No part of this publication may be reproduced in any form or by any means, whether
electronic, mechanical, photocopying, or recording without the written consent of OvisLink
Corp.
OvisLink Corp. has made the best effort to ensure the accuracy of the information in this
user’s guide. However, we are not liable for the inaccuracies or errors in this guide.
Please use with caution. All information is subject to change without notice.
All Trademarks are properties of their respective holders.
The RS-2500 is powered by a powerful IXP425 533 MHz RISC processor, and increased of
memory capacity in order to make the performance better. Furthermore, it also provides
Web VPN/ SSL VPN Sever function, so remote users can easily connect to IPSec server by
using IE browser and access LAN resource.
Meanwhile, RS-2500 is also improved IM/P2P Blocking function, so it is not just able to
block IM and P2P program, the new Application Blocking is promoted to support the
blocking of Video/Audio Application, Webmail, Game Application, Tunnel Application, and
Remote Control Application. With omnibus advanced security function makes RS-2500 to
be an outstanding Security VPN Gateway than before.
1.2 How to Use This Guide
RS-2500 is an advanced VPN Security Gateway with many functions. It is recommended
that you read through the entire user’s guide whenever possible. The user guide is
divided into different chapters. You should read at least go through the first 3 chapters
before attempting to install the device.
Chapter 1 Introduction: This chapter is an introduction about the user’s manual.
It can help your to know the chapter’s contents, and how to get help from AirLive
Tech Support.
Chapter 2 Installing the RS-2500: This chapter is about hardware installation.
You should read through the entire chapter.
Chapter 3 Configuring the RS-2500: This chapter is the basic information
about preparation before you access RS-2500. It also includes the basic but
important information of RS-2500.
Chapter 4 Web Management: This chapter explains how to access RS-2500 via
web console.
1 AirLive RS-2500 User’s Manual
1. Introduction
Chapter 5 Administration: In this chapter, you can know how to create a
sub-admin account, change password, and upgrade firmware.
Chapter 6 Configure:
6.1 Setting: You can backup or restore RS-2500 config file, reset device to
default setting, define the mail address for notification, change the port
number of web management, change MTU value, enable RIP, SIP
pass-through function, and else.
6.3 Multiple Subnet: You can create the further subnet for LAN or DMZ
interface, and define those subnet as NAT mode or Routing mode.
6.5 DHCP: You can change DHCP client IP range for LAN or DMZ, or enable
DHCP Relay function to get the IP from upper DHCP server.
Chapter 7 Interface: This chapter is about interface configuration, and enable
Remote Management function.
Chapter 8 Address: The administrator can define the specific IP address, IP
range, IP subnet, or MAC address for the specific device in LAN, WAN, or DMZ,
so the Policy setting can be modified to restrict the service precisely.
Chapter 9 Service: In this chapter, it lists the standard protocol for user’s
reference, and it also allows user creating non-standard port number for the
request. In the end, the Address setting will be assigned to Mapped IP, Virtual
Server, or enabled by Policy setting.
Chapter 10 Schedule: This chapter can allow user defining the time schedule for
Policy setting.
Chapter 11 QoS: It is recommended to read this chapter if you would like to
configure the setting. This chapter will tell you how to configure QoS setting
correctly.
Chapter 12 Authentication: If you would like to ask user passing authentication
before to access Internet, you can read this chapter and follow the guide to
configure it.
Chapter 13 Content Blocking: You can configure the Content Blocking setting
and enable the function at Policy.
13.1 URL: You can define the key word or domain name to be blocked or be
allowed to access for the website.
13.3 Download: The specific type or extension name of files can be blocked.
AirLive RS-2500 User’s Manual
2
1. Introduction
Chapter 14 Application Blocking: You can select the application type and
software, and enable to block those applications at Policy.
Chapter 15 Virtual Server: When you install server in LAN and allow Internet
users accessing, you should define the Virtual Server function.
Chapter 16 VPN: This chapter is an introduction for IPSec and PPTP server. You
can read next chapter to know how to configure them.
