Home
Patton electronic 2603 User's Manual
Contents
1. Protect the unit from moisture vapors and corrosive liquids About this guide 15 Models 2603 2621 and 2635 Getting Started Guide About this guide Factory default parameters IPLink Series High Speed Routers have the following factory default parameters Ethernet IP address 192 168 200 10 24 WAN Connection PPP Bridged Ethernet and serial connections MDI LAN connector Model 2621 X 21 DB 15 port DTE Model 2635 V 35 DB 25 port DCE DTE when using special V 35 cable e Model 2603 T T 1 configuration RJ 48C 100 ohm interface Model 2603 K EI configuration RJ 48C 120 ohm and dual BNC interface 75 ohm Typographical conventions used in this document This section describes the typographical conventions and terms used in this guide General conventions The procedures described in this manual use the following text conventions Table 1 General conventions Convention Meaning Indicates a cross reference hyperlink that points to a figure graphic table or sec tion heading Clicking on the hyperlink jumps you to the reference When you have finished reviewing the reference click on the Go to Previous View Garamond blue type button in the Adobe Acrobat Reader toolbar to return to your starting point Futura bold type Commands and keywords are in boldface font Futura bold italic type Parts of commands which are related to elements already named by th
2. T391 Value fio T392 Value fis Update Figure 34 LMI Configuration webpage Frame Relay Configuration The Frame Relay service can be configured for either bridged or routed applications The use of DLCI values since the original publication of the Frame Relay specifications has been modified as to their use For the two octet address format they are as follows DLCI Number Use 0 Used for in channel signaling 1 15 Reserved DLCI s 16 991 Assigned using Frame Relay connection procedures Verify that none of these values have been assigned to permanent frame relay cells 992 1007 Layer 2 management of FR bearer service 1008 1022 Reserved 1023 Used for in channel layer management WAN Service Configuration 60 Models 2603 2621 and 2635 Getting Started Guide 6 WAN Services Frame Relay bridged This application shows configuration for two IPLink units in bridged mode If using a third party router at the Central site review the routers configuration for connection to a remote bridge Remote Site Configuration First configure the IP address of the Ethernet port interface ip1 via the command line CLT for 192 168 200 2 24 The PC must be on the same subnet for configuring the IPLink via the web pages 1 Bring up the web page management system on your browser by entering the IP address of the IPLink 2 On the Menu go to Services Configuration then to WAN Delete the factory default WAN servi
3. Figure 78 Error Log and Syslog Settings SNMP Daemon For remote management from an SNMP capable management station the IPLink s SNMP Daemon must be configured To identify a specific IPLink configure the Static Variables which the system administrator may use for link identification The Community Table has three configurable parameters Password this is the password which the remote management station must use to access the IPLink for reading writing the SNMP variables Management IP the IP address of the management station Access select either Write or Read The management station can be authorized to configure the IPLink by writing to the SNMP variables or limited to a read only function To delete an entry click on the Del box and click on the Update button Error Log 102 Models 2603 2621 and 2635 Getting Started Guide 10 System Configuration SNMP Daemon Settings This allows the user to modify the SNMP settings for this unit Static Variables System Description 2603 Single Port Router System Location otsest System Contact fotset System Name hoste Update Community Table Index Password Management IP Access Del 1 secret 1010 22 45 write I Update NEW 0 0 0 0 Write y Create Trap Table Index Password Management IP Del NEW 0 Do Create Save SNMP Configuration save Figure 79 SNMP Daemon configuration The Trap Table identifies the
4. Interface blank You can see the status of the PPP link by going to the Edit PPP web page and paging down until you see the Summary description To get to the Edit PPP web page follow this path Services Configuration gt WAN gt Edit Edit PPP LMI Management Frame Relay links LMI Configuration Frame Relay Local Management Interface The Frame Relay Local Management Interface LMI is a mech anism that two separate frame relay systems can use to communicate the status of the interface The LMI inter face allows dynamic updates on the status of the DLCI connections and the congestion state of the network The IPLink implements all three versions of LMI available within the frame relay network These are defined in table 3 Table 3 LMI Implementation on the IPLink Protocol Specification Options Available LMI Frame Relay Forum Implementation Agreement User Side IA FRF 1 superseded by FRF 1 1 Annex D ANSI T1 617 User Side Annex A ITU Q 933 referenced in FRF 1 1 User Side Note LMI uses DLCI 0 but ANSI CCITT has also reserved 1 15 Best practice per the recommendation is to use only DLCIs 16 991 for FR data PVCs and DLCIs 0 15 for LMI PVCs WAN Service Configuration 58 Models 2603 2621 and 2635 Getting Started Guide 6 WAN Services LMI Configuration Options The Frame Relay Local Management Interface is configurable through either the CLI or web interface on the IPLink Series
5. Enable disable The button in the first section enables or disables the DHCP relay on the IPLink router Introduction 89 Models 2603 2621 and 2635 Getting Started Guide 8 DHCP and DNS Configuration Edit DHCP server list The IP addresses of DHCP servers can be updated reset or deleted from the list Add new DHCP server the IP addresses of the DHCP servers are added to the DHCP relay list in this sec tion In the first section of the DHCP Relay webpage click on the Enable button on the DHCP Relay webpage DHCP Relay This page allows you to enter a list of DHCP server IP addresses that the relay will forward DHCP packets to You may also enable and disable the DHCP relay from here The DHCP relay is currently disabled Enable Edit DHCP server list Use this section to edit existing DHCP server addresses present in the DHCP relay s list There are currently no DHCP servers in the list Use the section at the bottom of the page to add a new DHCP server Add new DHCP server Use this section to add a new DHCP server to the DHCP relay s list New DHCP server IP address f L Create Figure 62 DHCP Relay webpage In the third section of the DHCP Relay webpage enter the IP address of a DHCP server and click on the Cre ate button See figure 63 The IP addresses will appear in the section section Edit DHCP server list In the second section you may update or delete the DHCP server IP addresses Sc
6. Power Down Normal y Configure and Activate Figure 25 El port configuration WAN Serial Port Configuration 48 Models 2603 2621 and 2635 Getting Started Guide 5 Serial Port Configuration Time Slot Select For unframed El service Clear Channel go to the Line Option parameter and select Clear Channel E1 G 703 For a full framed El enter 1 31 for partially filled El enter the range of timeslots using the format for example 1 2 3 5 or 1 5 10 31 Any entry for timeslots above 31 will return and invalid selection message Line Options Choose from Clear Channel E1 G 703 or Channelized E1 G 703 G 704 Consult with your service provider which option is required Line Code Choose from AMI or HDB3 Most El applications use HDB3 Line Build Out Select 120 Ohms if the El connection is made via the RJ 48C connector select 75 Ohm if the El connection is made via the dual BNC connectors FDL Mode FDL is a T1 application therefore select Fdl none for El applications Clocking Mode Options are Internal or Receive Recover Clock network In most applications clocking for the 2603 will be derived from the El network set the unit for Receive Recover unless instructed otherwise by your service provider Idle code Options are Enabled or Disabled When idle code is Enabled the 2603 inserts idle codes 7E hex on unused timeslots Set this option to Disabled unless instructed otherwise Power Down Optio
7. B M 99 Update 100 A liano 100 Backup Restore initial lalla AR lar 100 NS 101 Contents Models 2603 2621 and 2635 Getting Started Guide 11 12 13 Website Settings eta edat ep Eom bai eu donee d i le egt ceret lie ceo Da 101 lug TEN 102 SNMP Daemofi M 102 System bl m Vance dead 103 SNTP Client Configuration P 104 Min RO ducado ais cias 105 Configuring th SN TP Client ii 105 SNTP Client Mode Configuration Parameters iii 105 SNTP Client General Configuration Parameters iii 106 System Clock Setting titi dial 106 System AAA 108 Oy Stein ts a a iia 109 Port Connection ascii 109 LAN STATUS niesieni rin eo e tbe Raiti 110 b Egi qr M n 110 Hardware Statuscnee tenetur AS dated s 110 Defined Interfaces isaac 110 Status LED 111 Contacting Patton for assistance 112 Introducido 113 Contact iN oRMAN sacadas 113 Patton support headquarters in the USA comic 113 Alternate Patton support for Europe Middle East and Africa EMEA sese 113 Warranty Service and Returned Merchandise Authorizations RMAs eese 113 Wa
8. See figure 19 Advanced Ethernet Port Configuration Return to basic attribute list o Advanced Port Attributes Name Value Rx No Buffer 0 Rx Error Align 0 Max Multicast Listsize 64 Max Queue 32 Disable false Promiscuous Enable false Figure 19 Advanced Ethernet port attributes The three configurable parameters are all either true or false Auto Negotiation the autonegotiation can be enabled default or disabled In some instances autonegotia tion may be problematic if another device on the LAN does not work properly with autonegotiation 100Base Mode the default is for 100BaseT true To configure it for 10BaseT operation at all times set to false Introduction 42 Models 2603 2621 and 2635 Getting Started Guide 4 Ethernet LAN Port Full Duplex Mode the default value is true for Full Duplex operation Setting it to false configures the Ethernet port to operate only in half duplex mode Rarely do these parameters require a change from their default operation Introduction Auto Negotiation Auto Negotiate Restart Connected Dis Reconnect Count Enable Duplex Check Full Duplex Jabber Jabber Count Link Speed 100Base Mode Full Duplex Mode Remote100BTFD Remote100BTHD Remote10BTFD Remote10BTHD Remote Fault Remote Fault Count Update Reset Clear ifEntry true y false true 14 true false false 100000 true y false y fal
9. Server NAT DHCP DHCP Server Routed NAT Bridged Relay DNS Relay Routed Bridged DHCP Server or DHCP Relay NAT Bridged Routed DHCP Server DHCP Relay DNS Relay DHCP Cli Routed ent WAN side Static IP Routed WAN side Some comments on figure 4 Routed means a routed WAN service and Bridged means a bridged WAN service DHCP Server and DHCP Relay cannot be used simultaneously NAT can be used only if a Routed WAN service is configured Hfa DHCP Server were used with a Bridged WAN service the DHCP server would respond to IP address requests from both interfaces that is the Ethernet and the WAN serial interfaces When NAT is used together with DHCP Relay the WAN service must be routed When DHCP Relay is used with a Bridged WAN service the DHCP server must be on the same subnet as the clients and the IPLink DHCP Server Go to the DHCP Server webpage from the Configuration Menu gt Services Configuration gt DHCP Server The DHCP server default is disabled Click on the Enable button to begin the configuration process Introduction 84 Models 2603 2621 and 2635 Getting Started Guide 8 DHCP and DNS Configuration Patton Home Page o Home o System Status gt System Configuration V Services Configuration LAN WAN LMI Management TP routes DHCP server DHCP relay DNS relay TP Services Security SNTP client i Z El Z o z Em z O 603 C 2 DHCP
10. The following variables are available for configuration managementType Default Value no_maintanence the management Type variable defines the LMI proto col that will be used from the table above The following options are available no_maintenence No maintenance interface will be used for this frame relay connection ITU Network The ITU Q 933 protocol will be used The unit will operate as the Network side of the connection ITU User The ITU Q 933 protocol will be used The unit will operate as the User side of the connection ITU Both NNI The ITU Q 933 protocol will be used The unit will operate as both the Network and User side of the connection ANSI Network The ANSI T1 617 protocol will be used The unit will operate as the Network side of the connection ANSI User The ANSI T1 617 protocol will be used The unit will operate as the User side of the connection ANSI Both NNI The ANSI T1 617 protocol will be used The unit will operate as both the Network and User side of the connection Management State Defines the current state of the DTE side LMI Possible options are as follows Mgt Port DOWN Currently the LMI on the DTE side is DOWN Mgt Port UP Currently the LMI on the DTE side is UP Management Auto Start Default Value FALSE The management Auto Start variable allows the user to start the LMI session before any DLCI connections are created within the unit If this variable is set
11. 2 A SYN ACK packet is sent from the network server to the host 3 An Ack acknowledge packet is sent from the host to the network server Ifthe host sends unreachable source addresses in the SYN packet the server sends the SYN ACK packets to the unreachable addresses and keeps resending them This creates a backlog queue of unacknowledged SYN ACK packets Once the queue is full the system will ignore all incoming SYN request and no legitimate TCP connections can be established Once the maximum number of unfinished TCP handshaking sessions is reached an attempted DOS attack is detected The firewall blocks the suspected attacker for the time limit specified in the DOS Attack Block Duration parameter Maximum Ping Count Default 15 Sets the maximum number of pings per second that are allowed by the firewall before an Echo Storm is detected Echo Storm is a DOS attack An attacker sends oversized ICMP datagrams to the system using the ping command This can cause the system to crash freeze or reboot resulting in denial of service to legiti mate users Maximum ICMP Count Default 100 Sets the maximum number of ICMP packets per second that are allowed by the firewall before an ICMP Flood is detected An ICMP Flood is a DOS attack The attacker tries to flood the network with ICMP packets in order to prevent transmission of legitimate network traffic 4 After selecting the chosen parameters click on Update Intrusion De
12. Configuration peto ee te c UD eure ere tite tub dp eiie ied 52 PPP CONSUMO d e E ue uetus 52 PPEP Bridged EEEE 52 PPP Bridged Remote Site Configuration iii 52 Central Site Configuration siii 53 N e T Ri ere re eet t enit Ud eri pe E dO eere 54 Remote site Cobfiguration cinici aii 54 Central Site Configuration eese entente nennen tenente nennen enitn entre tene nara eene nenne 57 LMI Management Frame Relay links ie 58 LMI Configuration tete bust io ua UU E se iia 58 Frame Relay Local Management Interface eese entente tnnt nentes 58 LMI Configuration Options M 59 Web Configuration Methods iii 59 Frame Relay Configuration DL HEU E HH ia 60 Frame Relay bridged cti hes DERE IU IEEE EU 61 Remote Stte Confipurati n vidi ini a tisdale 61 Central site configuration initial 62 Frame Relay Routed iria er e dcr ee te oen e Pei ens ores 63 Models 2603 2621 and 2635 Getting Started Guide Contents 10 Remote Site TTT dada do 63 Central site configuration cine la lada 66 T NO 68 Introducido 69 Configuring the router suriesti aen r i oda 69 Configuring the security interfaces ie 71 Contiguring Security Polici s cuidada 73 Deleting a Security POM Cy X 74 Enabling the Firewall cas iieri ertet eder aret es ec aaa 74 Firewall Pore aaa ia lara 74 NO 75 Intrusion Detection System IDS iia iia 78 In
13. IP address of the SNMP trap along with its password System Tools The System Tools webpage provides two utilities for testing network connectivity The two utilities are ping and traceroute Enter the IP address of the device to ping or traceroute and click on the appropriate button The example in shows a successful ping of a PC System Tools This page gives the user access to system tools Ping and Traceroute Controls This allows the box to initiate a Ping or Traceroute request Note that input must be an IP address in the form XXX XXX XXX XXX 1010 22 45 Ping Trace Route PING 10 10 22 45 32 data bytes 40 bytes from 10 10 22 45 seg 0 ttl 128 rtt lt 10ms Figure 80 Ping and Traceroute utilities System Tools 103 Chapter 11 SNTP Client Configuration Chapter contents Introductio meea I 105 Gontiourime A e E OLI nn 105 SIP Ghent Mode ContiguramenParameters n 105 SNIP Client General Gontistuacion oca 106 System Clock S etina on cos 106 104 Models 2603 2621 and 2635 Getting Started Guide 11 SNTP Client Configuration Introduction The Simple Network Time Protocol SNTP Client webpage contains the configurable parameters for either setting up the SNTP client or in the abscence of an SNTP server setting the internal clock If you plan the use of an SNTP server you will configure the SN TP Client Mode Configuration Parameters and SNTP Client General Configu
14. Model 2621 comes with an X 21 interface presented on a female DB 15 connector see figure 7 This interface can be configured as a DTE factory default or as a DCE via internal configuration jumper and shall be rated for the proper application with respect to volt age current anticipated temperature flammability and CAUTION mechanical serviceability The interconnecting cables shall be acceptable for external use Ethernet connector X 21 Interface connector RJ 45 DB 15 10 100 Crossover 0000000 E 0000000009 Power Ethernet X 21 Interface Figure 7 Rear view of the 2621 showing location of Ethernet and X 21 connectors Hardware installation 31 Models 2603 2621 and 2635 Getting Started Guide 3 Initial Configuration When the local third party equipment is configured as DTE the Model 3086 X 21 serial port can be config ured as DCE and a regular straight through cable can then be used Do the following to configure the X 21 port as a DCE 1 Open the IPLink case by inserting a screwdriver into the slots and twist the screwdriver head slightly The top half of the case will separate from the lower half of the case see figure 8 Take caution not to damage any of the PC board mounted components Figure 8 Case being opened with a screwdriver 2 Locate the small daughter board on the Model 2621 board to the right of the DB 9 connector figure 9 show
15. Status 109 Models 2603 2621 and 2635 Getting Started Guide 12 System Status LAN Status There are two hyperlinks LAN Settings and DHCP Server Settings which go to the LAN Connections and DHCP Server webpages respectively The other parameters shown in LAN Status are as follows Local IP address the IP address of the Ethernet port LAN subnet mask the subnet mask of the Local IP address e Actas Local DHCP Server indicates Yes or No as to whether the DHCP server is enabled or disabled An enabled DHCP server provides IP addresses to DHCP clients attached to the Ethernet port MAC address the MAC address of the Ethernet port WAN Status Displays the basic parameters and status of the WAN port service and a link to the WAN Services configura tion web page IP Address Type indicates whether the IP address of the WAN service is statically assigned or as a DHCP client e Default gateway the gateway defined by the IP Routes submenu item under Services Configuration in the Configuration Menu Primary DNS DNS dlient is currently not available Hardware Status The definitions of the parameters are as follows Up Time this is the time since the IPLink was last rebooted either soft or hard power cycle Current Time the time is derived from one of two sources If the IPLink is configured as an SNTP client the time is from an SNTP server If the SNTP client is not configure
16. are no validators 1 Return to the Security page 2 Under Security State select Enabled for Security Click on Change State 3 Next select Enabled for Firewall Click on Change State The network is now secure All the interfaces which have been defined are protected and all traffic is blocked between different the different interface types That is all traffic is blocked between the external and internal interfaces The next section describes how to configure the Firewall for allowing certain types of data transfer to occur between the PC s on different networks Firewall Portfilters Next we configure the Firewall to permit certain types of data transfer between the PCs in general hosts on the different networks This is done by the implementation of Firewall portfilters Portfilters are individual rules that determine what kind of traffic can pass between two interface types For the Protocol Number below the different types are defined as thi Abbreviation 1 ICMP 2 IGMP 3 GGP 4 IP Enabling the Firewall 7A Models 2603 2621 and 2635 Getting Started Guide 7 Security Protocol Muniber Abbreviation 6 TER 8 EGP 9 IGP 17 UDP 46 RSVP 47 GRE 89 OSPFIGP 92 MTP 94 IPIP This example continues to allow pings over the firewall 1 From the Configuration Menu gt Configuration gt Security gt Security Policy Configuration gt Port Filters gt Add Raw IP Filte
17. ation NP CPU Usage 0 Status Z El zZ A P E E es o k Z e N eo N Up Time 2 days 23 hours Current Time Sat 03 Jan 1970 23 32 13 Figure 15 Model 2621 home page Hardware installation 38 Models 2603 2621 and 2635 Getting Started Guide 3 Initial Configuration Patton Home Page o Home Patton Electronics Company 2635 Single Port Router Software Revision o System Status 2 6 3 Jan 13 2006 gt System Configuration Status of 2635 Si Port Rout V Services Configuration m ingle Po ix Z Eq e Z E P pa E m Z Q a Le e vo N LAN Local IP Address 10 10 19 30 WAN S EEN PP CPU Usage 1 IP routes NP CPU Usage 1 DHCP server DHCP rela Up Time 2 days 23 hours DNS relay Current Time Sat 03 Jan 1970 23 30 18 TP Services Secr Alarm State NoAhms 0000 SNTP client o Ethernet gt Serial Copyright c 2005 Patton Electronics Co Terms and conditions Figure 16 Model 2635 home page Hardware installation 39 Chapter 4 Ethernet LAN Port Chapter contents o RR ce 41 IOS HS T E cM m UCM METTI ERUIT 41 EA e e nr ve Tus EUM cp Ra aas 41 40 Models 2603 2621 and 2635 Getting Started Guide 4 Ethernet LAN Port Introduction The Ethernet LAN interface port can be configured with two IP addresses a primary and a secondary IP address The configuration web page is found by following the
