniquely identifies the terminal and provides the mapping to the correct IP address which identifies the terminal to the customer application The mapping of parameters for is shown in Figure 7 Note Even though the terminals use dynamic IP address allocation over PPP the terminal w
4. A MAINGATE User Guide IP Connect GPRS Wireless Maingate Document number Date Information class Address Phone number Fax number MG040123 PdM F 2007 10 03 Open Information Wireless Maingate Box 244 S 371 24 KARLSKRONA Sweden 46 455 36 37 00 46 455 36 37 37 Copyright Wireless Maingate Nordic AB 2007 The contents of this document are subject to revision without notice due to continued progress in methodology design and manufacturing Wireless Maingate Nordic AB shall have no liability for any error or damages of any kind resulting from use of this document TABLE OF CONTENTS 1 INTRODUCTION PRODUCT OVERVIEW ORDERING IP CONNECT DEVICE IP RANGES IP CONFIGURATION REGISTERING TERMINALS COMMUNICATION SECURITY ASPECTS INVOICING SUPPORT REFERENCES DOCUMENT HISTORY 11 13 15 17 18 19 19 W MAINGATE 1 INTRODUCTION This document is intended to be used by the customer during ordering configuration and use of the Wireless Maingate IP Connect GPRS product 1 1 TERMINOLOGY Account An IP Connect GPRS account containing a group of terminals and a customer application between which communication can take place API Application Programming Interface APN Access Point Name CSD Circuit Switched Data GPRS General Packet Radio Service GSM Global System for Mobile communication IP Default Route LAN Default destination of unspecified IP pack
5. S In order for the IP Connect GPRS product to be successfully used with a terminal the terminal must satisfy the following requirements e The terminal must be equipped with a GSM modem that supports GPRS e The terminal must be equipped with a Maingate GSM subscription e The terminal must support PPP according to RFC 1661 of the IETF e The terminal must support dynamic IP address allocation over PPP e The terminal must use Default Route or alternatively static routing must be defined for IP Connect GPRS Copyright Wireless Maingate Nordic AB 2007 5 19 W MAINGATE 3 ORDERING IP CONNECT The IP Connect GPRS product is ordered by filling in and signing the Product Agreement The signed agreement can be delivered in original to a Maingate sales representative or sent by post to Maingate The pages of the Product Agreement are shown in Figure 2 MAINGA Product Agreement ID 7 nn MAINGATE Account Details Customer Detaili AINGATE Complete ons form per account Technical Contact Perion time eral Ades Feb Cha Par Tre VPN Detalla I Viho Palins gt travail Prange oredan Piare Tas r ie rain OH er raat Device IP Addrente at Pogacd nmo of Pathos Tera tat aa Pa Ge rot I2mende Operational Updater Customer Detalla Mied In by Aarele 11 Maingate bral sities fa Orden Up Biting Gurur be rar Aare mortar Aha Crete Note The signed agreom entmurtbe rentin origil Vacina Nam
6. ark bs ale Inodee number In SvI1 fed no 70 Orvbmalan bo bere day vhenmatirg Fe paynend Tr wen 77 7 ke Pan PUT gmc ET Mii BATT STi ERLANG Frut pe Jando heste grabim Figure 9 Example of invoice Copyright Wireless Maingate Nordic AB 2007 Paez BS SEER pos sere esd Summary ofCharge c per Budge tente rk Fear un Oder Tas Ignore sete inge 166 tge Trage IPR e Capaci S550 BIR aneren ee ope ope opo oo ope 1540 ER Tesh teji tee 1070 tet Teje 1055EUR ODEUR 768 EUR Tre Irug Is sunma d and grouped Inbal hanes per Bag kenie Ore VPM orrecioni probably related b me Budge Genie The cubana am fom Meingeie systm b emirs v be ened b he same Budge Gnie Forde Bie shoul Pe oubolrg raic de bed reicspedtaion omeur wal be prodded Tre deres te renfctom eminsis in b Meirgale sy em wel be teed beach SMa lik a 768 66 EUR Margate 250 w ur oe i eo Plan PET gamcord ET ET IT STIS ERLANG Frut pae Jardrheste gray sina 17 19 W MAINGATE 10 SUPPORT IP Connect GPRS customers are automatically entitled to the use of Maingate Support Maingate Support is staffed by qualified personnel that have thorough experience in supporting customers using GSM communication for industrial applications The support organization helps customers with the following queries Administration of subscriptions and SIM cards Invoicing queries Ordering and managing Maingate s products Troubleshooting Queries about technical produ