Chapter 17 Configuration Example - IPSec & PPTP VPN: We list several
examples for the VPN connection, and you can find the one and refer to the
example to configure your own setting.
Chapter 18 Policy: It is recommended to read this chapter, because it is the most
important setting for RS-2500. No matter how you configure QoS, VPN, or else
function, you have to enable them at Policy setting.
Chapter 19 Configuration Example - Policy Setting: We list several Policy
setting for your reference, and you can know better how to configure it.
Chapter 20 Web VPN / SSL VPN: This chapter will explain you the Web VPN /
SSL VPN function, and we also list the example for your reference about how to
configure it.
Chapter 21 Anomaly Flow IP: This chapter is an introduction to tell user how to
configure RS-2500 for the protection from being intrusion by the known malware.
Chapter 22 Monitor:
22.1 Log: Display kinds of log records for user’s reference.
22.2 Accounting Report: Display the calculation of Internet access result per
Source IP, Destination IP, and Service.
22.3 Statistic: Display WAN or Policy Statistic result for user’s reference.
22.4 Diagnostic: RS-2500 offers Ping and Traceroute tools to diagnostic
connection’s status per WAN, LAN, DMZ, or VPN.
22.5 Wake On Lan: This chapter is an introduction about the Wake On Lan
function, so Internet user can wake on LAN PC.
22.6 Status: You can find out the real-time status about Interface,
Authentication, ARP table, and DHCP Clients.
3 AirLive RS-2500 User’s Manual
1. Introduction
1.3 Firmware Upgrade and Tech Support
If you encounter a technical issue that can not be resolved by information on this guide, we
recommend that you visit our comprehensive website support at www.airlive.com. The
tech support FAQ are frequently updated with latest information.
In addition, you might find new firmware that either increase software functions or provide
bug fixes for RS-2500. You can reach our on-line support center at the following link:
http://www.airlive.com/support/support_2.jsp
Since 2009, AirLive has added the “Newsletter Instant Support System” on our website.
AirLive Newsletter subscribers receives instant email notifications when there are new
download or tech support FAQ updates for their subscribed airlive models. To become an
AirLive newsletter member, please visit: http://www.airlive.com/member/member_3.jsp
Figure: AirLive Newsletter Support System
AirLive RS-2500 User’s Manual
4
1. Introduction
1.4 Features
Web VPN/SSL VPN, IPSec and PPTP VPN Server
VPN Trunk
Application Blocking, IM / P2P Blocking, Content Blocking
User Authentication
QoS, Max. Bandwidth Per Source IP, Max. Concurrent Sessions Per Source IP
Dual WAN Load Balance and Fail-over
Multiple Subnet
Custom Service Definition for IP, TCP, UDP
Detect and block the anomaly flow IP
Policy based Firewall
DMZ Transparent
Schedule
Static Route, RIPv2
Web Management
5 AirLive RS-2500 User’s Manual
2. Install the RS-2500
2. Installing the RS-2500
2
This section describes the hardware features and the hardware installation procedure for
the RS-2500. For software configuration, please go to chapter 3 for more details.
2.1 Before You Start
It is important to read through this section before you install the RS-2500
The RS-2500 comes with everything you need to start installation. You can use
CAT-5 Ethernet cable according to the length you need.
The RS-2500 must be installed with 5V adapter. Please do not use the other
voltage of adapter.
During upgrading firmware, please do not renew or close the webpage, otherwise
it could crash the firmware.
Please do not use FTP to transfer firmware file, because the firmware could be
transferred incompletely. If user upgrades RS-2500 with incomplete firmware it
will damage the device.