18. can access the system via a dialin connection using PPP for example The second command creates a user who can login to the system For example the commands system add user fred user with dialin access system add login joe user with login access creates two new users called fred and joe The accounts are created with no passwords To view details about the new users enter system list users The following information is returned Users May May Access ID Name Conf Dialin Level Comment noes ad asa oa a Iria 1 fred disabled ENABLED default user with dialin access 2 joe ENABLED disabled default user with login access 3 admin ENABLED disabled superuser Default admin user Setting user passwords To change the password for the user you are currently logged in as use the command user password Enter the new password twice as prompted Enter new password Again to verify gt Administering user accounts 132 Models 2603 2621 and 2635 Getting Started Guide E Command Line Interface CLI Operation Note No check is made for any current password which may have been set for the user If you wish to change the password for another user enter the command user change username This command logs you into the system as another user You can then use the user password command to change the password for this user Note Changing to another user means that
19. configuration home page 2 Goto the third section Security Interfaces on the Security Interface Configuration webpage Click on the hyperlink Add interface 3 Select ipl beside the Name pull down menu and select internal beside the Interface Type pull down menu Click on Create See figure 45 Security Add Interface New Interface Setup external Create dmz Return to Interface List y Figure 45 Define ip1 interface as Internal 4 Again click on the hyperlink Add interface to define the WAN interface as external 5 Select ppp 0 beside the Name pull down menu and select external beside the Interface Type pull down menu Click on Create See figure 46 Configuring the security interfaces 72 Models 2603 2621 and 2635 Getting Started Guide 7 Security Security Add Interface New Interface Setup Name ppp 0 y Interface Type f external iv Create Return to Interface List y Figure 46 Define ppp 0 interface as External Configuring Security Policies Continue the previous example by defining security policies We will add only one Firewall policy called etoi signifying an external to internal policy between the external and internal interfaces 1 Go to the last section on the Security Interface Configuration webpage called Policies Triggers and Intru sion Detection Click on the hyperlink Security Policy Configuration See figure 47 Polici
20. create a shadow copy of the world wide web WWW All access to the shadow Web goes through the attacker s machine so the attacker can monitor all of the victim s activities and send false data to or from the victims machine When enabled packets destined for the victim host of a spook ing style attack are blocked Victim Protection Block Duration Default 600 seconds DOS Attack Block Duration Default 1800 seconds 30 minutes A Denial of Service DOS attack is an attempt by an attacker to prevent legitimate users from using a service If a DOS attack is detected all suspicious hosts are blocked by the firewall for a set time limit Scan Attack Block Duration Default 86400 seconds Sets the duration for blocking all suspicious hosts The firewall detects when the system is being scanned by a suspicious host attempting to identify any open ports Intrusion Detection System IDS 78 Models 2603 2621 and 2635 Getting Started Guide 7 Security Victim Protection Block Duration Default 600 seconds 10 minutes Sets the duration of the block in seconds Maximum TCP Open Handshaking Count Default 100 Sets the maximum number of unfinished TCP handshaking sessions per second that are allowed by a firewall before a SYN Flood is detected SYN Flood is a DOS attack When establishing normal TCP connections three packets are exchanged 1 A SYN synchronize packet is sent from the host to the network server
21. from default Channel segment size The channel segment size is used to define fragmentation of the packets based on the Frame Relay Forum IA FRE 12 If this variable is set to 0 then FRE12 Frame Relay Fragmentation will be disabled if set to any other value it will set the fragmentation size used Port Defines the port that should be used to setup the Frame Relay Connection For routed applications the port should be set to frf for bridged applications the port should be set to fr Click on the Create button Edit Frame Relay Edit Frame Relay Channel Edit Frame Relay Channel Options Name Value Dici 21 Encaps Type BridgedEther hd Rx Max Pdu paso Tx Max Pdu ESE Chnl Segment Size po Port fr Port Class framerelay Create Reset Figure 36 Frame Relay Channel configuration Central site configuration Note Ifyou are using a IPLink at the Central location follow the instructions below otherwise refer to your third party router documentation for configu ration See the web pages for the IPLink above Some parametric values will differ but the process remains the same First configure the IP address of the Ethernet port interface ip1 via the command line CLI for 192 168 172 3 24 The PC IP address 192 168 172 229 must be on the same subnet for configuring the IPLink via the web pages l Bring up the web page management system on your browser by entering the IP address of
22. situ ation the IPlink typically is at the customer premise or branch office and connects to a router or bridge at a ser vice provider location this can be another IPLink router This application shows configuration for two IPLink units in bridged mode If using a third party router at the Central side review the router configuration for connection to a remote bridge See figure 27 Remote Central Figure 27 PPP Bridged Application IPlink series Remote First configure the IP address on the Ethernet port interface ip1 for 192 168 100 2 24 via the command line CLI Once this is done you can complete the configuration using the web pages l Bring up the web page management system on your browser by entering the IP address of IPLink 2 On the Menu go to Services Configuration then to WAN Delete the factory default WAN services already defined 3 Click on Create a new service in the main window select PPP bridged and click on the Configure button WAN Service Configuration 52 Models 2603 2621 and 2635 Getting Started Guide 6 WAN Services WAN connection create service Please select the type of service you wish to create Ethernet C PPPoE over Ethemet Bridge routed Frame Relay Frame Relay routed C Frame Relay bridged PPP C PPP routed C PPP bridged Continue gt Figure 28 WAN services options 4 In the Description field enter the description you wish This is a mandatory field Without
23. the AC power cord into The IPLink Series router to power up the router Type superuser for Login and press Enter 6 Then type superuser for the password press Enter Hardware installation 36 Models 2603 2621 and 2635 Getting Started Guide 3 Initial Configuration 7 A message will display Login Successful By typing the character all the commands will be displayed Login superuser Password 00 asus gt 8 Any commands parameters may be seen by entering the command followed by a space and a question mark ethernet The following parameters appear add delete set show list clear IP address modification The first parameter to change is the IP address from the default IP address of 192 168 200 10 to your selected IP address Do the following comments are in brackets ip list interfaces enter lists the characteristics of the different interfaces IP Interfaces ID Name IP Address ip set interface ipl ipaddress 10 10 19 10 255 255 0 0 lt enter gt Sets the new IP address which you have selected The IP address in this example is for illustrative purposes only ip list interfaces enter To see if the change in IP address is correct system config save enter To save the new IP address in flash memory gt The IP address has now been successfully changed Web Operation and Configuration Now that the IP address has been configured for your application yo
24. to FALSE the LMI session will begin when the first DLCI channel is created If this variable is set to TRUE the LMI session will begin immediately Full Report Cycle Default Value 6 This variable represents the N391 protocol value User Max Errors Default Value 3 Network side N392 protocol value Net Max Errors Default Value 3 Network side N392 protocol value User Error Window Size Default Value 4 User side N393 protocol value Net Error Window Size Default Value 4 Network side N393 protocol value T391 Value Default Value 10 This variable sets the T391 timers in seconds T392 Value Default Value 16 This variable sets the T392 timers in seconds Web Configuration Methods The following documentation defines how to configure the Frame Relay Local Management Interface using the Web Interface on the IPLink Series WAN Service Configuration 59 Models 2603 2621 and 2635 Getting Started Guide 6 WAN Services All LMI configuration variables are contained under the LMI Management window found through the Ser vices Configuration gt LMI Management link The following screen shows the configuration variables available LMI Management LMI Configuration Management Type no maintenance y Management State NA Management Auto Start false 7 Full Report Cycle ce User Max Errors B Net Max Errors B User Error Window Size KG Network Error Window Size RN
25. will be derived from the T1 network set the unit for Receive Recover unless instructed otherwise by your service provider Idle code Enabled Disabled When enabled the 2603 inserts idle codes 7E hex on unused timeslots Set this option to Disabled unless instructed otherwise Power Down Normal Powered Down When powered down T1 E1 transceiver input and output lines will be set to high impedance to protect the device set unit to Normal for regular operation After all options have been selected click on the Configure and Activate button at the bottom of the screen Additionally save the configuration in non volatile memory by going to the System Configuration Save menu This concludes the T1 interface configuration via the web browser go to section WAN Service Configura tion on page 52 for instructions on router bridge and WAN service configuration Configuring the IPLink Series 2603 for El Operation Web Configuration Launch Internet Explorer or similar web browser type the IP address of the 2603 enter username superuser and password superuser From the main page click on the TI E1 gt Configuration See figure 25 T1 E1 Configuration Configuration Options Time Slot Select 33 Payload Rate 1984 31 Line Options Channelized ET 6 703 6 704 2 Code Sel HDB3 Line Build Out 120 Ohm FDL Mode Farnone i Clocking Mode Receive Clock y Idle Codes Enabled El
26. you lose all superuser privileges Note Only superusers can use the user change command Changing user settings To change any of the default settings for a user use the following commands For example to change the set tings for user fred system set user fred access default engineer superuser system set user fred maydialin enabled disabled system set user fred mayconfigure enabled disabled For example to change the security level for fred enter system set user fred access engineer Note Only superusers can use the user change command Controlling login access To set user login access for user username use the command all on one line system set login lt username gt access default engineer superuser Controlling user access To set user access for user username use the command all on one line system set user lt username gt access default engineer superuser Administering user accounts 133
27. 01 K e E E E a NU UM Te dM TU 101 Error kome e m E E Seer 102 SISIMUPAID Berti e e A E A A E AAA EAE AEE ER E E E E a eee 102 T R e E PE E SE Pee T RENE ARN RISE RoE SCE 103 96 Models 2603 2621 and 2635 Getting Started Guide 10 System Configuration Introduction The System Configuration item on the Configuration Menu opens to provide access to twelve 12 different items They are Authentication allows you to control access to the IPLink s console and web configuration pages Alarm shows the Alarm Table and CPU Usage Settings You can configure the alarm severity for each of the alarms and enable disable the Alarm Error Log Remote Access enable and set the time limit for a remote user to have access to the IPLink Update update the IPLink software from here Save to save the IPLink configuration in non volatile memory Backup Restore used to save the IPLink s configuration on a PC or to load a configuration already saved on a PC Restart to do a soft start of the IPLink or to restore the IPLink to factory defaults Key the key version is used to identify which features are installed in the IPLink Website Settings configures the refresh rate of the web pages Error Log displays the Syslog Settings and shows recent configuration errors from the IPLink SNMP Daemon to modify the SNMP parameters for the IPLink Tools provides ping and traceroute commands from the IPLink Also us
28. 03 K showing location of Ethernet and WAN connectors LL 30 Rear view of the 262 showing location of Ethernet and X 21 connectors c eee uo EET NUES 31 Gase being opened With a screwdriver no ce esce LI eM LEE 32 ocatiomor DEE CE boird q a a e c 32 Rear view of the 2639 showing location of Ethernet and V 3S connectors e e eane eaa HEISE 33 Connecting the 263510 a DEE dae 34 Power connectorlocation on rear panel Model 2603 nno 35 IPLink front panel LEDs and Console port locations Model 2603 shown L LL 36 Model 26009 home page arrarena e a RR Ina 38 Model 2621 home page oce etse terre Ree o E EEE O EE E ee ane eens 38 Model 2695 home page eee IRR A 39 Ethernet LAN port IP addressiconfieuration rene 41 Basic Ethernet porta cr Learnt E tr E II ded 42 Advanced Ethernetiportattnbutes ias 42 GontsurableErhernebpdramietenpe e e ect Gis ole ciate rl ec et E Vt EU 43 Model 2621 X 21 sena postconhcuration parameters ios 46 Model 263595 serial POICEONASUrAO PARERE 46 Model 2603 TI EL WAN port configuration parameters aan 47 To o UU I UTI UE T EE 47 El port configuration seare e eaor e a a E Mee E TEIL E IM IDEE 48 Edoruconts ruonesc ROTOLI Sil PPP Bridged Application ooo Inn 52 NANI services Options vedete deu e dep M Ee token lu RA Co er MEI Ne DI PPE Roud Application somete eran dad 54 EPP Routed Conteuranon menu II 55 EdielPaddress of WAN portistas eee vereri Dd Neh ace are tens 56 Contigurino the edtewayr cc es eem cedes ise ICM P
29. 35 OxFFFF for TCP or UDP protocols means that the mapping will apply to all port numbers for that protocol Some applications embed address and or port information in the payload of the packet The most notorious of these is FTP For most applications it is sufficient to create a trigger with address replacement enabled However there are three applications for which a specific Application Level Gateway is provided FTP Net BIOS and DNS Enabling NAT The configuration of NAT in this example follows on the preceding configuration completed earlier in this chapter 1 Go to the Security Interface Configuration page by clicking on Security under Configuration in the menu 2 Click on Enable NAT to internal interfaces in the Security Interfaces table NAT is now enabled between the internal LAN and the external WAN interfaces of the firewall Global address pool and reserved map 1 Click on Advanced NAT Configuration on the web page Security Interface Configuration 2 Click on the hyperlink Add Global Address Pool The global IP addresses need to be created and put into the Global Address Pool 3 Set the parameters to the following values See figure 53 Interface Type internal Use Subnet Configuration Use IP Address Range IP Address 100 100 100 101 Subnet Mask IP Address 2 100 100 100 102 Introduction to NAT 80 Models 2603 2621 and 2635 Getting Started Guide 7 Security Click on Add Gl
30. 6 Client for autonomous network connection Eliminates the requirement of installing client software on a local PC and allows sharing of the connection across a LAN User configurable PPP PAP RFC 1661 or CHAP RFC 1994 authentication WAN Interfaces TI EI V 35 or X 21 interfaces Available with female RJ 48C dual BNC DB 25 and DB 15 connectors User configurable DTE DCE for X 21 Management User selectable HDLC or Frame Relay WAN datalink connection e Web Based configuration via embedded web server e CLI menu for configuration management and diagnostics e Local Remote CLI VT 100 or Telnet SNMPvI RFC 1157 MIB II RFC 1213 IPLink Series High Speed Routers overview 19 Models 2603 2621 and 2635 Getting Started Guide 1 General Information Logging via SYSLOG and VT 100 console Console port set at 9600 bps 8 N 1 settings no flow control Security e Packet filtering firewall for controlled access to and from LAN WAN Support for 255 rules in 32 filter sets 16 individual connection profiles e DoS Detection protection Intrusion detection Logging of session blocking and intrusion events and Real Time alerts Logging or SMTP on event e Password protected system management with a username password for console and virtual terminal Sepa rate user selectable passwords for SNMP RO RW strings Access list determining up to 5 hosts networks which are allowed to access management system SNMP HTTP T
31. 635 Getting Started Guide Installing an interface cable on the IPLink 2635 s V 35 interface port sees eee 33 Installing the AG power cord tii ia 34 Installing the Ethernet cable coi E e tee nie rie abies Re ined 36 IP address modification satis ia 37 Web Operation and Configuration decre DERE ED pepe brit eere a d pe ERE EE AD e Ua seb Poe cepe DRE 37 PC Configuration 2 rtr ette diia 37 Web BEOWSeE cct an eterne aepo reae ute aD us O ia 37 4 Ethernet LAN Port ocoonocoononocnononnononnononcnonnnononnonanonanononnonasnonannonannonas conoscan ezio zie izezzio ezio as conan non eSa SLEE SANKEN 40 Introduce iia rita 41 LAN Connections sia aaa aaa 41 Ethernet Porta taa iii ia 41 5 Serial Port Configuration zeri rzeeee zio zio rio nine ie riz ioni zeo zio nio rin iS erso zio nio nio M sssi sos 44 WAN Serial Port Configuration cinta lia 45 Serial Interface ata ici i iaia i e 45 Variables orina 45 Web Interface Configuration iii 46 TIET Interface Configuration s 3 1 ipee eget octies 46 Configuring the IPLink Series 2603 for T1 Operation ii 47 Web 6 TTT carai 47 Configuring the IPLink Series 2603 for El Operation ie 48 Web Configuration talladas 48 NANA 50 WAN Services cier A AAA i 51 Configuring the IPLink Series 2603 for El Operation eene eren 51 Web Configuration M M 51 WAN Service
32. After you disable the WEB Server from the web page you can no longer access the any of the IPLink s web pages The only way to enable it is through the Command Line Interface CLI CLI Configuration After configuring a terminal emulator to access the IPLink s serial port there are two commands for the enabling or disabling the WEB Server The following command enables the WEB Server so you can access the management web pages via a browser Remember that by only doing this command the change is saved only in volatile memory Be sure to execute the next command to save it in non volatile memory webserver enable system config save The next command disables the WEB server webserver disable IP Services 94 Models 2603 2621 and 2635 Getting Started Guide 9 e IP Services Associated Ports for the different System IP Services This section is for information purposes only Consult the table to identify which ports are associated with the different System IP Services Table 5 Standard port numbers for the System Services System IP Service TCP UDP FTP 21 control con nection 20 data con nection TFTP 69 SNMP 161 WEB Server 80 80 IP Services 95 Chapter 10 System Configuration Chapter contents O ER EEE OOO ER ocean PRE ERE 97 AuthenticatioN eee E E E UNIES rina 97 AMI E 98 Rem te NECES e TI A E R UE NE E 99 Updater n 100 er LL ina 100 Backup Restore een 100 I a ELE ORDRE reo S 1
33. DE PATTON Mai ElecironicsTo Models 2603 2621 and 2635 IPLink Series High Speed Routers Getting Started Guide Important C This is a Class A device and is intended for use in a light industrial environment It is not intended nor approved for use in an industrial or residential environment Sales Office 1 301 975 1000 Technical Support 1 301 975 1007 E mail support patton com WWW www patton com Document Number 03328U1 001 Rev B Part Number 07M2600Ser GS Patton Electronics Company Inc 7622 Rickenbacker Drive Gaithersburg MD 20879 USA Tel 1 301 975 1000 Fax 1 301 869 9293 Support 1 301 975 1007 Web www patton com E mail support patton com Copyright O 2008 Patton Electronics Company All rights reserved The information in this document is subject to change without notice Patton Elec tronics assumes no liability for errors that may appear in this document Warranty Information The software described in this document is furnished under a license and may be used or copied only in accordance with the terms of such license Patton Electronics warrants all IPLink Series router components to be free from defects and will at our option repair or replace the product should it fail within one year from the first date of the shipment This warranty is limited to defects in workmanship or materials and does not cover customer damage abuse or unauthorized modification If the product