7. ate Ma de AB Bax 20 3 571 Kabhi ong Sveden fc ama 58 59 win mangde ae Yen arg DE om a me Pack age te on can cree arm Va daa Margate Nade AB Be 38 3571 24 Kabbiona Sveden fd sanan sas m wanmangacar 26 ag f Bz s jale Ma de AB Bert 294 5 571 N Kabhi ona Sveden 38 37 0 nwnmangarar st Figure 2 IP Connect GPRS Product Agreement One separate form for Account Details page 2 is required for each separate account that is required The Account Details are filled in as follows Technical Contact Person Contact details of the person responsible for configuring the VPN tunnel at the customer Operational Updates Email address of customer representative that shall receive updates concerning operational issues such as planned or unscheduled outages from Maingate VPN Configuration VPN configuration either LAN to LAN or VPN Client Requested IP Size An estimate of the number of IP addresses that are required for the account One IP address is required for each terminal that shall use IP Connect GPRS Based on the required number Maingate will suggest a suitable range to the customer NOTE Due to a scarcity of IP addresses do not over estimate the need for addresses Additional IP ranges can be assigned to an account at a later time NOTE Due to conflicting IP addresses between applications it is possible that specific IP addresses or ranges of IP addresses cannot be used Read section 4 bef
8. ation Transactions to the XML API for registration of terminals shall not be sent though the VPN tunnel Unencrypted Internet communication is used for transactions towards the XML API see Figure 4 Copyright Wireless Maingate Nordic AB 2007 9 19 W MAINGATE Registration of terminals is done over unencrypted Internet and does not pass through the VPN tunnel leman q leman Wireless Maingate LAN Customer LAN All TCP IP traffic for communication between terminals and application passes through the encrypted VPN tunnel Figure 4 API transactions over unencrypted Internet terminal communication through the VPN tunnel 5 3 FIREWALL CONFIGURATION The customer must secure that the customer s firewall is open to allow the types of IP sessions to pass that are used by terminal and application If not the IP packets will be blocked by the customer s firewall and communication will not function correctly Wireless Maingate s firewall towards the VPN tunnel is open to allow for all types of IP sessions to pass When using VPN Client to access terminals the firewall protecting the customer host must be set up to pass through UDP packets bidirectional on port 22022 as the VPN Client recommended by Maingate will use this port to set up the VPN 5 4 TERMINAL CLIENT CONFIGURATION IP communication through IP Connect GPRS will not function correctly if the terminal s IP client is not configured with the co
9. ch authentication and encryption key information is passed and one or more data channels over which private network traffic is carried The key exchange channel is a standard UDP connection to and from port 500 The data channels carrying the traffic between the client and server use IP protocol number 50 ESP More information is available in RFC 2402 the AH protocol IP protocol number 51 RFC 2406 the ESP protocol IP protocol number 50 and RFC 2408 the ISAKMP key exchange protocol Configuration details are provided by mail from Maingate after product ordering The VPN tunnel must be configured according to these methods in order to function The IPSec VPN to customer could be set up in two ways Either with a standard Site to Site configuration or with a VPN Client software on customer host Customer will choose which method that is best suitable 5 2 IP ROUTING Once the VPN tunnel has been established the customer LAN or host must be configured to route applicable packets through the VPN and allow packets from the VPN to reach the customer application When using VPN Client this would normally been take care off automatically by the software it self IP traffic from terminals to customer application VPN tunnel IP traffic from customer application to terminals Maingate Figure 3 IP routing between Maingate and customer LAN The VPN tunnel is only used for data traffic between terminals and applic
10. ct functions Information about planned outages and operational disturbances Maingate Support can be reached via telephone fax or e mail Contact details are supplied with the product confirmation e mails that are sent to customers after product ordering More information regarding Maingate support is presented in reference 3 Copyright Wireless Maingate Nordic AB 2007 18 19 W MAINGATE 11 REFERENCES 1 Interface Specification HTTP XML MG000137 AU revision D 2 IP Connect GPRS Interface Specification MG040116 AU revision A 3 Service Level Agreement MG020973 PdM revision B 12 DOCUMENT HISTORY B 2004 11 22 Niklas E Modification section 2 2 and 3 D 2005 11 14 Niklas E Modifications section 4 and 9 2006 10 20 Modifications section 8 and 10 2007 10 03 HS TS Added VPN Client Copyright Wireless Maingate Nordic AB 2007 19 19