2.2 Package Content
The RS-2500 package contains the following items:
One RS-2500 main unit
One 5V 2.5A DC power adapter
2 x RJ-45 Ethernet Cable
User’s Guide CD
Quick Start Guide
AirLive RS-2500 User’s Manual
6
2.3 Knowing your RS-2500
Below are descriptions and diagrams of the product:
2. Install the RS-2500
2.4 Hardware Installation
1. Plug in power adapter to RS-2500 and
electric
3. Wait for RS-2500 Status LED to stop
blinking the light
outlet at wall
2. Connect an Ethernet cable to PC and
RS-2500 LAN port
4. PC should get the IP address from RS-2500
DHCP server, and now you can login to
RS-2500 and configure the setting.
7 AirLive RS-2500 User’s Manual
2.5 LED Table
This section describes the LED behavior of RS-2500.
You can find the LED on the Front side of the RS-2500.
Power
Steady Green – Power On device
OFF – No Power
Status
Steady Green – Ready to use
Blinking – At the booting process
WAN1/2, LAN, DMZ
Steady Green – Cable is connected
Blinking – Packets is sending/receiving
2. Install the RS-2500
2.6 Restore Settings to Default
If you have forgotten your RS-2500’s IP address or password, you can restore your
RS-2500 to the default settings by pressing on the “reset button” for more than 10 seconds.
You can find the reset button at back panel. Please see diagram below for details.
AirLive RS-2500 User’s Manual
8
3. Configuring the RS-2500
3. Configuring the
3
To use this product correctly, you have to properly configure the network settings of your
computers and install the attached setup program into your MS Windows platform
(Windows 95/98/NT/2000/XP).
RS-2500
3.1 Important Information
The following information will help you to get start quickly. However, we recommend you
to read through the entire manual before you start. Please note the password are case
sensitive.
The default IP address is: 192.168.1.1 Subnet Mask: 255.255.255.0
The default user name is: admin
The default password is: airlive
After power on, please wait for 2 minutes for RS-2500 to finish boot up
3.2 Prepare your PC
The default IP address of this product is 192.168.1.1, and the default subnet mask is
255.255.255.0. These addresses can be changed on your need, but the default values are
used in this manual. If the TCP/IP environment of your computer has not yet been
configured, you can refer to the example:
1. Configure IP as 192.168.1.2, subnet mask as 255.255.255.0 and gateway as
192.168.1.1, or more easier,
2. Configure your computers to load TCP/IP setting automatically, that is, via DHCP
server of this product.
After installing the TCP/IP communication protocol, you can use the ping command to
check if your computer has successfully connected to this product. The following example
shows the ping procedure for Windows platforms. First, execute the ping command
ping 192.168.1.1
9 AirLive RS-2500 User’s Manual
3. Configuring the RS-2500
If the following messages appear:
Pinging 192.168.1.1 with 32 bytes of data:
Reply from 192.168.1.1: bytes=32 time=2ms TTL=64
A communication link between your computer and this product has been successfully
established. Otherwise, if you get the following messages,
Pinging 192.168.1.1 with 32 bytes of data:
Request timed out.
There must be something wrong in your installation procedure. You have to check the
following items in sequence:
1. Is the Ethernet cable correctly connected between this product and your computer?
Tip: The LAN LED of this product and the link LED of network card on your computer must
be lighted.
2. Is the TCP/IP environment of your computers properly configured?
Tip: If the IP address of this product is 192.168.1.1, the IP address of your computer must
be 192.168.1.X and default gateway must be 192.168.1.1.
3.3 Management Interface
The RS-2500 can be configured using one the management interfaces below:
Web Management (HTTP): You can manage your RS-2500 by simply typing its IP
address in the web browser. We recommend using this interface for initial
configurations. To begin, simply enter RS-2500 IP address (default is 192.168.1.1) on
the web browser. The default password is “airlive”.
Secure Web Management (HTTPS): HTTPS is also using web browser for
configuration. But all the data transactions are securely encrypted using SSL
encryption. Therefore it is safe and easy way to manage your RS-2500.
AirLive RS-2500 User’s Manual
10
3. Configuring the RS-2500
3.4 Introduction to Web Management
The RS-2500 offers both normal (http) and secured (https) Web Management interfaces.