34. Description fFRrouted DLCI fa Encapsulation method Routed IP y C Use DHCP WAN IP address 192 168 164 2 Enable NAT on this interface Figure 38 Frame Relay routed configuration Description FR routed DLCI Enter DLCI number Consult with your service provider for the DLCI number required Encapsulation Method Defines the RFC1490 encapsulation type that will be used by the channel Choose the encapsulation method best suited for your network needs from the following options Routed IP default value Raw WAN IP address Enter the IP address assigned to the WAN port V 35 X 21 or T1 E1 Enable NAT on this interface In this example leave this option blank Click the Create button Go to System Configuration gt WAN gt Edit for Frame Relay Routed service gt Edit IP Interface Enter the WAN IP Address in this example 192 168 164 2 and click on the Create button oN A From the IP Interface web page click on Edit Frame Relay then click on Edit Frame Relay Channel See figure 39 WAN Service Configuration 64 Models 2603 2621 and 2635 Getting Started Guide 6 WAN Services Edit Frame Relay Edit Frame Relay Channel Edit Frame Relay Channel Options Name Value Dici 41 Encaps Type RoutedlP y Rx Max Pdu no Tx Max Pdu fia Chnl Segment Size po Port a Port Class framerelay Create Reset Figure 39 Frame Relay C
35. ELNET Logging or SMTP on events POST POST errors PPP DHCP IP Front Panel Status LEDs and Console Port The IPLink routers have all status LEDs and console port on the front panel of the unit and all other electrical connections are located on the rear panel Model 2600 ipLink Gateway High Speed WAN Access Router 10 100 Crossover V 35 Interface Ethernet MDI X Figure 1 IPLink Series Router Model 2635 shown The status LEDs from left to right are see table 2 for LED descriptions Power Sync Serial TD RD CTS and DTR Ethernet Link 100M Tx and Rx Table 2 Status LED descriptions Power Green ON indicates that power is applied Off indi cates that no power is applied IPLink Series High Speed Routers overview 20 Models 2603 2621 and 2635 Getting Started Guide 1 General Information Table 2 Status LED descriptions Continued T1 E1 Link Green Solid green connected Off disconnected LOS Red On indicates a T1 E1 loss of frame condition It also indicates that no T1 E1 signal is detected TD Green Green indicates a binary 0 condition off indicates a binary 1 or idle condition RD Green Green indicates a binary O condition off indicates a binary 1 or idle condition Sync Serial TD Green Green indicates a binary 0 condition off indicates a binary 1 or idle condition RD Green Green indicates a binary O condition off indicates a b
36. Edit PPP web page and paging down until you see the Summary description In figure 33 the PPP link is in the Establishment phase To get to the Edit PPP web page follow this path Services Configuration gt WAN gt Edit gt Edit PPP WAN Service Configuration 56 Models 2603 2621 and 2635 Getting Started Guide 6 WAN Services MRU fisco Ip Addr From IPCP rue 7 Use Ip Addr From IPCP true y Discover Primary DNS true y Discover Secondary DNS true 7 Give DNSto Relay tue y Give DNSto Client true y Lcp Echo Every fo Auto Connect false 7 Idle Timeout po Bcp Tagged Frame Not Enforced v Summary enabled up phase Establish Connect State connecting Uptime 0 Idletime D NCPRemote Addr Wersion 1 04 If In Octets D If Out Octets 16536 Figure 33 PPP link status Central Site Configuration If the router at the ISP or Central site is another IPLink series follow the instruc tions below If not consult your third party router user manual for configuration See the web pages for the desktop above Some configurable parameters are different although the process is the same Configure the IP address of the Ethernet port interface ip1 to be 192 168 172 3 24 The PC connected to the Ethernet LAN directly must be on the same subnet in order to access the configuration web pages In this example the PC s IP address is 192 168 172 229 24 Notice that this subnet differs from t
37. Figure 74 Save configuration changes in non volatile memory Backup Restore You may save or use previously saved configurations from this webpage Should you want to save a specific application configuration from the IPLink click on Backup configuration to your computer To reload a previously saved configuration file icf browse and select the file from your computer Click on the Restore button to load into the IPLink See figure 75 Update 100 Models 2603 2621 and 2635 Getting Started Guide 10 lt System Configuration Configuration Backup Restore This page allows you to backup the configuration settings to your computer or restore configuration from your computer Backup Configuration Backup configuration to your computer Restore Configuration Restore configuration from a previously saved file Configuration File Browse Restore Figure 75 Saving or reloading previously saved configuration files Restart Erom this webpage you can do a soft reboot of the IPLink or restore the IPLink to factory defaults To restore to factory defaults click on the box for Reset to factory default settings see figure 76 Then click on the Restart button No warning is given before beginning the reboot process You will need to configure the IP address of the Ethernet port again as described in Chapter 3 Initial Configuration Restart Router From this page you may restart your router Restart After resta
38. HOP server configuration web page Parameters for the DHCP Server subnet Four parameters are in the section for defining the DHOP subnet See figure 57 Parameters for this subnet Edit the definition of the DHCP subnet here If you do not wish to specify the subnet value and subnet mask by hand you may instead select an IP interface using the Get subnet from IP interface field The subnet will track the IP address and subnet mask belonging to the chosen IP interface Subnet value po po po po Subnet mask p po p NN Get subnet from IP interface fen Maximum lease time jemo seconds Default lease time ao seconds Figure 57 DHCP Server subnet parameters The first two parameters are applicable when you will define the subnet Subnet value It is necessary to enter the selected value here and the Subnet mask if you do not Get subnet from IP interface See description for the 3rd parameter Subnet mask Introduction 86 Models 2603 2621 and 2635 Getting Started Guide 8 DHCP and DNS Configuration The third parameter is e Get subnet from IP interface If you use this option then you will not enter any values in the first two parameters Should you define another subnet and also select Get subnet from IP interface the IPLink uses the Get subnet from IP interface as the ruling parameter and sets Subnet value and Subnet mask appropriately overriding your initial selection The ip
39. Link 7 8 RJ 45 non shielded RS 232 console port EIA 561 The RS 232 serial control port of the IPLink is configured to operate as a DCE Table 8 RS 232 Control Port Pin No Signal Name Direction 1 DSR from IPLink 2 CD from IPLink 3 DTR to IPLink 4 Signal Ground 5 RD from IPLink 6 TD to IPLink 7 CTS from IPLink 8 RTS to IPLink RJ 45 shielded 10 100 Ethernet port 125 Models 2603 2621 and 2635 Getting Started Guide D IPLink Physical Connectors Serial port V 35 M 34 and DB 25 Connector The Model 2635 has a DB 25 connector for the V 35 interface table 9 provides the pinouts for the M 34 and DB 25 connectors Table 9 V 35 pinout for M 34 amp DB 25 connectors M 34 DB 25 Pin No Pin No Signal Name Direction A Frame Chassis n a Ground P 2 TD a from DTE R 3 RD a to DTE C 4 RTS from DTE D 5 CTS to DTE E 6 DSR to DTE B Z Signal Ground n a F 8 CD to DTE X 9 RC b to DTE 10 W 11 XTC b from DTE AA 12 TC b to DTE 13 S 14 TD b from DTE Y 15 TC a to DTE T 16 RD b to DTE V 17 RC a to DTE L 18 Local Loopback to DTE 19 H 20 DTR from DTE N 21 Remote Loopback to DTE 22 23 U 24 XTC a from DTE M 25 Test Mode to DTE Serial port 126 Models 2603 2621 and 2635 Getting Started Guide D IPLink Physical Connectors X 21 DB 15 Connector The X 21 interface in the Model 2621 may b
40. NSE RIETI EDITIO E TU D IEEE IEEE EE EU 118 Gable Recommendations esee OUI ERUNT OIN III ID EIN IE 122 IPLink Physical Connectors ETA 124 Command Line Interface CLD Operation eerte OUTDOOR UTD UE EE 129 Contents Summary Table of Contents eere TU EUREN EDITI EE e ve eR RENO E E season 3 Contents e POD A PE PRETO E EDT ET TIT y 4 A S T EE 10 LEEN ES AAA Pro Ec CE ECO CERO EO 12 ADout this guide a eese eie EU E T D INTE 13 REO 13 O E IUE LT 13 IN rana 14 Satetyawheni ee e nno 15 Cr iO en 15 Ec OS 16 Illy poeraphicaliconventions used imfthisido eum ent a 16 General conventions ct 16 E a ETES e e IE tnt 17 Phink Series High Speed Routers Oveiview ee nn 18 General EEIT EEE 18 A UTI 19 Drotocolisupport Eoosec 19 PEP SUpport a E iii 19 AIN LI nni 19 Management T 19 A I TITTI 20 Front Panel staros LEDs and Console Pont ia 20 o e M M T aos DI Rear panel connectorsiand switches eerie enni 21 NA TTT RTT TET EEEE ET UE EE 22 AC universal eene uu uu tT Me TT 22 48 VDC power SUPDIY ee e E a 22 Ethernetport ne GE 22 MDI cc ete EE 22 E AOIN AAE ete 24 A o 25 Applications sro 26 3 Ural Comi 27 Hardwareunstallatione oooO asec cree E E enue ete E E E E nears 28 K youa need a aa EA EE EE E E E R TE IRI RES 28 I T san 28 Installing an interface cable on the IPLink 2603 s T1 E1 interface port iii 29 Installing an interface cable on the IPLink 2621 s X 21 interface port eee Sil Contents Models 2603 2621 and 2
41. Server This page allows creation of DHCP server subnets and DHCP server fixed host IP MAC mappings You may also enable and disable the DHCP server from here The DHCP server is currently disabled Enable Server Status There are currently no DHCP server subnets defined Create new Subnet O Help O There are currently no DHCP server fixed IP MAC mappings defined Create new Fixed Host O Help Figure 55 DHCP Server web page The server needs to have a subnet of IP addresses which will be allocated when a DHCP client makes a request Define the subnet by clicking on the hyperlink Create new Subnet The next webpage Create new DHCP Server subnet has four sections Parameters for this subnet defines the subnet and netmask the origin of the subnet maximum lease time and default lease time IP addresses to be available on this subnet either define the IP address range for the DHCP server IP pool or use the default range which is a set of 20 IP addresses DNS server option information enter the IP addresses of the primary and secondary DNS servers which are provided to the DHCP clients Default gateway option information You may use the local host as the default gateway figure 56 shows the entire configuration web page for the DHCP server Introduction 85 Models 2603 2621 and 2635 Getting Started Guide 8 DHCP and DNS Configuration Create new DHCP server subnet This page allows yo
42. The interconnecting cables shall be acceptable for external use The Model 2635 V 35 DB 25 interface is configured internally as a DCE However when using the Patton cable with the 2635 the V 35 interface at the M 34 end of the cable is a DTE see figure 11 In other words the Patton DB 25 to M 34 cable is a sync null modem cable Ethernet connector V 35 Interface connector RJ 45 DB 25 10 100 o ie 0000000000000 Power Ethernet V 35 Interface Figure 10 Rear view of the 2635 showing location of Ethernet and V 35 connectors Hardware installation 33 Models 2603 2621 and 2635 Getting Started Guide 3 Initial Configuration Note The IPLink comes with a V 35 cable configured as a tail circuit Use this cable to interconnect the IPLink s V 35 port to a device configured as a DCE Modem Use cable provided DCE with 2635 IPLink Figure 11 Connecting the 2635 to a DCE device The serial port on the IPLink Model 2635 is configured as a DCE it connects directly to a DTE using a stan dard straight through V 35 cable However in many applications the IPLink s V 35 interface will connect to a DCE modem or multiplexer in this situation use the special cable provided with your Model 2635 This DB 25 M35 cable presents the 2635 s V 35 interface as a DTE for direct connection to a DCE see figure 11 Installing the AC power cord The IPLink router comes with an in
43. With Anycast mode the IPLink s SNTP client sends a request to a designated broadcast address One or more SNTP servers may reply with a unicast message to the IPLink The IPLink communicates with the server first responding After this point the IPLink operates in unicast mode When Anycast is enabled Unicast is auto matically enabled and the IP address of 255 255 255 255 is in the SNTP server s IP address field Anycast takes precedence over Broadcast mode The field Configured IP Address of SN TP Server is the IP address of the dedicated unicast server that the SNTP client will use for synchronization SNTP client SNTP Client Mode Configuration Parameters SNTP Synchronization mode s Unicast Mode C Enabled Disabled Anycast Mode Enabled Disabled Broadcast Mode Enabled C Disabled Set Mode Configured IP Address of SNTP Server 0 0 0 0 Update Figure 81 SNTP synchronization and server IP address configuration Introduction 105 Models 2603 2621 and 2635 Getting Started Guide 11 SNTP Client Configuration SNTP Client General Configuration Parameters The general configuration parameters for the SNTP client are for selecting your timezone and setting the poll ing parameters for the client s transmit packets Current Timezone select the appropriate time zone and click on the Set New Timezone button The next three parameters configure the polling and synchronization process e Timeout value The SNTP c
44. a description you cannot create the WAN service WAN connection PPP bridged Description Interface fi LLC header mode dialout y LLC header mode off HDLC header mode on y No authentication C PAP C CHAP or PAP User name Password Create Verify the settings to be Interface 1 LLC header mode dialout LLC header mode off HDLC header mode on No authentication e Leave User name and Password blank Click on Create Central Site Configuration If the central site also has an IPLink you may configure as described in this sec tion Refer to the web page images for the Remote IPLink configuration above In this example the IP address of interface p1 is changed to 192 168 100 3 24 WAN Service Configuration 53 Models 2603 2621 and 2635 Getting Started Guide 6 WAN Services 1 Bring up the web page management system on your browser by entering the IP address of the IPLink 2 On the Menu go to Services Configuration then to WAN Delete the factory default WAN services already defined 3 Click on Create a new service in the main window select PPP bridged and click on the Continue button 4 In the Description field enter the description you wish for example PPP Bridged Verify the settings to be Interface 1 LLC header mode dialout LLC header mode off HDLC header mode on No authentication e Leave User name and Password blank Cl
45. ample Paint cs Tx Clock Invert normal Rx Clock Invert normal Enabled true Configure Figure 22 Model 2635 V 35 serial port configuration parameters After the serial port has been configured go to WAN Service Configuration on page 52 section WAN Ser vice Configuration on page 52 for router bridge and WAN service configuration T1 E1 Interface Configuration The IPLink Series Model 2603 is equipped with a user selectable T1 E1 interface The T1 interface is pre sented on an RJ 48C 100 ohm connector while the El interface can use the RJ 48C 120 ohm or dual BNC 75 ohm connectors The 2603 T1 E1 serial port configuration page appears in figure 23 WAN Serial Port Configuration 46 Models 2603 2621 and 2635 Getting Started Guide 5 Serial Port Configuration mus T1 E1 Configuration Configuration Options i Z E E Z SA o Home E o System Status Time Slot Select 1 24 Payload Rate 1536K 24 f gt System Configuration Line Options Fractional T1 ESF y SH gt Services Configuration E TF Code Sel B8zs y Fa o Ethernet e V TIEL Line Build Out 100 Ohm 0dB y 2 i T1 X 2 Stakis FDL Mode Ansi T1 403 a 1 A 1 Co ation Clocking Mode Receive Clock Idle Codes Enabled y Power Down Normal y Configure and Activate Figure 23 Model 2603 T1 E1 WAN port configuration parameters Configuring the IPLink S
46. and features normally associated with eachother ete RENI NIRE 83 OO a ee 84 Parameters D OUS A E NE a E ETE ERU 86 IP Addressesito be availableon this subnet oe aer n ae Aaaa E E E eie eeu 87 DNS server option mormant oer sees e e E E cece E 88 Default ateway option informan on enon 89 O S a OE EE EE 89 DACP Ry onen rece a E E EE AEE E R E EE ER 89 Contigurationor the DACAR cem eo 89 BNSRE ro seas Nn 91 Contigurine the DNS Relay oie TUS 91 82 Models 2603 2621 and 2635 Getting Started Guide 8 DHCP and DNS Configuration Introduction The routers offer a DHCP Server DHCP Relay capability and DNS Relay incorporated into the IPLink Of the two DHCP features only one can be enabled at a time either DHCP server or DHCP relay DNS relay can hold two DNS server IP addresses in memory so the DNS relay can forward DNS queries and responses between the host user and the DNS server The DHCP Server will listen for DHCP client requests on a suitable IP interface Typically this is the Ethernet interface named ipl by default Note The Ethernet LAN port can be configured as a DHCP client to receive its IP address from a DHCP server on the Ethernet LAN If so configured you should not enable the IPLink s DHCP server on the Ethernet interface DHCP Relay functions transparently between a a DHCP client and a DHCP server The DHCP relay appears as a DHCP server to the DHCP clients point of view The relay operates by forwarding all broadc
47. ast client request to known DHCP servers The DHCP relay listens on all available interfaces All relay server communi cation is unicast It is important that valid routes are set up to the server and also to the client Services and features normally associated with each other The following table figure 4 is to give guidance on what services of IPLink features to configure when you have decided to use DHCP Server DHCP Relay or DNS Relay If you are configuring a feature listed in the first column Configured Feature you can determine which other features either cannot be must be usually can be or are rarely used The Rarely used column is listed to be technically correct but it is ill advised to use The three most important columns other than the first are Cannot be used Must be used Usually used Use the table like this The feature in this column with the Configured Feature in Column 1 For example 1 The feature DHCP Relay column 2 cannot be used with DHCP Server row 1 column 1 2 The feature Routed column 4 usually is used with DHCP Relay row 2 column 1 Introduction 83 Models 2603 2621 and 2635 Getting Started Guide 8 DHCP and DNS Configuration Table 4 Features and services matrix The feature in this column with Column 1 feature Configured Cannot be Must be Feature used used Usually used Can be used Rarely used DHCP DHCP Relay Routed Bridged
48. by Patton Electron ics technical support Keep at default Serial Speed Any n x 64 kbps speed Defines the generated speed for internal clock mode opera Speed should be enter ed as the rate i e 512 for 512 kbps or 2048 for 2 048 Mbps tion or the clock that will be received in external clock mode operation TX Data Sample Point Ext Clk Tx Clk When the unit is running in internal clock mode the setting of TX Data SamplePoint will indicate to the system which clock to use to sample the in coming data Some systems require that the data be sampled on one clock or another This is also useful when tail circuits are being created When running in the external clock mode this should be set to Ext Clk WAN Serial Port Configuration 45 Models 2603 2621 and 2635 Getting Started Guide 5 Serial Port Configuration Web Interface Configuration The following screen capture shows the variables available to configure the X 21 serial interface Serial Configuration Configuration Options Serial Speed 512K y Clock Mode extemal y Tx Clock Invert normal y Rx Clock Invert normal y Enabled tue Configure Figure 21 Model 2621 X 21 serial port configuration parameters The next figure shows the Model 2635 V 35 serial port configuration parameters Serial Configuration Configuration Options Serial Speed 512K v Clock Mode external Tx Data S
49. c MAC IP parings Selectable lease period DHCP relay agent RFC 2132 RFC 1542 with 8 individual address pools DNS Relay with primary and secondary Name Server selection NAT RFC 3022 with Network Address Port Translation NAPT for cost effective sharing of a single DSL connection Integrated Application Level Gateway with support for over 80 applications NAT MultiNat with 1 1 mapping NAT Many 1 NAT Many Many mapping NAT Port IP redirection and mapping IGMPv2 Proxy support REC 2236 Frame Relay with Annex A D LMI RFC 1490 and FRE 12 Fragmentation PPP Support Point to Point Protocol over HDLC PPPoE REC 2516 Client for autonomous network connection Eliminates the requirement of installing client software on a local PC and allows sharing of the connection across a LAN User configurable PPP PAP REC 1661 or CHAP RFC 1994 authentication PPP BCP RFC 1638 support for bridged networking support Management Web Based configuration via embedded web server CLI menu for configuration management and diagnostics Local Remote CLI V T 100 or Telnet SNMPvI1 RFC 1157 MIB II RFC 1213 Logging via SYSLOG and VT 100 console Console port set at 9600 bps 8 bits no parity 1 stop bit no flow control Protocol Support 120 Models 2603 2621 and 2635 Getting Started Guide B Specifications Security Packet filtering firewall for controlled access to and from LAN WAN Support for 255 rules in 32
50. ce Configuration 65 Models 2603 2621 and 2635 Getting Started Guide 6 WAN Services e Cost 1 Interface frame 0 Create Ip V4Route Name Value Destination 0 0 0 0 Gateway 192 168 164 3 Netmask 0 0 0 0 Cost Interface Update Reset Cancel Figure 40 IP route for Frame Relay routed application 12 Click on the Update button This concludes the configuration of the remote site Be sure to save the configuration in non volatile memory by System Configuration gt Save gt Click on Save in the main window Central site configuration Note Ifyou are using an IPLink at the central location follow the instructions below otherwise refer to your third party router documentation for configu ration First configure the IP address of the IPLink s Ethernet port interface ip1 via the command line CLI for 192 168 172 3 24 The PC must be on the same subnet for configuring the IPLink via the web pages 1 Bring up the web page management system on your browser by entering the IP address of the IPLink 2 On the Menu go to Services Configuration then to WAN Delete the factory default WAN services already defined Click on Create a new service in the main window select Frame Relay routed and click on Continue Enter the description for the circuit in the Description field This is a mandatory field Without a descrip tion you cannot create a WAN service Description FR routed DLCI Enter DLCI numbe