11. ets Local Area Network NTP Network Time Protocol PDP Packet Data Protocol PPP Point to Point Protocol RADIUS Remote Access Dial in User Service TCP IP Transmission Control Protocol Internet Protocol VPN Virtual Private Network XML Extensible Mark up Language Copyright Wireless Maingate Nordic AB 2007 4 19 W MAINGATE 2 PRODUCT OVERVIEW IP Connect GPRS provides transparent IP communication between a customer application and terminals equipped with GSM GPRS modems using fixed IP addressing An overview of the functionality is shown in Figure 1 rad 1 Machine with GSM terminal Wireless Maingate Transparent IP Communication Figure 1 Product overview Customer The customer application is connected to Wireless Maingate over Internet using a VPN tunnel Each terminal is configured once in Maingate s RADIUS with desired parameters that control the communication settings through an XML API or Excel file Once the configuration has been done communication is initiated by activating a GPRS PDP Context and thereafter sending IP packets from application or from a terminal The VPN tunnel could either be set up site to site as in figure above or directly from a host with VPN client software provided by Maingate 2 1 PRODUCT SPECIFICATIONS The IP Connect GPRS product supports the following functionality e Support for IP addressing according to IP v4 2 2 TERMINAL REQUIREMENT
12. ill always be assigned the same IP address from RADIUS for each PDP Context Coe Dynamic Era IP addressing Fixed IP addressing Yt nn En EB Kar PPP over GPRS IP an Terminal Maingate Customer Application Figure 6 IP address allocation E E MSISDN Mapping IP address i L EI re PPP over GPRS I MSISDN IP address IP mn PDP Context Activation Versen ee Terminal Maingate Customer Application Figure 7 Parameter mapping during PDP Context activation Copyright Wireless Maingate Nordic AB 2007 13 19 W MAINGATE 7 3 DISCONNECTION Normally an activated PDP Context does not need to be terminated The PDP Context can be kept open constantly to assure that the application can communicate to the terminal IP Connect GPRS will not initiate a disconnection In some cases the terminal may lose its PDP Context due to network related issues Thus if a constant IP connection to the terminal is required the terminal must contain functionality to identify a disconnection and automatically reconnect to IP Connect GPRS 7 4 TIME SYNCRONISATION Terminals using IP Connect GPRS have access to a local NTP server within Wireless Maingate s LAN This NTP server can be used to perform time synchronisation of terminals using NTP The IP address of Maingate s NTP server is provided in the confirmation mail Copyright Wireless Maingate Nordic AB 2007 14 19 W MAINGATE 8
13. nt IP Connect GPRS accounts attempt to associate the same IP address to different terminals each account is only permitted to register IP addresses from a predefined number of IP address ranges These IP address ranges are compared and verified during product ordering NOTE If one IP Connect GPRS account has been allocated a certain range of IP addresses this range cannot be used by another account This is the reason why Maingate reserves the right to refuse the use of certain IP addresses It is possible allocate several IP address ranges to one IP Connect GPRS account Copyright Wireless Maingate Nordic AB 2007 8 19 W MAINGATE 5 IP CONFIGURATION In order for IP Connect GPRS to function correctly the transmission of IP packets between Maingate and the customer must be carefully configured A VPN tunnel is used to carry the traffic between terminals and application The VPN tunnel ensures that private IP addresses can be used protects data across the Internet and ensures that one customer s traffic is separated from other traffic 5 1 VPN CONFIGURATION IPSec encryption is used for the VPN tunnel between Maingate and the host or LAN connecting the customer application IPSec is a set of standard protocols for implementing secure communications and encryption key exchange between computers An IPSec VPN generally consists of two communications channels between the endpoint hosts a key exchange channel over whi
14. ore filling in this section of the Product Agreement Copyright Wireless Maingate Nordic AB 2007 6 19 W MAINGATE Once the customer has sent the completed Product Agreement to Maingate Maingate will process the agreement and contact the person stated as Technical Contact Person to agree IP addresses and VPN configuration procedures When the account has been configured a confirmation mail with be sent to the Main Contact Person and Technical Contact Person Attached to the confirmation mail are three documents e P Connect User Guide this document e VPN Configuration Form VPN Client confirming the allocated IP address range and configuration parameters for the VPN tunnel e IP Connect GPRS Configuration Form providing login details to the registration API see section 6 APN see section 7 IP address to Maingate s NTP server documentation references on the web and contact details to Maingate Support Passwords for the registration API and the VPN pre shared key or user credentials are sent to the customer in separate emails Copyright Wireless Maingate Nordic AB 2007 7 19 W MAINGATE 4 DEVICE IP RANGES Since a terminal is identified and addressed using its IP address it is vital to secure that each terminal always is allocated a unique IP address IP Connect GPRS performs a check each time a terminal is registered to verify that the IP address is unique In order to avoid that differe