51. ceed with warranty service It is often more con venient for you to work with your local reseller to obtain a replacement Pat ton services our products no matter how you acquired them Warranty coverage Our products are under warranty to be free from defects and we will at our option repair or replace the prod uct should it fail within one year from the first date of shipment Our warranty is limited to defects in work manship or materials and does not cover customer damage lightning or power surge damage abuse or unauthorized modification Introduction 113 Models 2603 2621 and 2635 Getting Started Guide 13 Contacting Patton for assistance Outofwarranty service Patton services what we sell no matter how you acquired it including malfunctioning products that are no longer under warranty Our products have a flat fee for repairs Units damaged by lightning or other catastro phes may require replacement Returns for credit Customer satisfaction is important to us therefore any product may be returned with authorization within 30 days from the shipment date for a full credit of the purchase price Ifyou have ordered the wrong equipment or you are dissatisfied in any way please contact us to request an RMA number to accept your return Patton is not responsible for equipment returned without a Return Authorization Return for credit policy Less than 30 days No Charge Your credit will be issued upon receipt and inspection
52. ces already defined 3 Click on Create a new service in the main window select Frame Relay bridged and click on Continue Enter the description for the circuit in the Description field This is a mandatory field Without a descrip tion you cannot create a WAN service 5 Click on Create a new service in the main window select Frame relay bridged and click on the Configure button See figure 35 WAN connection Frame Relay bridged Description FR bridge DLCI f Encapsulation method Bridged Ethernet Create Figure 35 Frame Relay bridged creation 6 Click along the following path Services Configuration gt WAN gt Edit Then click on Edit Frame Relay Channel See figure 36 The configurable parameters are e DICI Consult with your service provider for the DLCI number required LMI uses DLCI 0 but ANSI CCITT has also reserved 1 15 Best practice per the recommendation is to use only DLCIs 16 991 for FR data PVCs and DLCIs 0 15 for LMI PVCs WAN Service Configuration 61 Models 2603 2621 and 2635 Getting Started Guide 6 WAN Services Encapsulation type Bridged Ether Defines the REC 1490 encapsulation type to be used by the channel In some instances you may need to choose another type Consult your service provider RX Max PDU 8192 Receive side max PDU default 8192 normally not changed from default TX Max PDU 8192 Transmit side max PDU default 8192 normally not changed
53. ction PPP routed Description PPP Security Firewall Interface 1 WAN IP address 0 0 0 0 255 255 255 255 LLC header mode off HDLC header mode on No authentication C PAP C CHAP or PAP User name Po Password Po Create Figure 41 PPP routed WAN service for Security Firewall example 6 Click on Edit in the WAN Connections webpage and then click on the Edit Ip Interface hyperlink 7 In the Edit Ip Interface webpage enter the fields as follows and click on the Create button See figure 42 Ipaddr 192 168 101 1 Mask 255 255 255 0 Edit Ip Interface Edit Tcp Mss Clamp Edit Ip Interface Options Name Value Ipaddr 192 168 101 1 Mask 255 255 255 0 Dhcp false y MTU 1500 Name ppp 0 Enabled true y Layer2Session Create Reset Figure 42 IP address of PPP routed WAN service The next step in configuring the router is to add the default gateway route The WAN IP address of the routed PPP WAN service at the CO site is 192 168 101 2 so this will be the gateway IP address on the IPLink 1 Clickon IP routes under Services Configuration in the Configuration Menu 2 Clickonthe Create a new Ip route hyperlink Configuring the router 70 Models 2603 2621 and 2635 Getting Started Guide 7 Security Enter 192 168 101 2 in the box adjacent to Gateway Leave Destination and Netmask both as 0 0 0 0 because this is the gateway default route Click on the Update bu
54. d Interface W WAN IP address 21681642 255 255 255 255 LLC header mode ot 7 HDLC header mode on y No authentication C PAP C CHAP or PAP User name Password Create Figure 30 PPP Routed Configuration menu Click on Create 5 Go to Services Configuration gt WAN gt Edit for PPP routed gt Edit TP Interface gt Ipaddr enter the WAN IP Address and Mask in this example 192 168 164 2 and 255 255 255 255 See figure 31 WAN Service Configuration 55 Models 2603 2621 and 2635 Getting Started Guide 6 WAN Services 6 Click on Create Edit Ip Interface Options Name Value Ipaddr 192 168 164 2 Mask 255 255 255 255 Dhep false y MTU 1500 Name ppp 0 Enabled tue Layer2Session Create Reset Figure 31 Edit IP address of WAN port 7 Click on Services Configuration gt IP Routes gt Create new Ip V Route Create the gateway to the remote router by entering the WAN IP address of the remote router in this example enter 192 168 164 3 in the Gateway field See figure 32 8 Click the Update button Create Ip V4Route Name Value Destination 0000 Gateway 21681643 Netmask ooo Cost NN Interface none Cancel Figure 32 Configuring the gateway The other fields should be Destination 0 0 0 0 e Gateway 192 168 164 3 Mask 0 0 0 0 Cost Interface blank You can see the status of the PPP link by going to the
55. d the time derives from the Clock Set ting as set by the user The Clock Setting is found in the SNTP Client configuration page Version lists the version of the operating software in the IPLink The version information is more detailed than is listed on the Home webpage of the IPLink Set Time a link to the SNTP Client configuration page Defined Interfaces Provides links to operating statistics of the defined interfaces System Status 110 Models 2603 2621 and 2635 Getting Started Guide 12 System Status Status LEDs The LEDs indicate the status of the Power the WAN Sync Serial port and the Ethernet connection All LED indicators will present the same looking profile e g clear when unlit due to being single color water clear high efficiency LEDs Table 6 Status LED descriptions Power Green ON indicates that power is applied Off indi cates that no power is applied T1 E1 Link Green Solid green connected Off disconnected TD Green Green indicates a binary 0 condition off indicates a binary l or idle condition RD Green Green indicates a binary O condition off indicates a binary 1 or idle condition Sync Serial TD Green Green indicates a binary 0 condition off indicates a binary 1 or idle condition RD Green Green indicates a binary O condition off indicates a binary 1 or idle condition CIS Green ON indicates the CTS signal from the router is activ
56. d 2635 Getting Started Guide 2 e Product Overview Introduction The IPLink Series Router operates as a bridge or a router and has two ports for communication The Ethernet port Connects to the LAN side of the connection The Serial port Connects to local DTE devices Model 2621 and 2635 The T1 El port Connects directly to T1 E1 lines Model 2603 The router provides all layer 2 and layer 3 protocols required for end to end link communication When configuring the IPLink router questions must be answered so the IPLink router functions as desired For example when a router or bridge module needs to be activated some questions would be Isa default gateway required Which encapsulation technique is best for this application Frame Relay PPP or another These decisions can be made and implemented more easily if The IPLink Series router s fundamental architecture is understood Also while configuring The IPLink Series router via a browser using the built in HTTP server is very intuitive an understanding of the architecture is essential when using the command line interface CLI commands The fundamental building blocks comprise a router or bridge interfaces and transports the router and bridge each have interfaces A transport provides the path between an interface and an external connection For exam ple the Ethernet transport attaches to an Internet Protocol IP interface A transport consists of layer 2 and every
57. d for entering an IP address and mask WITHOUT use of a console connection Default IP address of 192 168 200 10 24 Simple software upgrade using FTP into FLASH memory Front panel LEDs indicate Power WAN Ethernet LAN speed and status Field Factory Default Option Standard 1 year warranty Ethernet Auto sensing Full Duplex 10Base T 100Base TX Ethernet Standard RJ 45 and built in MDI X cross over switch IEEE 8021 d transparent learning bridge up to 1 024 addresses e 8 IP address subnets on Ethernet interface Sync Serial Interface e ITU T X 21 or V 35 interface Available with female DB 25 and DB 15 connectors User configurable DTE DCE for X 21 T1 E1 Interface Line Rate 1 544 Mbps T1 and 2 048 Mbps E1 RJ 48C connector also includes dual BNC for El connections e DSX 1 levels for connection to local T1 E1 device PBX e Nx56 64 kbps with full DSO mapping AMI B8ZS T1 AMI HDB3 El e ESF coding and framing T1 General Characteristics 119 Models 2603 2621 and 2635 Getting Started Guide B Specifications Protocol Support Complete internetworking with IP RFC 741 TCP RFC 793 UDP RFC 768 ICMP RFC 950 ARP REC 826 IP Router with RIP REC 1058 RIPv2 REC 2453 Up to 64 static routes with user selectable priority over RIP OSPF routes Built in ping and traceroute facilities Integrated DHCP Server REC 2131 Selectable general IP leases and user specifi
58. e binary 1 off indicates CTS is binary O DTR Green ON indicates the DTR signal from the DTE device attached to the serial port is active binary 1 Ethernet Link Green ON indicates an active 10 100 BaseT connec tion 100M Green ON connected to a 100BaseT LAN Off connected to a 10BaseT LAN Tx Green Flashing when transmitting data from the router to the Ethernet Rx Green Flashing when transmitting data from the Ether net to the router Status LEDs 111 Chapter 13 Contacting Patton for assistance Chapter contents INTORNO OI 113 our 113 Pa US Ae E OO e 113 Alternate Patton support tor Europe Middle Hast and Africa EMEA meee 113 Warranty Service and Returned Merchandise Authorizations RIMAS enne inn 113 OOO T 113 Oe Of arara Service eee rer ORT EUER EGET ERES 114 A L TI 114 Returmtorctedit policy ecu cec OE Ue UU ITE 114 RN nuestra OOO 114 EE ee v ee mM TNR M E 114 112 Models 2603 2621 and 2635 Getting Started Guide 13 Contacting Patton for assistance Introduction This chapter contains the following information e Contact information describes how to contact PATTON technical support for assistance e Warranty Service and Returned Merchandise Authorizations RMAs contains information about the RAS warranty and obtaining a return merchandise authorization RMA Contact information Patton Electronics offers a wide array of
59. e IP interface For exam ple assume that the IP address of ip1 is 10 10 19 10 16 figure 59 shows that the IP address pool ranges from 10 10 19 11 to 10 10 19 30 Introduction 87 Models 2603 2621 and 2635 Getting Started Guide 8 DHCP and DNS Configuration Parameters for this subnet Edit the definition of the DHCP subnet here If you do not wish to specify the subnet value and subr instead select an IP interface using the Get subnet from IP interface field The subnet will track the mask belonging to the chosen IP interface Subnet value 10 ego co J Subnet mask 255 255 0 J Get subnet from IP interface ipl y Maximum lease time 86400 seconds Default lease time 43200 seconds IP addresses to be available on this subnet You need to make sure that the start and end addresses offered in this range are within the subnet 1 Alternatively you may check the Use a default range box to assign a suitable default IP address pr Start of address range 10 o ng dm End of address range 10 io ig 30 iv Use a default range Figure 59 Example based on default range of IP address pool DNS server option information When a client requests an IP address from a DHCP server the server can also send the IP addresses of the pri mary and secondary DNS servers IP addresses The IPLink can accomplish this in one of two ways neither really having an advantage over the other This section of the configuration page is one method th
60. e configured for either DTE or DCE Default is DCE Table 10 X 21 Interface Model 2621 Pin No Circuit Signal Name Direction Signal Ground or Common Return 2 T Transmit Data a from DTE 3 Controla from DTE 4 R Receive Data a to DTE 5 Indication a to DTE 6 S Signal Timing a to DTE 7 z z 8 Ga DTE Common Return 9 T Transmit Data a from DTE 10 C Control b from DTE 11 R Receive Data b to DTE 12 Indication b to DTE 12 5 Signal Timing b to DTE 14 15 1 Frame Ground Transmit B 9 9 Transmit A RE e corola aw 4 Receive Indication B 12 5 Indication Signal Timng B 13 anl Timinn M 6 Signal Timing A 7 15 8 Signal Ground Figure 85 X 21 DB 15 connector Serial port 127 Models 2603 2621 and 2635 Getting Started Guide D IPLink Physical Connectors E1 T1 RJ 48C Connector The T1 E1 transmit signals are not polarity sensitive even though they have the traditional designation of Tip and Ring Table 11 T1 E1 Port Pin No Signal Receive Ring Receive Tip Shield Receive Transmit Ring Transmit Tip Shield Transmit l N S Gi A CON RX RX T IX 12345678 Figure 86 T1 E1 RJ 48C connector Serial port 128 Appendix E Command Line Interface CLI Operation Chapter contents Introducti br TE RR RR CR MIRROR 130 CE erminologgi ne 130 RUE 9 REA OTe rac T A
61. e de Dt ED Me EE LUE 56 ER e 57 ERICA RONN PASTI 60 Frame Relay bridged creation nina 61 Frame Relay Channel con essc a rre o EP E UE EE 62 Frame Relay routed application ate AT 63 Frame Relay noutedicon enpationa reco ee co o E 64 Frame Relay Channel si Routed contfis urationoe o DS E 65 IP route for brane Relay routed appli Po 66 PPP routed WAN service fon Security ios 70 liPraddressioh EP Droured UGO SU a RR 70 Valid gateway TOWLE agg nce buen ete TOR REL ee om mU Dade oan Hee Hue ter ete gn vul Securty con euro ROME pases e OS 72 Define ipi antesfacejas Internal eoe ic eere 70 Define ppp O inteniace asini en 73 Security Policy Conhoutation hyperlink sevo mcin ron me Models 2603 2621 and 2635 Getting Started Guide 48 49 50 51 32 53 54 55 56 57 58 29 60 61 62 63 64 65 66 67 68 69 70 val 72 73 74 75 76 FE 78 79 80 81 82 83 84 85 86 New Policy link to contiguration Webpage ias ed 73 Deleting a Security Policy ssa area rior AA EN RUD RH HR RE den 74 Denning ICMP port filter Tor pine ss usb a se A A ad 75 Configuring TCP port filter for FTP cinc ori dia oa 76 Adding trpeer for FIP data tramster erre Vets ved AA A 77 NAT Global Address Pool configuration 2 035 010 2008 o doer e ai em eminent on de mee dr bre n 81 NAT Reserved mapping configuration 12 524 TE ELISE ribus tages EFE Den ea pA RP dene Fade 81 DHCP Server web Page ss ci pai sussa ERI PE ERE DIRMI E ae ROS FESSA P ERE dA 85 DHCP server co
62. e figure 63 To update or change a DHCP server IP address enter the desired IP address over the IP address which is no longer valid Click on the Update button With this action you do not need to delete the IP address and sub sequently add a new IP address It is one action To delete a DHCP server IP address check the Delete box for the appropriate IP address and click on the Update button Introduction 90 Models 2603 2621 and 2635 Getting Started Guide 8 DHCP and DNS Configuration Edit DHCP server list Use this section to edit existing DHCP server addresses present in the DHCP relay s list DHCP server IP address Delete fo fo pss fo r Update Reset Add new DHCP server Use this section to add a new DHCP server to the DHCP relay s list New DHCP server IP address f L Create Figure 63 DHCP Relay server list DNS Relay The DNS Relay webpage contains a configurable list of DNS server IP addresses The IPLink s DNS Relay for wards DNS queries from a client to a pre defined DNS server and DNS server responses to the client You can configure the DNS Relay for two IP addresses These are for access to primary and secondary DNS servers Configuring the DNS Relay Go to the DNS Relay webpage by following the hyperlink path Configuration Menu gt Services Configura tion gt DNS Relay See figure 64 Patton Home Page o Home System Status gt System Configuration V Services Confi
63. e it will set the fragmentation size used Port Defines the port that should be used to setup the Frame Relay Connection For routed applications the port should be set to frf for bridged applications the port should be set to fr Click on the Create button This conclude the central site configuration Frame Relay Routed This application shows the configuration for two IPLink units in routed mode If using a third party router at the Central site review the routers configuration for connection to a remote bridge Remote Central Figure 37 Frame Relay routed application Remote Site Configuration First configure the IP address of the IPLink s Ethernet port interface ip1 via the command line CLI for 192 168 100 2 24 The PC must be on the same subnet for configuring the IPLink via the web pages 1 Bring up the web page management system on your browser by entering the IP address of the IPLink WAN Service Configuration 63 Models 2603 2621 and 2635 Getting Started Guide 6 WAN Services 2 On the Menu go to Services Configuration then to WAN Delete the factory default WAN services already defined Click on Create a new service in the main window select Frame Relay routed and click on Continue Enter the description for the circuit in the Description field This is a mandatory field Without a descrip tion you cannot create a WAN service See figure 38 WAN connection Frame Relay routed
64. e other is DNS Relay to be described later in this chapter Refer to figure 60 DNS server option information Enter the addresses of Primary and Secondary DNS servers to be provided to DHCP clients on this subnet You may instead allow DHCP server to specify its own IP address by clicking on the Use local host address as DNS server checkbox Primary DNS server address 10 ho in 10 Secondary DNS server address 10 10 f an r Use local host address as DNS server Figure 60 Configuration of the DNS server IP addresses Enter the IP addresses of the primary and secondary DNS servers Subsequently the client will receive these addresses when assigned an IP address When the client makes a DNS inquiry it sends the request directly to the appropriate DNS server The IPLink router merely forwards the packet The third parameter is Use local host address as DNS server which is the IP address of the IPLink In this sce nario the client considers the IPLink as a DNS server by sending all requests to the IPLink s IP address The IPLink forwards the request to the DNS servers using the IP address of the actual servers You still need to define the IP addresses of the primary and secondary DNS servers in the section because the IPLink needs to know in order to forward the DNS requests Introduction 88 Models 2603 2621 and 2635 Getting Started Guide 8 DHCP and DNS Configuration Default gateway option information The IPLink is the gateway al
65. e user are in boldface italic font Italicized Futura type Variables for which you supply values are in italic font Futura type Indicates the names of fields or windows Garamond bold type Indicates the names of command buttons that execute an action 16 Chapter 1 General Information Chapter contents MS A aV civ ley eere RI ETE OTT TEC UTE TIE 18 Generalatttibutes oorr tes casper eec OI e 18 T ce rece ere T OA 19 INST TETE ooo roer E eee ae DUE E I T LE 19 PPP SUPPO to tenia Rien rit 19 ITE aa oo Ro doado ado aba a a ap 19 Management senso oa o 19 SU pera RE a aca PER eet 20 Front Panel Statis LEDs and Console Portese ie e e E 20 Console po ita eU UE eM reos 21 Repo TTS K T E E E M eyes 21 POWET CONNEC o E 22 RIRE TEE eer TT po ES eoe ec ere M Mee UE NA UA eM eed eT 22 Ethernet green eee eee TU nn po HE Co UU p 17 Models 2603 2621 and 2635 Getting Started Guide 1 General Information IPLink Series High Speed Routers overview The IPLink Series of gateway routers bridges combine full set of high speed IP routing features and WAN access via PPP IP FR protocols All IPLink routers come with an auto sensing full duplex 10 100Base T Ethernet port MDI X cross over switch console port and internal or external power supply There are three versions in the IPLink series corresponding to a choice of WAN interface The Model 2603 is equipped with an integrated T1 E1 CSU DSU for connection to full and frac
66. eceive Recover Clock network In most applications clocking for the 2603 will be derived from the El network set the unit for Receive Recover unless instructed otherwise by your service provider Idle code Options are Enabled or Disabled When idle code is Enabled the 2603 inserts idle codes 7E hex on unused timeslots Set this option to Disabled unless instructed otherwise Power Down Options are Normal and Powerdown When powered down the E1 will put high impedance on the input and output lines to protect the device set unit to Normal for regular operation WAN Services 51 Models 2603 2621 and 2635 Getting Started Guide 6 WAN Services Once all options have been selected click on the Configure and Activate button at the bottom of the screen Additionally save the configuration by going to the System Configuration gt Save menu This concludes the El interface configuration via the web browser go to section WAN Service Configuration on page 52 for instructions on router bridge and WAN service configuration WAN Service Configuration The IPLink Series Routers offer various WAN services for the proper transport encapsulation Ethernet Frame Relay and PPP options The Ethernet option is PPPoE bridged only Frame Relay and PPP can be used in either bridged or routed applications PPP Configuration PPP Bridged PPP Bridged Remote Site Configuration The IPlink series routers can be configured as bridges in this
67. ed to clear the interface table counters Authentication The IPLink manager controls access to the IPLink s console and web pages The default defined user is supe ruser See figure 68 Authentication This page allows you to control access to your router s console and these configuration web pages Currently Defined Users User May Configure Authenticate Remote End Comment superuser true false Default admin user Edit user D o Create a new user q Figure 68 Authentication web page showing default superuser The superuser is the default administrative user and is given authority to configure the IPLink but the default settings have disabled the ability to authenticate through a remote connection To enable remote access authen tication click on Edit user To add another user account click on Create a new user See figure 69 You will define the new user by Introduction 97 Models 2603 2621 and 2635 Getting Started Guide creating a Username defining the Password give the user ability to configure the IPLink or read only authority add a comment useful to the administrator Alarm 10 System Configuration Authentication create user Details for new user Username Password m May Configure false y May Dial in Comment Create Reset Cancel and return to Authentication Setup Page y false S Figure 69 Creating new user Acce
68. efault 8192 Channel segment size The channel segment size is used to define fragmentation of the packets based on the Frame Relay Forum IA FRE 12 If this variable is set to 0 then FRE 12 Frame Relay Fragmentation will be disabled if set to any other value it will set the fragmentation size used Port Defines the port that should be used to setup the Frame Relay Connection For routed applications the port should be set to frf For bridged applications the port should be set to fr 9 Click on the Create button 10 Click on System Configuration gt IP Routes gt Create new Ip V Route 11 Create the gateway to the remote IPLink by entering the WAN IP address of the remote IPLink in this example enter 792 168 164 3 in the Gateway field The other fields should be Destination 0 0 0 0 e Gateway 192 168 164 2 Mask 0 0 0 0 Cost nterface frame 0 12 Click on the Update button This concludes the configuration of the remote site Be sure to save the configuration in non volatile memory by System Configuration Save Click on Save in the main window WAN Service Configuration 67 Chapter 7 Security Chapter contents Introduction 69 Configurina H crest ares setcessseeccceus Loses posts E rar ap do ses SONORA Dos Dad DE Desire ds Road nro 69 S T TT Ne e RTE e n ER A OR e e 71 TRT ITH 73 DAMA T ROY een 74 E RL 74 IST TT ES T e TU ae aia ooo rrt 74 Security E de E TUTTA nn 75 In
69. er of data via FTP has not been defined no data can be transferred Data transfer occurs with the commands ls dir get put commands The portfilter allows an ftp control channel but does not allow the use of a secondary data channel for passing data by ftp To enable the FTP data channel add a trigger to open a secondary channel only when data is being passed This minimizes the number of open ports Each open port is a security risk 1 From the Configuration Menu gt Configuration gt Security gt Security Trigger Configuration gt New Trig Set the parameters as follows See figure 52 Transport Type tcp Port Number Start 21 Port Number End 21 Allow Multiple Hosts Block Max Activity Interval 3000 Enable Session Chaining Block Enable UDP Session Chaining Block Binary Address Replacement Block Address Translation Type none Click on Create Security Triggers 76 Models 2603 2621 and 2635 Getting Started Guide Security Add Trigger 7 Security Transport Port Port Allow Max Enable Enable Binary Address Type Number Number Multiple Activity Session UDP Address Translation Start End Hosts Interval Chaining Session Replacement Type Chaining tcp y fe fe Block y 3000 Block y Block y Block y Create You should now be able to use FTP commands to pass data between Remote and Local Security Trig
70. eries 2603 for T1 Operation Web Configuration Launch JVetscape Internet Explorer or similar web browser type the IP address of the 2603 enter username superuser and password superuser From the main page click on the 71 E1 gt Configuration See figure 24 T1 E1 Configuration Configuration Options Time Slot Select i24 Payload Rate 1536K 24 Line Options Fractional TIESF y Code Sel Bezs y Line Build Out 100 onmod8 y FDL Mode Ansi T1 403 y Clocking Mode Receive Clock y Idle Codes Enabled Power Down Noma y Configure and Activate Figure 24 T1 configuration WAN Serial Port Configuration 47 Models 2603 2621 and 2635 Getting Started Guide 5 Serial Port Configuration Time Slot Select For a T1 using all 24 time slots enter 1 24 for fractional T1 enter in any format for example 1 2 3 5 or 1 5 10 24 Any entry for timeslots above 24 will return an invalid selection message Line Options Fractional T1 Line Code The 2603 uses B8Zs and AMI B8Zs is the most widely used Line Build Out Select from 100 0dB 100 Ohm 7 5dB 100 Ohm 15dB and 22 5dB For CSU DSU application use 100 OdB option consult your T1 service provider for more information FDL Mode Options are ANSI T 1 403 and Fdl none Consult your T1 service provider if FDL is active on your T1 link Clocking Mode Internal Receive Clock network In most applications clocking for the 2603
71. ers tell the security mechanism to expect these second ary sessions and how to handle them Rather than allowing a range of port numbers triggers handle the situa tion dynamically opening the secondary sessions only when appropriate The triggers work without needing to understand the application protocol or reading the payload of the packet although this does happen when using NAT Triggering allows you to set up a trigger for different application protocols that use multiple sessions The tim eout between sessions and whether or not session chaining are allowed are configurable Session chaining is not needed for FTP but is for NetMeeting Configuring the router The configuration of security assumes that the IPLink router has been configured with a valid IP address for the Ethernet port so that the user may access the modem via the web page If the IP address is still the factory default go to the section in Chapter 3 entitled IP Address Modification In this example the WAN transport between the two IPLink router Routers will be PPP routed 1 Clickon WAN under Services Configuration in the IPLink routers Configuration Menu 2 Clickon Create a new service Select PPP routed and click on the Cont inue gt button For this example enter PPP Security Firewall in the Description field See figure 41 YN gt p Click on Create Introduction 69 Models 2603 2621 and 2635 Getting Started Guide 7 Security WAN conne
72. es Triggers and Intrusion Detection Security Policy Configuration y Security Trigger Configuration O Configure Intrusion Detection O Figure 47 Security Policy Configuration hyperlink 2 Click on the hyperlink New Policy See figure 48 Security Policy Configuration Current Security Policies No Policies Defined New Policy y Figure 48 New Policy link to configuration webpage 3 Select the parameters so the policy is defined as follows Between interfaces of types external internal Validators will allow traffic Click on Apply Configuring the security interfaces 73 Models 2603 2621 and 2635 Getting Started Guide 7 Security Deleting a security Policy To delete a security policy go to the table of Current Security Policies and click on the Delete button for the selected security policy Security Add Policy Between interfaces of types extemal internal Validators will allow traffic Selecting allow will block traffic from all hosts except those hosts which have validators apply Figure 49 Deleting a Security Policy Enabling the Firewall At this point both security and the firewall can be enabled and the network is secure All the interfaces which have been defined are protected that is all traffic has been blocked between the internal ip1 and external ppp 0 interfaces Only traffic which has validators is allowed to pass through and at this moment there
73. etting Started Guide About this guide Precautions Notes cautions and warnings which have the following meanings are used throughout this guide to help you become aware of potential problems Warnings are intended to prevent safety hazards that could result in per sonal injury Cautions are intended to prevent situations that could result in property damage or impaired functioning Note A note presents additional information or interesting sidelights important information i The alert symbol and IMPORTANT heading calls attention to IMPORTANT ard Strictly follow the instructions to avoid property damage The alert symbol and CAUTION heading indicate a potential haz potential electric shock hazard Strictly follow the instructions to avoid property damage caused by electric shock The shock hazard symbol and CAUTION heading indicate a The alert symbol and WARNING heading indicate a potential safety hazard IN Strictly follow the warning instructions to avoid personal injury shock hazard Strictly follow the warning instructions to avoid injury caused j The shock hazard symbol and WARNING heading indicate a potential electric by electric shock 14 Models 2603 2621 and 2635 Getting Started Guide Safety when working with electricity A WARNING A General observations This device contains no user serviceable parts The equipment shall be returned to Patton Electronics for repairs or repaired by quali
74. fails to perform as warranted your sole recourse shall be repair or replacement as described above Under no condition shall Patton Electronics be liable for any damages incurred by the use of this product These damages include but are not limited to the following lost profits lost savings and incidental or consequential damages arising from the use of or inability to use this product Patton Electronics specifically disclaims all other warran ties expressed or implied and the installation or use of this product shall be deemed an acceptance of these terms by the user Note Conformity documents of all Patton products can be viewed online at www patton com under the appropriate product page Summary Table of Contents V 0 NU OG UL WB N i em e 11 General PECES UA cito 17 Read USC TS ELS A Ora 24 Initial Configuration EEE 27 Ethernet LAN PETI SOEETEDHEEEEEEUEEEEEEEHEYTENECHUQEHECEREDEEEE sos Seose Eeee ne HEEDET CHE TEEERHENEEEEDEEEEEEEXREREEEERETEEEXEPULE CO Sea Sea Eae 40 SIS el ROT ETH E EST CLET T GRTEECOOUEEERELCEQ ROG E GEEGODODEREOOUCEEEY EEEEPERESDECOGODCEECEEGEEEDEREOCHOHEOERCUREEE sauna cuca dadas cranici 44 NEUSS T ER TITTI IT 50 SECUrIty RR ATE RCE DUTO RR EO RO 68 DHCP and DNS Configuratio ET 82 LE E IAA EII OTT TTO O OO OOTO OO 93 KARE TT TT iii 96 SNTP S T eT ETT T 104 SITA SE A A A III 108 Contacting Patton TTT T 112 Compliance informations eere ee EI RA ER TDI T EU 115 SpCCHICAUODS recono cosets e IRIS EE
75. fied service personnel Mains Voltage Do not open the case the when the power cord is attached Line voltages are present within the power supply when the power cords are connected The mains outlet that is utilized to power the devise shall be within 10 feet 3 meters of the device shall be easily accessible and pro tected by a circuit breaker For AC powered units ensure that the power cable used meets all applica ble standards for the country in which it is to be installed and that it is con nected to a wall outlet which has earth ground For units with an external power adapter the adapter shall be a listed Lim ited Power Source Hazardous network voltages are present in WAN ports regardless of whether power to the unit is ON or OFF To avoid electric shock use caution when near WAN ports When detaching the cables detach the end away from the device first Do not work on the system or connect or disconnect cables during periods of lightning activity In accordance with the requirements of council directive 2002 96 EC on Waste of Electrical and Electronic Equipment WEEE ensure that at end oflife you separate this product from other waste and scrap and deliver to the WEEE collection system in your country for recycling e Clean the case with a soft slightly moist anti static cloth e Place the unit on a flat surface and ensure free air circulation Avoid exposing the unit to direct sunlight and other heat sources
76. filter sets 16 individual connection profiles e DoS Detection protection Intrusion detection Logging of session blocking and intrusion events and Real Time alerts Logging or SMTP on event e Password protected system management with a username password for console and virtual terminal Sepa rate user selectable passwords for SNMP RO RW strings Access list determining up to 5 hosts networks which are allowed to access management system SNMP HTTP TELNET e Logging or SMTP on events POST POST errors PPP DHCL IP Dimensions 1 58H x 4 16W x 3 75D in 10 6H x 4 1W x 8 8D cm Power and Power Supply Specifications The IPLink router may come with either an AC or DC power supply AC universal power supply The IPLink Series router offers internal or external AC power supply options The internal power supply connects to an AC source via an IEC 320 connector 100 240 VAC 200 mA 50 60 Hz e The external power supply connects to an external source providing 5 VDC via a barrel type connector 48 VDC power supply Rated voltage and current 36 60 VDC 400 mA The DC power supply connects to a DC source via a terminal block Connect the equipment to a 36 60 VDC source that is electri A cally isolated from the AC source The 36 60 VDC source is to be reliably connected to earth CAUTION Security 121 Appendix C Cable Recommendations Chapter contents RN O 123 Ud AD GR Ate toe eee E E 123 122 M
77. free technical services Ifyou have questions about any of our other products we recommend you begin your search for answers by using our technical knowledge base Here we have gathered together many of the more commonly asked questions and compiled them into a searchable database to help you quickly solve your problems Patton support headquarters in the USA Online support available at http www patton com E mail support e mail sent to support patton com will be answered within 1 business day Telephone support standard telephone support is available 5 days a week from 8 00am to 5 00pm EST 1300 to 2200 UTC GMT by calling 1 301 975 1007 e Fax 1 253 663 5693 Alternate Patton support for Europe Middle East and Africa EMEA Online support available at http www patton inalp com E mail support email sent to support patton inalp com will be answered within 1 day Telephone support standard telephone support is available five days a week from 8 00 am to 5 00 pm CET 0900 to 1800 UTC GMT by calling 41 0 31 985 25 55 e Fax 441 0 31 985 25 26 Warranty Service and Returned Merchandise Authorizations RMAs Patton Electronics is an ISO 9001 certified manufacturer and our products are carefully tested before ship ment All of our products are backed by a comprehensive warranty program Note Ifyou purchased your equipment from a Patton Electronics reseller ask your reseller how you should pro
78. gers Figure 52 Adding trigger for FTP data transfer 77 Models 2603 2621 and 2635 Getting Started Guide 7 Security Intrusion Detection System IDS The security feature in the IPLink Router provides protection from a number of attacks Some attacks cause a host to be blacklisted i e no traffic from that host is accepted under any circumstances for a period of time Other attacks are simply logged The subsequent table is a summary of the attacks detected Attacking Host Attack Name Protocol Blacklisted Ascend Kill UDP yes Echo Chargen UDP no Echo Scan UDP yes WinNuke TCP yes Xmas Tree Scan TCP yes IMAP SYN FIN Scan TCP yes Smurf ICMP If victim protection set SYN FIN RST Flood TCP If scanning threshold exceeded Net Bus Scan TCP yes Back Orifice Scan UDP yes 1 To enable IDS click on Enabled for Intrusion Detection Enabled on the Security Interface Configura tion page Then click on Change State 2 Click on Configure Intrusion Detection 3 You may choose which of the parameters to configure and for which value Use Blacklist Default 10 minutes when enabled If IDS has detected an intrusion an external host access to the network is denied for ten minutes Use Victim Protection Default Disabled Victim Protection When enabled Victim Protection protects the victim from an attempted spoofing attack Web spoofing allows an attacker to
79. guration LAN WAN LMI Management TP routes DHCP server DHCP relay DNS relay Zz LO Z o 2 S Zi e V N Figure 64 Hyperlink path to the DNS Relay webpage Enter the IP address of the primary DNS server see figure 65 and click on the Create button Similarly enter the IP address of the secondary DNS server Introduction 91 Models 2603 2621 and 2635 Getting Started Guide 8 DHCP and DNS Configuration DNS Relay This page allows you to enter a list of DNS server IP addresses that the DNS relay can forward DNS queries to Edit DNS server list Use this section to edit existing DNS server addresses present in the DNS relay s list The first address should be the Primary DNS server and the second address should be the Secondary DNS server You cannot have more than two addresses at a time There are currently no DNS servers in the list Use the section below to add a new DNS server Add new DNS server Use this section to add a new DNS server to the DNS relay s list New DNS server IP address ig ho li ao Figure 65 DNS Relay configuration webpage You can change the IP address of the DNS servers on the DNS Relay webpage see figure 66 by modifying the IP address requiring the change and clicking on the Update button To delete the IP address of a DNS server check the Delete box then click on the Update button DNS Relay This page allows you to enter a list of DNS serve
80. hannel Routed configuration Edit Frame Relay Channel Enter the appropriate information in the following fields e Dci Consult with your service provider for the DLCI number required in this example use 45 Encapsulation Method Defines the RFC1490 encapsulation type that will be used by the channel Chose the encapsulation method best suited for your network In this example enter Routedlp RX Max PDU Enter the number of receive side max PDU in this example it is the default 8192 TX Max PDU Enter the number of transmit side max PDU in this example it is the default 8192 Channel segment size The channel segment size is used to define fragmentation of the packets based on the Frame Relay Forum IA FRE 12 If this variable is set to 0 then FRE12 Frame Relay Fragmentation will be disabled if set to any other value it will set the fragmentation size used Port Defines the port that should be used to setup the Frame Relay Connection For routed applications the port should be set to frf For bridged applications the port should be set to fr 9 Click on the Create button 10 Click on System Configuration gt IP Routes gt Create new Ip V Route 11 Create the gateway to the remote IPLink by entering the WAN IP address of the remote IPLink in this example enter 792 168 164 3 in the Gateway field The other fields should be Destination 0 0 0 0 e Gateway 192 168 164 3 Mask 0 0 0 0 WAN Servi
81. he subnets of the WAN service link and also the Ethernet port of the remote IPLink which we just configured 1 Bring up the web page management system on your browser by entering the IP address of the IPlink 192 168 172 3 2 On the Menu go to Service Configuration then to WAN Delete the default WAN services already defined 3 Click on Create a new service in the main window select PPP routed and click on the Continue button In the Description field enter the description In this example it is called PPP Routed Description PPP Routed Interface 1 e WAN IP address and Mask 192 168 164 3 255 255 255 255 LLC Header Mode off HDLC Header Mode ON e No authentication WAN Service Configuration 57 Models 2603 2621 and 2635 Getting Started Guide 6 WAN Services Username blank e Password blank Click on the Create button 4 Goto Services Configuration gt WAN gt Edit for PPP routed gt Edit TP Interface gt Ipaddr enter the WAN IP Address and Mask in this example 192 168 164 3 and 255 255 255 255 Click on Create Go to Configuration Menu gt Configuration gt IP Routes gt Click on Create new Ip V Route 7 Create the gateway to the remote IPLink by entering the WAN IP address of the remote IPLink in this example enter 192 168 164 2 in the Gateway field 8 Click OK The other fields should be e Destination 0 0 0 0 e Gateway 192 168 164 2 e Mask 0 0 0 0 Costl
82. ick on Create PPP Routed This application shows configuration for two IPLink units in PPP routed mode An IPLink may be used as the router at the Central site but it is not necessary You can use a third party router as long as it supports PPP routed operation If using a third party router at the Central site review the routers configuration See figure 29 Remote site configuration First configure the IP address on the Ethernet port interface ip1 for 192 168 200 2 24 via the command line CLI The PC will be on the same subnet as the IPLink Ethernet port Once this is done you can complete the configuration using the web pages Figure 29 PPP Routed Application l Bring up the web page management system on your browser by entering the IP address of the IPLink 2 On the Menu go to Services Configuration then to WAN Delete the factory default WAN services already defined WAN Service Configuration 54 Models 2603 2621 and 2635 Getting Started Guide 6 WAN Services 3 Click on Create a new service in the main window select PPP routed and click on the Continue button In the Description field enter the description you wish In this example it is called PPP Routed Description PPP Routed Interface 1 WAN IP address 192 168 164 2 255 255 255 255 LLC Header Mode off HDLC Header Mode ON No authentication Username blank Password blank WAN connection PPP routed Description PPP route