15. rrect settings The terminal must be configured as follows e Allow dynamic IP address allocation over PPP e Default Route or alternatively static routing must be defined for IP Connect GPRS NOTE If dynamic address allocation is not allowed the terminal will not be able to receive its correct IP address from RADIUS If the Default Route or static routing is not configured the terminal will be able to connect correctly to IP Connect GPRS but not be able to communicate with the application Copyright Wireless Maingate Nordic AB 2007 10 19 W MAINGATE 6 REGISTERING TERMINALS Before communication can take place every terminal must be registered in Maingate s systems This is done in one of two ways Either by using the provided XML API or by sending a list of terminals to be registered to Maingate 6 1 USING THE XML API The specification of the XML API is presented in References 2 How to use the XML API and general API details can be found in References 1 Both documents can be downloaded from www maingate se sdk The IP Connect GPRS XML API supports the following calls CreateRadiusPost UpdateRadiusPost DeleteRadiusPost Export Values This call is used to register one or more new terminals This call is used to modify the parameters of an existing terminal This call is used to delete an existing terminal from RADIUS This call is used to generate a file containing the parameter se
16. te Nordic AB 2007 16 19 9 INVOICING MG040123 PdM F W MAINGATE Use of IP Connect GPRS is invoiced one time per month The invoice specifies any applicable initiation fees and periodic fees per account The structure of fees for IP Connect GPRS is as follows Initiation fee Periodic usage fee Periodic capacity fee Registration fee A fixed one time fee per account for set up and configuration of the account A fixed yearly fee per account for use of IP Connect GPRS A variable monthly fee per account that depends on the number of subscriptions that are registered for use through that account A fixed fee per Excel file that has been registered by Maingate Note All GPRS traffic between terminal and application through IP Connect GPRS are invoiced to the respective subscription that has initiated the PDP Context An example of an invoice is shown in Figure 9 En RER 1I0 5 mn RER porse ranil 2004 01 02 Bummar ot Char s br Anonunt INlalonchenes Penaticchespes unil HAH Usage ofsensces 11 21 2006 11 20 Ofer cape AUX 200H0 31 Tots amounts soluding VAT VAT DMH on 755 55 BUR Amounti pay Invoice Inleres I vil be dana IYpayment are receiued aver he due ise THs accounihes been asgred bSuercka Hardasbanken ad Hard arken Frere AB HF S 105 3 Sbotcm and Is bbe pad b HFS aouri IBAN SES00MDOD0D 1S 0 U Serca Hardekterken Skohdm SWIFT CO DE HAN ISES Piee svens Pe Incl you b
17. ttings of terminals in RADIUS To register a terminal in RADIUS the following parameters are used MSISDN IP This parameter is the mobile number of the terminal MSISDN must be unique for each terminal This parameter is the IP address that is assigned to the terminal from the Device IP Range IP must be unique for each terminal NOTE The parameters MSISDN and IP must always be unique for each registered terminal It may take up to 1 hour after a terminal has been registered or updated in RADIUS before communication is possible to the terminal or the updates take effect Copyright Wireless Maingate Nordic AB 2007 11 19 W MAINGATE 6 2 MANUAL REGISTRATION USING EXCEL FILE Instead of using the XML API the customer may send an Excel file to Maingate that contains a list of terminals to be registered To initiate a manual registration the Excel file is sent by e mail to Maingate s support function The Excel file must conform to the following specification e Clearly identify the customer name account domain login and password These parameters are found in the confirmation mail that the customer has received from Maingate during product ordering see section 3 e MSISDN and IP address shall be presented in individual columns and using one row for each terminal e MSISDN shall be presented including country code without or 00 prefix and without spaces or symbols to delimit the number
Download Pdf Manuals
Related Search
Related Contents
Manuel d`utilisation Macintosh Simpli Home AXCHOL003 Instructions / Assembly Eltako – Le système radio pour bâtiments Sondes passives NC65A beauté • CHEVEUX Dynacord DL 92 Speaker User Manual HELSINKI Edital pregão eletrônico 007-2011-emparn secretaria da educação pregão eletrônico nº Copyright © All rights reserved.
Failed to retrieve file