83. inary 1 or idle condition CIS Green ON indicates the CTS signal from the router is active binary 1 off indicates CTS is binary O DTR Green ON indicates the DTR signal from the DTE device attached to the serial port is active binary 1 Ethernet Link Green ON indicates an active 10 100 Base T connec tion 100M Green ON connected to a 100BaseT LAN Off connected to a 10BaseT LAN Tx Green Flashing when transmitting data from the router to the Ethernet Rx Green Flashing when transmitting data from the Ether net to the router Console port Located on the front panel the unshielded RJ 45 RS 232 console DCE port EIA 561 with the pin out listed in the following table A Signal Signal SAL odes ered Yeas 1 Out DSR 2 Out CD 3 In DTR 4 Signal Ground 5 Out RD 6 In TD 7 Out CTS 8 In RTS Rear panel connectors and switches On the rear panel from left to right are the following IPLink Series High Speed Routers overview 21 Models 2603 2621 and 2635 Getting Started Guide 1 General Information Power input connector Ethernet connector e MDI X switch e WAN port V 35 X 21 T1 E1 Power connector AC universal power supply The IPLink Series router offers internal or external AC power supply options The internal power supply connects to an AC source via an IEC 320 connector 100 240 VAC 200 mA 50 60 Hz e The external power s
84. it Remote Access 99 Models 2603 2621 and 2635 Getting Started Guide 10 System Configuration Update To upgrade the IPLink to another software version select the software image by clicking on the Browse button The software is a tar file See figure 73 After selected the software is downloaded to the IPLink Wait until the upload has completed The best way to monitor when the IPLink reboots is to view the process from the RS 232 console port Firmware Update From this page you may update the system software o Select Update File Updates where available may be obtained from Patton Electronics Company New Firmware Image CA2603_243tar Browse Update Options Figure 73 Updating software Clicking on Options provides for selecting Firmware Update Configuration If enabled the IPLink will pre vent updating with incorrect software Save To save configuration changes to non volatile memory it is essential to click on the Save button on this webpage See figure 74 Ifyou do not do this all configuration changes are stored only in volatile memory meaning that if the IPLink is restarted all configuration changes are lost Click on the Save button and wait until seeing the message Saved information model to im conf Save configuration Confirm Save Please confirm that you wish to save the configuration There will be a delay while saving as configuration information is written to flash Save
85. l Ethernet interface is always one option However there may be a WAN interface also as an additional option The interface is the DHCP server listening interface It listens for client requests on this interface The two remaining parameters are Maximum lease time the default value is 86 400 seconds e Default lease time the default value is 43 200 seconds IP Addresses to be available on this subnet The next section see figure 58 has three parameters IP addresses to be available on this subnet You need to make sure that the start and end addresses offered in this range are within the subnet you defined above Alternatively you may check the Use a default range box to assign a suitable default IP address poo on this subnet Start of address range y b End of address range b b Use a default range O Figure 58 DHCP IP address pool Start of address range Enter the first IP address to be available in the DHCP IP address pool End of address range Enter the last IP address to be available in the DHCP IP address pool Use a default range Checking this box will give you an IP address pool of 20 contiguous addresses This set ting when checked overrides anything entered in the Start and End of address range If you have selected Get subnet from IP interface and have checked the Use a default range the first of the twenty IP addresses will be the next sequential address following the IP address of th
86. l client traffic when Use local host as default gateway is checked see figure 61 Additional option information You may wish to provide additional information to the clients on the DHCP subnet Click on the hyperlink Create new DHCP option to access the configuration webpage The options can specify A default gateway Domain name RC server HTTP server SMTP server e POP3 server NNTP server WINS server Time servers Refer to figure 61 as an example of multiple options to be sent to the clients Default gateway option information Use local host as default gateway O Additional option information Add and remove items from this list to configure additional option information you would like the DHCP server to give to clients on this subnet Name Value Delete default gateway 10 11 12 13 D domain name idealnetdomain D nntp server 10 15 1 1 D netbios name servers 10 10 1 11 10 10 1 12 DO Create new DHCP option Update Reset Figure 61 DHCP server optional information example DHCP Relay With this webpage you can enter a list of IP addresses for DHOP servers When a client requests an IP address it uses one of the DHCP addresses listed in the DHCP relay webpage The IPLink forwards or relays the request to the DHCP server Note Do not use the IPLinks DHCP server if the DHCP Relay is enabled Configuration of the DHCP Relay The DHCP Relay webpage has three sections See figure 62
87. lient will wait for the configured number of seconds of having no response from the server before retrying to send another time synchronization request The maximum timeout value is 30 seconds Default value is 5 seconds Packet retries When no response after the timeout period is received from the SNTP server the IPLink will send another request for the number times configured in this parameter The maximum number of retries is 10 Default value is 2 Polling value in minutes The SNTP client will automatically send a time synchronization request period ically If set to zero 0 the polling mechanism is disabled The maximum value is 30 minutes SNTP Client General Configuration Parameters Current Timezone 4 UTC GMT time US Eastern Standard 5h E Set New Timezone Enter new SNTP transmit packet timeout value in seconds 5s Enter new SNTP transmit packet retries value e Enter new SNTP automatic resynchronization polling value in minutes o Set New Values Figure 82 Timezone and Polling packet configuration System Clock Setting If you are not using a Stratum clock with the SNTP feature you can still configure the internal system clock for a calendar date and time This parameter is on the same web page as the SNTP Client configuration The format is lt Year 4 digits Month digits Day 2 digits lt Hour 2 digits Minutes 2 digits gt Seconds 2 digits The example in fig
88. lo io fa cio Subnet Mask l255 2955 l0 0 Secondary IP Address IP Address n o ao o Update Note there may be a short pause between clicking Update and receiving a response Advanced Figure 17 Ethernet LAN port IP address configuration The secondary IP address must be in the same subnet as the primary IP address With primary and secondary IP addresses you can reach the IPLink s webpages via either IP address However you will have to login for each separate IP address Ethernet Port The Ethernet Port Configuration webpage provides a summary of the Ethernet port s performance You reach it by clicking on the hyperlink Ethernet in the IPLink s Configuration Menu window The Basic Port Attributes webpage displays the most commonly used Ethernet parameters for determining the performance of the Ethernet port see figure 18 on page 42 Introduction 41 Models 2603 2621 and 2635 Getting Started Guide 4 Ethernet LAN Port Ethernet Port Configuration View advanced attributes o Basic Port Attributes Name Value MAC UO a0 ba 00 28 3f Rx Ok 1224338 Rx Broadcast Packets 654397 Rx Error Packets 1305 Tx Ok 2321 Tx Collisions 41 Tx Error Packets D 100Base false Connected true Full Duplex false Link Speed 100000 Update Reset Clear ifEntry Figure 18 Basic Ethernet port attributes For additional statistical parameters and a few configurable parameters click on the hyperlink View advanced attributes
89. lts air A ds 101 Webpage refresh rates otitis sd a a a a de des 101 Error Logand Syslog Settrigs oca is a 102 SNMP Daemon configuration 13 133 ss iria id e 103 Pine aed Traceroute nte diia ds di ic 103 SNTP synchronization and server IP address configuration LL 105 Timezoneand Polling packet confictiration aorta daa 106 Configuration of the internal system calendar clock LL 107 System Stars subsystems SUM a a 109 XZT DB 15 Connector ss es crs ARA gee ie reina 127 TAYE RSS conheco a A he ddr ds dida ug di o SHES 128 List of Tables No 0 N GAV KR Ua NW ra T emm IT ecce RE 16 Statue ED descHDHOHSE en I EC SUCRE ETUR Las 20 I MIdmpl mentation on thePIunk oce e cH ETUR EE US 58 Features A MIMO III 84 Standard port numbers tor the System erica canoe e LM UNO TEE 95 Status BED ale ser ELOA do s ec E M CU pet T3 Ethernet MIDI X switchiimoutipesition o 125 Ronn 125 Voa pinout tor NDA S DDB 5conhnect rse eee eic CM EE IU UNE Ue 126 A eere d WR uer a E 127 PEIRO E RR IR OI SUN EEUU M MIR UEM A 128 12 About this guide This guide describes installing and configuring Patton Electronics IPLink Series High Speed Routers The instructions in this guide are based on the following assumptions The router may connect to a serial DTE device or T1 E1 line There is a LAN connected to the Ethernet port of the router Audience This guide is intended for the following users Operators Installers Mainte
90. n A CO 130 Rana A E O E A E 130 Using the Console en 130 Admete ne Usera ccoin I 132 Adding new USES e eem E E E E E ETE 132 SAE SE a E E A A mM A T 132 Chancing tiser settings eee R ere Ee C E es E 133 EET TE 133 Control ne ser en 133 129 Models 2603 2621 and 2635 Getting Started Guide E Command Line Interface CLI Operation Introduction The modem configuration and status can also be view and modified through the console which is accessible through the RS 232 serial port or through a Telnet session over Ethernet CLI Terminology In order to use the CLI commands you need to understand the following CLI terms Transport A transport is a layer 2 session and everything below it You can create a transport and attach it to a bridge or router so that data can be bridged or routed via the attached transport The CLI supports the following transports e PPPoE Point to Point Protocol over Ethernet Frame Relay PPP Point to Point Protocol over HDLC e Ethernet Interface bridges and routers both have interfaces A single transport is attached to a bridge or router via an interface Object an object is anything that you can create and manipulate as a single entity for example interfaces transports static routes and NAT rules List Objects are numbered entries in a list For example if you have created more than one ethernet trans port the following command ethernet list transports produces a lis
91. nance technicians Structure This guide contains the following chapters and appendices Chapter 1 on page 17 provides information about router features and capabilities Chapter 2 on page 24 contains an overview describing router operation Chapter 3 on page 27 provides initial configuration procedures Chapter 4 on page 40 describes configuring the Ethernet LAN interface e Chapter 5 on page 44 describes configuring the serial WAN interfaces Chapter 6 on page 50 describes configuring WAN services Chapter 7 on page 68 describes configuring security for the router e Chapter 8 on page 82 describes DHCP and DNS configuration Chapter 9 on page 93 describes configuring IP services e Chapter 10 on page 96 describes system configuration e Chapter 11 on page 104 describes SNTP client configuration e Chapter 12 on page 108 provides a summary of the IPLink s status webpage and status LEDs e Chapter 13 on page 112contains information on contacting Patton technical support for assistance Appendix A on page 115 contains compliance information for the IPLink routers Appendix B on page 118 contains specifications for the routers Appendix C on page 122 provides cable recommendations Appendix D on page 124 describes the router s ports Appendix E on page 129 describes how to use the command line interface CLI For best results read the contents of this guide before you install the router 13 Models 2603 2621 and 2635 G
92. ncil Directive 2004 108 EC on the approximation of the laws of the member states relating to electromagnetic compatibility and Council Directive 2006 95 EC on the approximation of the laws of the member states relating to electrical equipment designed for use within certain voltage limits The safety advice in the documentation accompanying this product shall be obeyed The conformity to the above directive is indicated by the CE sign on the device Compliance 116 Models 2603 2621 and 2635 Getting Started Guide A Compliance information Authorized European Representative DRM Green European Compliance Services Limited Avalon House Marcham Road Abingdon Oxon OX14 1UD UK Authorized European Representative 117 Appendix B Specifications Chapter contents a 119 I E E poR Lana 119 Spe Serra a 119 AC GA Sel lta es St 119 Protocol Supporte ae a nno 120 PERES POLE nn TU 120 Management E II II 120 SEGUI I RR Lin 121 Dimensions T TT T RR LORI eni 121 Rowen amd Power n eno 121 NE universal aro 121 48 VOC power ccce uem ete E 121 118 Models 2603 2621 and 2635 Getting Started Guide B Specifications General Characteristics Compact low cost router bridge 10 100 Ethernet Unlimited host support Comprehensive hardware diagnostics works with any operating system easy maintenance and effortless installation Built in web configuration Setup allows for standard IP address and unique metho
93. nd 2603 T come with a selectable T1 E1 WAN interface see figure 4 Located on the back of the IPLink the T1 and El interfaces are presented on an RJ 48C connector with selectable line impedances of 100 ohms for T1 and 120 ohms for El lines see figure 5 The 2603 K also comes with dual BNC for alternate connection to unbalanced 75 ohm El lines see figure 6 on page 30 and shall be rated for the proper application with respect to volt age current anticipated temperature flammability and CAUTION mechanical serviceability The interconnecting cables shall be acceptable for external use Crossover MDI X Ethernet WAN Ethernet connector RX RX TX IX 12345678 Figure 5 RJ 48C pinout diagram Hardware installation 29 Models 2603 2621 and 2635 Getting Started Guide 3 Initial Configuration RX connector TX connector BNC BNC Crossover MDI X Ethernet WAN WAN connector RJ 48C Ethernet connector RJ 45 amp Figure 6 Rear view of the 2603 K showing location of Ethernet and WAN connectors The interface cable has been installed go to section Installing the AC power cord on page 34 Hardware installation 30 Models 2603 2621 and 2635 Getting Started Guide 3 Initial Configuration Installing an interface cable on the IPLink 2621 s X 21 interface port The IPLink
94. nor Informational and Ignore Time the time that the last alarm occurred Count the number of instances the alarm has occurred To configure the severity of each alarm and to configure the Alarm Error Log click on Modify Alarms to reach the webpage See figure 71 Alarm Error Log Reporting Log Severity Level Major Log Alarm State enable y Update Alarm Table ID Alarm Name Alarm Severity Update Alarm 1 PP Over Threshold Major Update 2 NP Over Threshold Major v Update 3 TI E1 Loss of Signal Mejor y Update 4 TWE1 Red Alam Minor y Update 5 HIE Yellow Alarm Minor y Update Figure 71 Alarm amp Alarm Error Log configuration The Alarm Error Log can be enabled or disabled The severity level of the Alarm Log can also be configured Similarly each alarm can be set for its own severity level Remote Access The IPLink can be accessed via Telnet known as Remote Access The length of access over a remote connec tion is set on this webpage If set for zero 0 no user can access the IPLink remotely However if a user is authorized for access then the time is the limit before the remote access session is closed Remote Access From this page you may temporarily permit remote administration of this network device Enable Remote Access Allow access for 0 minutes Enable Figure 72 Remote Access Telnet access lim
95. ns are Normal and Powerdown When powered down the E1 will put high impedance on the input and output lines to protect the device set unit to Normal for regular operation Once all options have been selected click on the Configure and Activate button at the bottom of the screen Additionally save the configuration by going to the System Configuration Save menu This concludes the El interface configuration via the web browser go to section WAN Service Configuration on page 52 for instructions on router bridge and WAN service configuration WAN Serial Port Configuration 49 Chapter 6 WAN Services Chapter contents WAN Services 51 Gontiguring the lPLink 2603 for EO cce ccce er eee TI 51 S EA EET SS 51 MAN CET G TT OD 52 IA eo 52 A SO 52 PPP Bridged Remote O HT T e eee TTE 52 CCENT SI CONIARE TRU vM TI 53 Pr NS ORG RON ROL ELL Nn GNU ERU ino 54 Remote Cono nto 54 A O I M E 57 LMI Management Frame Relay ink e ee e eerte E eU T ELT 58 JPN WOK Gest ratio N ETTI OSS A a 58 Frame Relay Local Management Interface eee er er TIT Te E EE 58 A DHT EUR C UE 59 O eee eruere t RT EM eU Tet 59 Erame Rehy oe 60 ETH E Te a 61 Remote A co nin 61 Centralisme O ee cree eL E n 62 Fiame Relay Routed OO DD da 63 Remote Site Conii gurit omoose e E E E E A 63 Centrale nio e nnt 66 50 Models 2603 2621 and 2635 Getting Started Guide 6 WAN Services WAN Services Configuring the IPLink Series 2603 for El Operation Web C
96. ntiguration meat coop ot Recibe ema Puede is mad sal eu ete 86 DHCP Server subnet parameters vestir A Rae Her RR PX RH RE e ede ee 86 DEICPIPaddress pool uai rain AA AE sit e wol pF edd oA dd PUR vb A 87 Example based on default range of IP address pool 1 55 1 oeil re ara ee 88 Configuration of tha DNS server IP addresses sirio tb ia 88 DHCP server optional information example ee ess ini rs 89 DHCP Relay Webpage sois aire re rea SE ase fa id eb PV Do pens e PES 90 DHCP Relay setvet list sau carioca 91 Hyperhnk patto the DNS Relay webpage suicida EQUIPE DON pae bd REPE 91 DNS Relay configuration webpage ss piccini mre ERE RES aa Rer x eee ESS GHOSE SEES 92 DNS Relay configuration completed voca eee h pb td es peus nup hPa iba Pad pa id 92 System Services configuration web page 24260 R caves id S ERREUR PR TEE es 94 Authentication web page showing default superuser aiii or px ep eo pa 97 Creating new USER ces A o Se Xen RR Rub V ron po 98 Alarm Management Web papeu is opened Pp RR PIRE ipu bed de qe Sha Shes dada bts 98 Alarm amp Alarm Error Log configuration ss sms ieee nad tors ERT WU o RERTR ERR ERES 99 Remote Access Telnet access limit ccc cece ee RR RR RR ee 99 Updating software uc metres mee eor mere NE PER eA REE Ieee eH dpa I PR Pepe IE us 100 Save configuration changes in non volatile Memory i2 pete Ra Ree REPE EG Ree E ne 100 Saving or reloading previously saved configuration files 101 Restonno to factory defau
97. obal Address Pool button NAT Add Global Address Pool ppp 0 Add Global Address Pool Interface Type Use Subnet Configuration IP Address Subnet Mask IP Address 2 internal y Use IP Address Range y fr00100 100 01 roo100 100 02 Add Global Address Pool Figure 53 NAT Global Address Pool configuration Next create a reserved mapping between a global IP address from the global pool and a PC on the side of the internal interface ip1 In this example 10 10 19 11 5 Click on the hyperlink Add Reserved Mapping 6 Setthe parameters to the following values See figure 54 Global IP Address 100 100 100 101 nternal IP address 10 10 19 11 Transport Type all Port Number 65535 This port number means all port numbers for TCP or UDP protocols will be mapped 7 Click on Add Reserved Mapping NAT Add Reserved Mapping ppp 0 Add Reserved Mapping Port Global IP Address Internal IP Address Transport Type Number fi 00 100 100 101 Set to 0 0 0 0 to use the primary IP address of the fi 0 10 19 11 all b 55535 interface ppp 0 Add Reserved Mapping Figure 54 NAT Reserved mapping configuration The PC on the Ethernet side of the IPLink can now communicate with the public or global side through NAT Introduction to NAT 81 Chapter 8 DHCP and DNS Configuration Chapter contents A G bode eer corre ec ester Sacre err et 83 Services
98. odels 2603 2621 and 2635 Getting Started Guide C e Cable Recommendations Ethernet Cable Ethernet cable P N 10 2500 refer to RJ 45 shielded 10 100 Ethernet port on page 125 and shall be rated for the proper application with respect to volt age current anticipated temperature flammability and CAUTION mechanical serviceability The interconnecting cables shall be acceptable for external use Adapter EIA 561 to DB 9 P N 16F 561 refer to RJ 45 non shielded RS 232 console port EIA 561 on page 125 and shall be rated for the proper application with respect to volt age current anticipated temperature flammability and CAUTION mechanical serviceability i The interconnecting cables shall be acceptable for external use Ethernet Cable 123 Appendix D IPLink Physical Connectors Chapter contents RJ 45 shielded 10 100 Ethernet port Rij lt Sinon shuelded RS 232 console port BTA 56 ee ete ee eee UM UNE eee 125 Serial port I A N A E O AA I 126 MESS MA A E A E A 126 orton EI OE 127 EER senno e E a USER oO emm M t TU T 128 124 Models 2603 2621 and 2635 Getting Started Guide RJ 45 shielded 10 100 Ethernet port D IPLink Physical Connectors Assuming the MDI X switch is in the out position Table 7 Ethernet Port MDI X switch in out position Pin No Signal Name Direction 1 TX from IPLink 2 TX from IPLink 3 RX to IPLink 4 5 6 RX to IP
99. of the equipment 30 to 60 days We will add a 20 restocking charge crediting your account with 80 of the purchase price e Over 60 days Products will be accepted for repairs only RMA numbers RMA numbers are required for all product returns You can obtain an RMA by doing one of the following Completing a request on the RMA Request page in the Support section at www patton com By calling 1 301 975 1000 and speaking to a Technical Support Engineer By sending an e mail to returns patton com All returned units must have the RMA number clearly visible on the outside of the shipping container Please use the original packing material that the device came in or pack the unit securely to avoid damage during shipping Shipping instructions The RMA number should be clearly visible on the address label Our shipping address is as follows Patton Electronics Company RMAF xxxx 7622 Rickenbacker Dr Gaithersburg MD 20879 4773 USA Patton will ship the equipment back to you in the same manner you ship it to us Patton will pay the return shipping costs Warranty Service and Returned Merchandise Authorizations RMAs 114 Appendix A Compliance information Chapter contents CAMPOS 116 PMO eese R GU UTR BREUI GIUM E 116 SEI RIO IA T O 116 P R oao Eoo 116 Radio andi IV Interierence E DUET DIES 116 CED hiona Conforme e A T NUN USUS 116 AutronzedikurapeaniRepresemtatve nn n 117 Models 2603 2621 and 2635 Getting S
100. on Setup allows for standard IP address and unique method for entering an IP address and mask without requiring a console connection Default IP address of 192 168 1 1 24 Simple software upgrades obtained via FTP Front panel LEDs indicate Power WAN and Ethernet LAN speed and status Convenient and standard RJ connectors for Ethernet Line and Console Standard one year parts and labor warranty IPLink Series High Speed Routers overview 18 Models 2603 2621 and 2635 Getting Started Guide 1 General Information Ethernet Auto sensing full duplex 10Base T 100Base TX Ethernet e Standard RJ 45 connector Built in MDI X cross over switch EEE 802 1d transparent learning bridge e 2 IP address subnets on Ethernet interface Protocol support Complete internetworking with IP RFC 741 TCP RFC 793 UDP RFC 768 ICMP RFC 950 ARP RFC 826 IP router with RIP RFC 1058 RIPv2 RFC 2453 e Up to 64 static routes Built in ping and traceroute facilities Integrated DHCP server RFC 2131 DHCP relay agent RFC 2132 RFC 1542 with 8 individual address pools DNS relay with primary and secondary name server selection NAT RFC 3022 with network address port translation NAPT MultiNat with 1 1 Many 1 Many Many mapping Port IP redirection and mapping Frame Relay with Annex A D LMI RFC 1490 and FRE 12 Fragmentation PPP Support Point to point protocol over HDLC PPPoE RFC 251
101. onfiguration Launch Internet Explorer or similar web browser type the IP address of the 2603 enter username superuser and password superuser From the main page click on the TI E1 gt Configuration See figure 26 T1 E1 Configuration Configuration Options Time Slot Select 1 31 Payload Rate 1984K 31 Line Options I Channelized El G 703 G 704 y Code Sel HDB3 Line Build Out 120 Ohm X FDL Mode Fd none v Clocking Mode Receive Clock Idle Codes Enabled x Power Down Normal y Configure and Activate Figure 26 El port configuration Time Slot Select For unframed El service Clear Channel go to the Line Option parameter and select Clear Channel El G 703 For a full framed El enter 1 31 for partially filled El enter the range of timeslots using the format for example 1 2 3 5 or 1 5 10 31 Any entry for timeslots above 31 will return and invalid selection message Line Options Choose from Clear Channel E1 G 703 or Channelized E1 G 703 G 704 Consult with your service provider which option is required Line Code Choose from AMI or HDB3 Most El applications use HDB3 Line Build Out Select 120 Ohms if the El connection is made via the RJ 48C connector select 75 Ohm if the El connection is made via the dual BNC connectors FDL Mode FDL is a T1 application therefore select Fdl none for El applications Clocking Mode Options are Internal or R
102. path gt Services Configuration in the Configu ration Menu gt LAN gt Change default LAN port IP address button on the main window The Basic and Advanced Port Attributes of the Ethernet LAN port is found by clicking on the Ethernet hyper link in the IPLink s Configuration Menu the narrow window on the left hand side of the web page Clicking on the View advanced attributes hyperlink leads to a webpage with only a few parameters that could be of interest They are for controlling auto negotiation 100BaseT mode and Full duplex mode LAN Connections The default LAN port s IP address and netmask can be changed on this webpage Go to gt Services Configura tion in the Configuration Menu gt LAN gt Change default LAN port IP address button on the main window See figure 17 The primary IP address and mask can be modified here but if you do you will no longer be able to access the IPLink s webpages with the previous IP address The interface associated with the Ethernet is named ip1 You can also configure a secondary IP address to the Ethernet LAN port LAN connections This page allows you to change the IP address for the default LAN port The name of the IP interface is ip1 Default LAN Port The Secondary IP Address should be on the same subnet as the Primary IP Address and uses the same Subnet Mask Addresses on other subnets can be added using Virtual Interfaces Primary IP Address IP Address
103. ports ID Name Port Another example shows when the user must provide a parameter gt ip list clear add delete set attach attachbridge detach show interface ping gt ip interface lt name gt The name of the interface In this instance the interface name is ipl It is important that you do the inquiry to determine whether additional parameters follow gt ip interface ipl 7 add delete clear list gt ip interface ipl list secondaryipaddresses gt ip interface ipl list secondaryipaddresses CLI Terminology 131 Models 2603 2621 and 2635 Getting Started Guide E Command Line Interface CLI Operation ip interface ipl list secondaryipaddresses lt enter gt Secondary IP addresses for interface 101 ID IP Address In this example there was not a secondary IP address Now save the entire configuration in nonvolatile FLASH mem ory with the following command system config save Wait for the message that says Configuration Saved then reboot the modem with this command gt system restart Administering user accounts As admin user you can administer user accounts This section summarizes the CLI commands which can be used to administer user accounts Adding new users To add a new user username use the command system add user lt username gt lt Conment gt system add login user lt username gt lt Comment gt The first command creates a user who
104. r 2 Enter 1 for ICMP in the Protocol Number field 3 Set both Inbound and Outbound for Allow See figure 50 4 Clickon Create Firewall Add Raw IP Filter external internal Direction Protocol Number FR Create Inbound Outbound Allow y Figure 50 Defining ICMP port filter for ping You can now ping between the two networks Security Triggers Security triggers are used to allow an application to open a secondary port in order to transport data The most common example is FTP This procedure sets up a trigger on the Firewall to permit an FTP session from PC A to PC B but not the reverse 1 First create an outbound only portfilter for FTP and add it to the itemO policy 2 Following the path given in step 1 for the ping portfilter in the previous section click on Add TCP Filter 3 The Port Range is entered as 21 for both Start and End Security Triggers 75 Models 2603 2621 and 2635 Getting Started Guide 7 Security 4 Set Inbound as Block but Outbound as Allow See figure 51 5 Click on Create Firewall Add TCP Port Filter external internal Transport Port Range Direction Type Start End Inbound Outbound he ir ea a Figure 51 Configuring TCP port filter for FTP After configuring the FTP portfilter you can open an ftp session from Remote to Local however you can issue ftp commands e g login cd etc Because the trigger to permit transf
105. r Consult with your service provider for the DLCI number required Encapsulation Method Defines the REC1490 encapsulation type that will be used by the channel Choose the encapsulation method best suited for your network needs from the following options Routed IP default value Raw WAN IP address Enter the IP address assigned to the WAN port V 35 X 21 or T1 E1 WAN Service Configuration 66 Models 2603 2621 and 2635 Getting Started Guide 6 WAN Services Enable NAT on this interface In this example leave this option blank Click the Create button 5 6 Goto System Configuration gt WAN gt Edit for Frame Relay Routed service gt Edit TP Interface 7 Enter the WAN IP Address in this example 192 168 164 3 and click on the Create button 8 From the IP Interface web page click on Edit Frame Relay then click on Edit Frame Relay Channel Edit Frame Relay Channel Enter the appropriate information in the following fields e Dci Consult with your service provider for the DLCI number required in this example use 45 Encapsulation Method Defines the RFC1490 encapsulation type that will be used by the channel Chose the encapsulation method best suited for your network In this example enter Routedlp RX Max PDU Enter the number of receive side max PDU in this example it is the default 8192 TX Max PDU Enter the number of transmit side max PDU in this example it is the d
106. r IP addresses that the DNS relay can forward DNS queries to Edit DNS server list Use this section to edit existing DNS server addresses present in the DNS relay s list The first address should be the Primary DNS server and the second address should be the Secondary DNS server You cannot have more than two addresses at a time DNS server IP address Delete fio fio fi fio ri fio fio fi f fin Luni Update Reset Figure 66 DNS Relay configuration completed Introduction 92 Chapter 9 IP Services Chapter contents IHE OOO OTRO ee O Aa da Nasa E di UENIRE ENS 94 WEB Servet aos 94 A OO t 94 Associated Pors RIMOSSO A AEA EE OTT 95 93 Models 2603 2621 and 2635 Getting Started Guide 9 e IP Services IP Services Certain System Services can be enabled or disabled They are DNS Relay FTP TFTP SNMP and the WEB Server The importance of disabling any of these services is an issue of security If you are not using a particular service it is best to disable it By disabling it the associated port is not active which means it is not available to abuse with the intent of unauthorized access IP Services This allows the user to e System Services DNS Relay Enabled FTP Enabled y TFTP Enabled y SNMP Enabled y WEB Server Enabled Update Figure 67 System Services configuration web page WEB Server The System Service which must be wisely disabled is the WEB Server
107. ration Parameters If you are not accessing an SNTP server you can con figure the system clock for a calendar clock setting Configuring the SNTP Client The SNTP Client Mode Configuration Parameters section is for selecting the synchronization mode and entering the IP address of the SNTP Server With the SNTP Client General Configuration Parameters sec tion you will select the time zone and set the transmit packet timeout period retries and polling period SNTP Client Mode Configuration Parameters In this section you configure the synchronization mode and enter the IP address of the SNTP server The IPLink supports three synchronization modes unicast mode anycast mode and broadcast mode Unicast is a point to point mode Anycast is a multipoint to point mode Broadcast mode is for use when the SNTP server is on the local network that is the same subnet as the IPLink When Unicast mode is enabled the IPLink sends a request to the server designated in the field containing the SNTP server IP address See figure 81 This is a point to point communication link The IPLink requests from one server The server sends the timing information directly to the IPLink When disabled the IPLink does not send any requests to any SNTP Server In Broadcast mode the synchronization is with an SNTP server on the local network Since routers do not for ward broadcast IP addresses the SNTP server and IPLink must be on the same subnet
108. ration for configuring the modem see Web Operation and Configura tion on page 37 What you will need IPLink Series High Speed Router Ethernet cable with RJ45 plugs on each end included with router DB9 RJ45 adapter included with router e RJ45 RJ45 straight through cable for connecting to control port included with router e PC computer with Hyper Terminal or equivalent V 1 100 emulation program or an ASCII terminal also called a dumb terminal capable of emulating a V 1 100 Interface cable installation An IPLink Series router comes with a T1 E1 WAN V 35 or X 21 interface Refer to the appropriate section to install an interface cable on your IPLink router and shall be rated for the proper application with respect to volt age current anticipated temperature flammability and CAUTION mechanical serviceability The interconnecting cables shall be acceptable for external use e Model 2603 router see Installing an interface cable on the IPLink 2603 s T1 E1 interface port on page 29 Model 2621 router see Installing an interface cable on the IPLink 2621 s X 21 interface port on page 31 Model 2635 router see Installing an interface cable on the IPLink 2635 s V 35 interface port on page 33 Hardware installation 28 Models 2603 2621 and 2635 Getting Started Guide 3 Initial Configuration Installing an interface cable on the IPLink 2603 s T1 E1 interface port The IPLink Models 2603 K a
109. recare nie eee nie e tenens tn sierica nio neseeienie nere nee nese nio neceeie nie necenionecenne 124 RJ 45 shielded 10 100 Ethernet port e 125 RJ 45 non shielded RS 232 console port EIA 561 ie 125 NN 126 1 35 M 34 and DB 25 Connector inne m drin oit iaia 126 X21 DB Connector isa 127 EITI RJ48C Connector aereas 128 E Command Line Interface CLI Operation cmoonoccononnonnonnononncnncnnonacanonnononanononnonnonnon enen 129 irre r S 130 CET Terminology estacion RI Oo ei ee ERE uit RI PRO Hee 130 Local VT 100 emulation diia 130 Remote SES MEE REOR ERI a RS PD OR RR 130 Using the Consoles iii nia P 130 Administering user aCcOURts oi ee rele ERR RH EE LIRE e utes tace tete EH da esto reinen 132 Adding new users o asses t canoe ri 132 Setting SEE passwords leais 132 Changing User Settings iii ria 133 Controlling login access oc it 133 Controlling User acces me teet et e ER er re I b PORE eH EDAD Re EP REA ERES HIR bs 133 List of Figures cod CV M KR WON e me ds ds ds HR AB BR DY UU QU LM Q LM Y Y b2 N NN NN M KM b LA a Ka Kah hhh ns NX OV d 0 NH SO CON AM VIN Sv CON GN KD EM NH DOAN GN Mh E U No HRES Senes Router ELT Gab T eee nt 20 SS A OI 26 TUEL Application RT ne TATE oe a 26 Rear View of the 2603 T showing location of Ethernet and WAN connectors LL 29 RJ ASC pinout MA ot onice enne ar 29 Rear view of the 26
110. rranty coverage nin ai 113 Out of watranty Ci iii 114 Returns for credit sii ella 114 Return for credit policy israeliana 114 RMA numbers criada 114 Shipping instructions MO 114 Compliance information RR zioneneee 115 Compliance ninia ae a Lain 116 EMG iti AAA 116 Nic rodadas A ia EE 116 PSTN Regulatory rsa dalai E ARAN ani i 116 Radio and TV Interference FCC Part 15 116 GE Declaration of Conformity pire alia ariana 116 Authorized European Representative erred ee ire rette P Ire ii toas 117 A loin iris 118 General Characteristics cerei pie UR Ip Cree dein Li alata n E eS 119 Dn d 119 Syne H risi MH Rm 119 Models 2603 2621 and 2635 Getting Started Guide Contents TW ET Interface uni dd 119 Protocol Support inicio 120 PPP Suppotta NN 120 Management ONO 120 Mei E E 121 In MP M EES 121 Power and Power Supply Specifications redet tendent dg rine e DCE QUE tente ee Pee ee ewe 121 AC universal power Supply eerte etel idalinlai ltda 121 48 VDC power supply nina tilde ee EU DEI RE Red 121 JEU nn 122 Ethernet Cabless hatte dettes in 123 aucem asa as a 123 D IPLink Physical Connectors e eeeeeeee ce rie
111. rting please wait for several seconds to let the system come up If you would like to reset all configuration to factory default settings please check the following box Restart Figure 76 Restoring to factory defaults Website Settings The refresh rate of the webpages is a configurable parameter Enter the desired refresh rate in seconds and click on the Update button Default value is 4 seconds See figure 77 Website Settings Refresh Rates Refresh Rate 4 seconds Update Figure 77 Webpage refresh rates Restart 101 Models 2603 2621 and 2635 Getting Started Guide 10 System Configuration Error Log The Error Log webpage shows recent configuration errors and provides for the configuration of the Syslog See figure 78 Two parameters are configurable for the Syslog Syslog Host enter the IP address of the Syslog Default 0 0 0 0 e Syslog Facility select the type of syslog facility Default disabled s Click on the Update button to activate the selected parameters Default value is a disabled Syslog Error log This page shows recent configuration errors from your router Syslog Settings Syslog Host 0 0 0 0 Syslog Facility disable y Update Error log most recent errors last times are in seconds since last reboot When Process Error 1072915200 im imcInvalid argument failed to set the SNTP host to 1072915201 alarm alarm Box State Change to Minor
112. s location of DTE DCE daughter board 4 DCE 4 Y 310 Y In this example the DCE DTE strap is X 21 connector configured for DCE because the DCE label on the strap is pointed toward the X 2 connector Figure 9 Location of DTE DCE board 3 The DTE DCE daughter board is installed at the factory with the DTE label and arrows pointing towards the X 21 connector DTE configuration To change to DCE configuration lift the daughter board from the connector turn it around so that the DCE label an arrows point to the X 21 connector and place it back on the connector The X 21 port is now configured as a DCE Note When the X 21 port is configured as a DTE the clocking mode for the port must be set for external clock Hardware installation 32 Models 2603 2621 and 2635 Getting Started Guide 3 Initial Configuration 4 Re assemble the case The interface cable has been installed go to section Installing the AC power cord on page 34 Installing an interface cable on the IPLink 2635 s V 35 interface port The IPLink Model 2635 comes with a V 35 interface presented on a DB 25 female connector see figure 10 and shall be rated for the proper application with respect to volt age current anticipated temperature flammability and CAUTION mechanical serviceability
113. se false false true false Figure 20 Configurable Ethernet parameters 43 Chapter 5 Serial Port Configuration Chapter contents WAN Serial Dari Con emanon oras ra ao doado uem e de cues ue errem ee uu nue eT rect ee eee 45 Serial interac a E A E E A E EE ER 45 Variables a a E E A E A E RO UTI a 45 Webleren oe een EP IR ME 46 TAB Interface ITH een 46 Gontigurme rhe Blin Series 2009 T0 t IU pera nn nno 47 ST ec cc e e aera TEE 47 Contiene Ple fonk LO pera nn 48 Web ecc me eer Te IUe UIT 48 44 Models 2603 2621 and 2635 Getting Started Guide 5 Serial Port Configuration WAN Serial Port Configuration The IPLink Series routers use a sync serial interface X 21 V 35 or a T1 El interface for connection to stan dard WAN services Below are the configuration options for the WAN interface Serial Interface The serial interface configuration menus allow the user to configure the serial interface for HDLC based con nections Variables The following table lists variables that are configurable on the IPLink s software Variable Options Function Clock Mode Internal The clock setting for the serial interface will determine the External source of timing for the serial interface only RX Clock Invert Inverted The clock invert functions could be used to invert the clocks TX Clock Invert that are used on the serial interface It is not recommended to Normal change this parameter unless requested
114. sistance on page 112 to find out how to replace it with a compatible power cord 4 Connect the male end of the power cord to an appropriate power outlet Verify that the green Power LED is lit see figure 13 Unplug the AC power cord from the IPLink Series router to power down the unit Hardware installation 35 Models 2603 2621 and 2635 Getting Started Guide 3 Initial Configuration Model 2603 ipLink Gateway High Speed WAN Access Router et KEE SMe 7 6009 0000 L wan L Ethernet Console Power Y So Leo WAN Link WAN TD Ethernet Ethernet Tx Ethernet Rx Console LED LED Link LED LED port WAN Frame WAN RD EP Ethernet LED LED 100M LED Figure 13 IPLink front panel LEDs and Console port locations Model 2603 shown Installing the Ethernet cable Do the following and shall be rated for the proper application with respect to volt age current anticipated temperature flammability and CAUTION mechanical serviceability The interconnecting cables shall be acceptable for external use 1 Connect the DB9 RJ45 adapter to the DB 9 serial port on the PC or dumb terminal Use the RJ45 RJ45 straight through cable between the adapter and the red marked RJ45 port on the IPLink Router 2 Do not connect the router to the Ethernet LAN at this time 3 On the PC start a terminal emulation session such as Tera Term or Hyper Terminal at 9600 bps 8 data bits 1 stop bit and no parity 4 Plug
115. ss the configuration and status of the alarms Alarm Management This page shows the table of alarms reported by the device Modify Alarms Alarm State No Alarms Alarm Error Log Reporting Log Severity Level Major Log Alarm State Enabled Alarm Table ID Alarm Name Alarm Severity Time Count Generate Clear Active Reset Alarm Condition Alarm 1 PP Over Threshold Major 00 00 00s D Generate Clear Reset 2 NP Over Threshold Major 00 00 00s 0 Generate Clear Reset 3 T1 E1 Loss of Signal Major 00 00 00s D Generate Clear Reset 4 TI E1 Red Alarm Minor 00 00 00s Generate Clear Reset 5 TU E1 Yellow Alarm Minor 00 00 00s 0 Generate Clear Reset Figure 70 Alarm Management web page ALL Alarms ALL Alarms All IPLinks have the PP over Threshold and NP over Threshold alarms The Model 2603 has additional alarms for the T1 E1 WAN port An alarm can be tested by clicking on the Generate button Similarly by clicking on the Clear button the alarm is cleared that is turned off however the Time and Count parameters Alarm 98 Models 2603 2621 and 2635 Getting Started Guide 10 lt System Configuration remain Only by clicking on the Reset button can you clear the alarm and reset the Time and Count parame ters The parameter definitions are e Alarm Severity there are five categories of severity Critical Major Mi
116. t of numbered transport objects ID Name Port 1 eth2 ethernet 2 ethl ethernet Local VT 100 emulation A connection is made with the DB9 RJ45 adapter and an RJ45 RJ45 straight through cable Set the data rate to 9 600 baud 8 data bits one stop bits and no parity You may use a dumb terminal or a VI 100 emulation such as HyperTerminal Remote Telnet Establishing a Telnet session displays the same CLI configuration and status parameters on the display Using the Console The console commands needed for the various modes of operation are described in later sections In this sub section are the most basic commands needed for console operation By entering all the high level commands the keywords are seen Introduction 130 Models 2603 2621 and 2635 Getting Started Guide E Command Line Interface CLI Operation By entering a keyword followed by a space and the options available will print immediately without press ing enter The previously entered commands are reprinted on the next lines For example gt ethernet After typing the you will not see the add delete set show list clear gt ethernet Then you may enter one of the keywords on the displayed list followed by a space and To continue our example gt ethernet list ports transports gt ethernet lis u gt etherne transports n gt etherne transports lt enter gt Ethernet trans
117. tarted Guide A Compliance information Compliance EMC e FCC Part 15 Class A EN55022 Class A EN55024 Safety UL60950 1 CSA C22 2 No 60950 1 EC EN 60950 1 e AS NZS 60950 1 PSTN Regulatory These devices are not intended for connection to the PSTN Radio and TV Interference FCC Part 15 This equipment generates and uses radio frequency energy and if not installed and used properly that is in strict accordance with the manufacturer s instructions may cause interference to radio and television recep tion This equipment has been tested and found to comply with the limits for a Class A computing device in accordance with the specifications in Subpart B of Part 15 of FCC rules which are designed to provide reason able protection from such interference in a commercial installation However there is no guarantee that inter ference will not occur in a particular installation If the equipment causes interference to radio or television reception which can be determined by disconnecting the cables try to correct the interference by one or more of the following measures moving the computing equipment away from the receiver re orienting the receiving antenna and or plugging the receiving equipment into a different AC outlet such that the computing equip ment and receiver are on different branches CE Declaration of Conformity We certify that the apparatus described above conforms to the requirements of Cou
118. tection System IDS 79 Models 2603 2621 and 2635 Getting Started Guide 7 Security Introduction to NAT The basic steps for configuring NAT are 1 Enable NAT between the internal and external interfaces of the firewall 2 Create global addresses which will be added to the global pool of IP addresses on the WAN interface 3 Create a reserved mapping between a global IP address and the IP address of an internal PC A Global Address Pool is a pool of addresses seen from the outside network Each external interface creates a Global Address Pool with a single address the address assigned to that interface For outbound sessions an address is picked from a pool by hashing the source IP address for a pool index and then hashing again for an address index For inbound sessions it is necessary to create a reserved mapping A reserved mapping is used so that NAT knows where to route packets on inbound sessions The reserved map ping will map a specific global address and port to an inside address and port Reserved mappings can also be used so that different inside hosts can share a global address by mapping different ports to different hosts For example Host A is an FTP server and Host B is a web server By mapping the FTP port to Host A and the HTTP port to Host B both insides hosts can share the same global address Setting the protocol number to 255 OxFF means that the mapping will apply to all protocols Setting the port number to 655
119. terfacecable onsthe IPLink 2603s DI ET interface port eee 29 Installing anuntertace cable onthe IPLink 2621s X 21 ntedace port eL RESET 31 Installing an mtertaceicable on the IPLink 2635 5 Ot port 0 S eee renee eee 33 Installine the AC power cord ote rocas TUM Ie UN m ET UE 34 dnstallinesthesEtherpetcabloe O ec m dE een ea ner ne eee 36 IP address modification ron na 37 Web BeroncndiGonieurdtion ee eret eT M te 37 IEA Goya at Re oo I o 37 WebiBrowsep nno no 37 27 Models 2603 2621 and 2635 Getting Started Guide 3 Initial Configuration Hardware installation If you are already familiar with IPLink Series Router installation and configuration this chapter will enable you to finish the job quickly Installation consists of the following Preparing for the installation see section What you will need Installing the T1 E1 WAN X 21 or V 35 interface cable see section Interface cable installation Hooking up network cables verifying that the unit will power up and running a HyperTerminal session see section Installing the Ethernet cable on page 36 and shall be rated for the proper application with respect to volt age current anticipated temperature flammability and CAUTION mechanical serviceability The interconnecting cables shall be acceptable for external use Changing the IP address from the factory default setting see section IP address modification on page 37 Launching a web browser in prepa
120. ternal or external power supply This section describes installing the power cord into the IPLink router Do the following and shall be rated for the proper application with respect to volt age current anticipated temperature flammability and CAUTION mechanical serviceability The interconnecting cables shall be acceptable for external use Note Do not connect the other end of the power cord to the power outlet at this time l Ifyour unit is equipped with an internal power supply go to step 2 Otherwise insert the barrel type con nector end of the AC power cord into the external power supply connector see figure 12 2 Insert the female end of the AC power cord into the internal power supply connector see figure 12 Hardware installation 3A Models 2603 2621 and 2635 Getting Started Guide 3 Initial Configuration Internal power supply connector Power External power supply connector N Figure 12 Power connector location on rear panel Model 2603 T shown The IPLink router power supply automatically adjusts to accept A an input voltage from 100 to 240 VAC 50 60 Hz CAUTION Verify that the proper voltage is present before plugging the power cord into the receptacle Failure to do so could result in equipment damage 3 Verify that the AC power cord included with your IPLink router is compatible with local standards If it is not refer to chapter 13 Contacting Patton for as
121. the IPLink 2 On the Menu go to Services Configuration then to WAN Delete the factory default WAN services already defined 3 Click on Create a new service in the main window select Frame Relay bridged and click on Continue WAN Service Configuration 62 Models 2603 2621 and 2635 Getting Started Guide 6 WAN Services 4 Enter the description for the circuit in the Description field This is a mandatory field Without a descrip tion you cannot create a WAN service 5 Click on Create a new service in the main window select Frame relay bridged and click on the Configure button 6 Click along the following path Services Configuration gt WAN gt Edit Then click on Edit Frame Relay Channel The configurable parameters are DICI Consult with your service provider for the DLCI number required Encapsulation type Bridged Ether Defines the REC 1490 encapsulation type to be used by the channel In some instances you may need to choose another type Consult your service provider RX Max PDU 8192 Receive side max PDU default 8192 normally not changed from default TX Max PDU 8192 Transmit side max PDU default 8192 normally not changed from default Channel segment size The channel segment size is used to define fragmentation of the packets based on the Frame Relay Forum IA FRE 12 If this variable is set to 0 then FRE 12 Frame Relay Fragmentation will be disabled if set to any other valu
122. thing below it Creating a transport and attaching it to a bridge or routers interface enables data to be bridged or routed The supported transports are PPPoE Frame Relay PPPoH and Ethernet Configuring an interface and transport for the router or bridge requires naming the interface and transport before attaching them When using the built in HTTP server web browser this is done automatically But when config uring The IPLink Series router via CLI commands through the RS 232 control port it must be done manually Introduction 25 Models 2603 2621 and 2635 Getting Started Guide 2 Product Overview Applications Overview Patton s IPLink Gateway routers deliver all the advanced features for secure reliable and high speed Internet data connections They combine ease of use with powerful data routing to make shared Internet connectivity simple and easy With NAT support the IPLink routers offer convenient and economical operation by using a single IP address while the integrated DHCP server automates IP address assignment for connected LAN computers Security is standard with built in firewall and violation alerting features that protect the network from would be intruders as eno 4 7 Figure 2 Sync Serial Application 2603 IPLink Figure 3 T1 E1 Application Applications Overview 26 Chapter 3 Initial Configuration Chapter contents Ad A A 28 What you will need RO 28 I TT T TET A 28 Installing an 15
123. tional T1 El services The Model 2621 is equipped with DTE DCE user configurable X 21 interface The Model 2635 equipped with a V 35 interface presented on a female DB 25 connector and a cable to convert to an M34 E The IPLink routers provide selectable bridging or routing functionality along with advanced IP features such as NAT NAPT Firewall and DHCP A complete set of configurable PPP IP FR WAN protocols allow a wide range of choices when connecting branches via common WAN services The IPLink routers boast easy installa tion offering Console VT 100 Telnet HTTP and SNMP management options The following sections describes the IPLink series features and capabilities General attributes see section General attributes Ethernet see section Ethernet on page 19 Protocol support see section Protocol support on page 19 PPP support see section PPP Support on page 19 Management see section Management on page 19 e WAN interface see section WAN Interfaces on page 19 Security see section Security on page 20 Front panel status LED see section Front Panel Status LEDs and Console Port on page 20 General attributes Compact low cost router bridge 10 100 Ethernet Comprehensive hardware diagnostics Easy maintenance and effortless installation e Plug and Play operation for fast and seamless turn up with pre configured WAN and LAN options Built in web configurati
124. to the WAN services defined on the serial port PPPoE Status the connection authentication status is available when the PPPoE WAN service is configured and activated Hardware Status shows the time that the IPLink has been operating the current time software version and a link to configure the time including the SNTP client Defined Interfaces provides links to statistics for the defined interfaces Status Port Connection Status Port Type Connected Line State Ethernet ethernet Y N A LAN Status Local IP Address 10 10 19 10 LAN Settings Q LAN Subnet Mask 255 255 0 0 Act as Local DHCP Server No DHCP Serer Settings y MAC Address 00 40 B4 00 5D 9C WAN Status IP Address Type Static IP Address Settings y WAN Subnet Mask None Default Gateway 192 1 1 4 Primary DNS None DNS Client Settings y PPPoE Status Connection Authentication None Hardware Status Up Time 00 44 46s Current Time Wed 31 Dec 2003 19 44 37 Set Time Version OP Image Software Revision 2 6 3 Kernal 8 2 0 37 Jan 13 2006 Defined Interfaces fr rtd Show Statistics q eth Show Statistics O Figure 84 System Status subsystems summary Port Connection Status The Ethernet link goes to the Ethernet Port Configuration webpage This is the same webpage accessed by clicking on the Ethernet menu item in the Configuration Menu Connected indicates whether the Ethernet port sees a received signal System
125. troduction to NAT ie 80 Enabling d dee 80 Global address pool and reserved map aa E aa 80 DHCP and DNS Configuration eeeeeeee eee re rire eee zone ee zio Stri tn nio nio nin one senten nie ezin zio zio nio nio nioezeo 82 Introduction t toner ree ed ee ret et ii 83 Services and features normally associated with each other sees 83 DHCP Server m 84 Parameters for the DHCP Server subnet i 86 IP Addresses to be available on this subnet ii 87 DNS server option information zc HR alia E edet 88 Default gateway option information i 89 Additional option information viii e de be te i eee PEE HE E AR ee tienen 89 DHCP Relay vito c 89 Config rati n of the DHCP Relay incaico rer ode E Hear tn 89 DNS Relay rosoinen eE oae paired it id 91 Configuring the DNS Relay retirer rette Feier meer ere cedet nut ina 91 IP Services secas ucessrsa 93 A e dae aT 94 WEB c a T 94 GLI Configuration iaia otia ene asa 94 Associated Ports for the different System IP Services sese 95 AGES Vario 96 Introduction aa 97 ROS 97 Alt catala 98 Remote Accessi
126. trusion Detection Ibsen eno 78 A AE 80 Enabling e ccce e MT HUM E Ue 80 Global addiess pool andireserved mapa 80 68 Models 2603 2621 and 2635 Getting Started Guide 7 Security Introduction Security provides the ability to setup and enforce security policies The policies define the types of traffic per mitted to pass through a gateway either inbound outbound or both and from which origins the traffic may be allowed to enter Within the security configuration is a stateful firewall A stateful firewall utilizes a security mechanism to main tain information concerning the packets it receives This information is used for deciding dynamically whether or not a packet may pass through Port filters are rules that determine how a packet should be handled The rules define the protocol type the range of source and destination port numbers and an indication whether the packet is allowed or not Security triggers are used with applications that require and create separate sessions The most common exam ple is FTP An FIP client establishes a connection to a server using port 21 but data transfers are done on a separate connection or port The port number and who makes the connection can vary depending on the FTP dient To allow FTP to work without triggers you would need to set up port filters allowing the correct port numbers through This is a significant security risk This risk can be avoided by using security triggers Trigg
127. tton DON gt p Seeing the green check mark under Valid indicates the IP addresses of the WAN service and the gateway are properly configured See figure 43 Edit Routes Existing Routes Valid Destination Gateway Netmask Delete v 0 0 0 0 192 168 101 2 0 0 0 0 D Update Reset Figure 43 Valid gateway route Configuring the security interfaces The interfaces and routes have been configured on the IPLink Router The Ethernet side of the IPLink router will be configured to be an internal interface and the WAN side is selected to be the external interface since it is on public side of the modem connection 1 Go to the Security Interface Configuration webpage as follows Configuration Menu gt Services Configu ration gt Security See figure 44 Configuring the security interfaces 71 Models 2603 2621 and 2635 Getting Started Guide 7 Security Security Interface Configuration Security State Security C Enabled Disabled Firewall Disabled Intrusion Detection Enabled Disabled Change State Security Level Security Level n a Enable Firewall to set level Security Interfaces There are currently no Interfaces defined Interfaces must be defined and Security enabled to configure NAT Add Interface y Policies Triggers and Intrusion Detection Security Policy Configuration O a Q Why cant configure this A Why cant I configure this Figure 44 Security
128. u can complete the configuration using any standard web browser PC Configuration In order to connect the PC to the Ethernet LAN to communicate with The IPLink Series router the PC s IP address should be on the same subnet as the router Connect a straight through Ethernet cable between the PC s NIC or PCMCIA Ethernet card and an Ethernet hub or switch Web Browser Do the following 1 Launch a standard web browser such as Netscape Communicator or Internet Explorer IE Hardware installation 37 Models 2603 2621 and 2635 Getting Started Guide 3 Initial Configuration 2 Enter the IPLink routers IP address into the URL or Address field of the browser To see the IPLink Series router home page refer to the following Figures Model 2603 is shown in figure 14 Model 2621 in figure 15 Model 2635 in figure 16 Patton Electronics Company 2603 Single Port Router Software Revision 2 6 3 Jan 13 2006 Status of 2603 Single Port Router Local IP Address 10 10 19 10 PP CPU Usage 1 NP CPU Usage 1 Up Time 01 58 50 Current Time Wed 31 Dec 2003 20 58 41 Figure 14 Model 2603 home page Patton Home Page o Home Patton Electronics Company 2621 Single Port Router Software Revision o System Status 2 6 3 Jan 13 2006 gt System Configuration gt Services Configuration o Ethernet V Serial Status of 2621 Single Port Router Local IP Address 10 10 19 20 PP CPU Usage 1 Co
129. u to set up a new DHCP server subnet so that the system can assign IP address subnet mask and option configuration parameters to DHCP clients Parameters for this subnet Define your new DHCP subnet here If you do not wish to specify the subnet value and subnet mask by hand you may instead select an IP interface using the Get subnet from IP interface field A suitable subnet will be created based on the IP address and subnet mask belonging to the chosen IP interface Subnet value L Subnet mask M JJ An Get subnet from IP interfac none Maximum lease time 86400 seconds Default lease time 43200 seconds IP addresses to be available on this subnet You need to make sure that the start and end addresses offered in this range are within the subnet you defined above Alternatively you may check the Use a default range box to assign a suitable default IP address poo on this subnet Start of address range End of address range Use a default range Vv DNS server option information Enter the addresses of Primary and Secondary ONS servers to be provided to DHCP clients on this subnet You may instead aliow DACP server to specify its own IP address by clicking on the Use local host address as DNS server checkbox Primary DNS server address i Secondary DNS server address L L Use local host address as DNS server r Default gateway option information Use local host as default gateway iv Create Reset Figure 56 D
130. upply connects to an external source providing 5 VDC via a barrel type connector 48 VDC power supply The DC power supply connects to a DC source via a terminal block Rated voltage and current 36 60 VDC 400 mA cally isolated from the AC source The 36 60 VDC source is to be reliably connected to earth Connect the equipment to a 36 60 VDC source that is electri CAUTION Ethernet port outlined in green Shielded RJ 45 10Base T 100Base TX Ethernet port using pins 1 2 3 82 6 See MDI X switch for hub or trans ceiver configuration The following table defines conditions that occur when the MDI X switch is in the out position Signal Signal Direction Name Pin No 1 Output TX 2 Output TX 3 Input RX 4 E E 6 Input RX 7 E 8 MDI X The MDI X push switch operates as follows When in the default out position the Ethernet circuitry takes on a straight through MDI configuration and functions as a transceiver It will connect directly to a hub When in the in position the Ethernet circuitry is configured in cross over MDI X mode so that a straight through cable can connect The IPLink Series routers Ethernet port directly to a PC s NIC card IPLink Series High Speed Routers overview 22 IPLink Series High Speed Routers overview 23 Chapter 2 Product Overview Chapter contents O i EE 25 Application venice eu II 26 24 Models 2603 2621 an
131. ure 83 is set for January 26 2006 at 1 57 50 pm System Clock Setting 106 Models 2603 2621 and 2635 Getting Started Guide 11 SNTP Client Configuration Clock Setting Set the system clock yyyy mm dd hh mm ss format 2006 01 26 13 57 50 Set Clock Figure 83 Configuration of the internal system calendar clock After entering the system clock values click on the Set Clock button to save in volatile memory If the IPLink is rebooted either soft or by power cycling the Clock Setting returns to its default value System Clock Setting 107 Chapter 12 System Status Chapter contents O SEACUUS cas conto eere e eed TITTEN NU UTUNTUR TENUES EE 109 Port ConnectioniStatst ae mee eI IUS RR Tnt 109 IRNERIO n 110 NUN Stats ere RO ONU URS UO EEUU MUNERE 110 Llandware Status NT ERNEUT 110 ISS DEE SR 110 A eee nn nn 111 108 Models 2603 2621 and 2635 Getting Started Guide 12 System Status System Status A quick but thorough summary of the IPLink s status is provided on this webpage but it also has links to the detailed webpages for the key subsystems of the IPLink The webpage is divided into six 6 sections Port Connection Status connection status of the Ethernet port and a link to the Ethernet Port Configura tion webpage LAN Status displays the local IP address on the Ethernet port the MAC address and links to the LAN con nections and DHCP Server web pages e WAN Status parameters and links
Download Pdf Manuals
Related Search
Related Contents
取扱説明書-HH-50A Trident TR-STD-SPLT-BG MH100 Leeb Hardness Tester User`s Manual Samsung BD-P1000 User Manual プリッセ木製ブラインド取扱説明書 Da-Lite Contour Electrol 20150923_AP700 APP_user manual Pelco DVR5100 User's Manual Installation and operating instructions Copyright © All rights reserved.
Failed to retrieve file