Their share the same interface and functions, and they can both be accessed through web
browsers. The only difference is HTTPS are encrypted for extra security. Therefore, we
will discuss them together as “Web Management” on this guide.
If you are placing the RS-2500 behind router or firewall, you might need to open virtual
server ports to RS-2500 on your firewall/router
HTTP: TCP Port 80
HTTPS: TCP/UDP Port 443
3.4.1 Getting into Web Management
Normal Web Management (HTTP)
To get into the Normal Web Management, simply type in the RS-2500’s IP address (default
IP is 192.168.1.1) into the web browser’s address field.
11 AirLive RS-2500 User’s Manual
3. Configuring the RS-2500
Secured Web Management (HTTPS)
To get into the Secured Web Management, just type “https://192.168.1.1” into the web
browser’s address field. The “192.168.1.1” is RS-2500’s default IP address. If the IP
address is changed, the address entered in the browser should change also.
A security warning screen from your browser will then pop-up depending on the browser
you use. Please follow step below to clear the security screen.
Internet Explorer: Select “Yes” to proceed
Firefox:
1. Select “or you can add an exception”
1
AirLive RS-2500 User’s Manual
12
3. Configuring the RS-2500
2. Click on “Add Exception”
2
3. Click on “Get Certificate”. Then, please enter RS-2500’s IP address. Finally,
please click on “Confirm Security Exception.”
3
4
13 AirLive RS-2500 User’s Manual
3. Configuring the RS-2500
3.5 Initial Configurations
We recommend users to browse through RS-2500’s web management interface to get an
overall picture of the functions and interface. Below are the recommended initial
configurations for first time login:
STEP 1:
1. Connect the Admin’s PC and the LAN port of the Security VPN Gateway.
2. Open an Internet web browser and type the default IP address of the Security VPN
Gateway as 192.168.1.1 in the address bar.
3. A pop-up screen will appear and prompt for a username and password. Enter the
default login username (admin) and password (airlive) of Administrator.
STEP 2:
After entering the username and password, the Security VPN Gateway WEB UI screen will
display. Select the Interface tab on the left menu and a sub-function list will be displayed.
Click on WAN from the sub-function list, enter proper the network setup information
Click Modify to modify WAN1/2 settings (i.e. WAN1 Interface)
WAN1 interface IP Address 60.250.158.64
NetMask 255.255.255.0
Default Gateway 60.250.158.254
DNS Server1 168.95.1.1
AirLive RS-2500 User’s Manual
14
3. Configuring the RS-2500
STEP 3:
Click on the Policy tab from the main function menu, and then click on Outgoing from the
sub-function list.
STEP 4:
Click on New Entry button.
STEP 5:
When the New Entry option appears, enter the following configuration:
Source Address – select Inside_Any
Destination Address – select Outside_Any
Service - select ANY
Action - select Permit ALL
Click on OK to apply the changes.
15 AirLive RS-2500 User’s Manual
3. Configuring the RS-2500
STEP 6:
The configuration is successful when the screen below is displayed. Make sure that all the
computers that are connected to the LAN port have their Default Gateway IP Address set to
the Security VPN Gateway’s LAN IP Address (i.e. 192.168.1.1). At this point, all the
computers on the LAN network should gain access to the Internet immediately.
AirLive RS-2500 User’s Manual
16
4. Web Management
4. Web Management
4
In this chapter, we will explain about the Administration settings in web management
interface. Please be sure to read through Chapter 3’s “Introduction to Web Management”
and “Initial Configurations” first.
4.1 About RS-2500’s Menu Structure
The RS-2500’s web management menu is divided into 7 main subjects: System, Interface,
Policy Object, Policy, Web VPN / SSL VPN, Anomaly IP Flow, and Monitor. Each subject
includes several sub-object settings, and each sub-object also includes several functions
for user’s configuration.
RS-2500 was designed as the policy based firewall, it means user should configure Policy Object setting, and enable the function at Policy.
Main Subject
Sub-Object
Functions
System: It includes Administration, Configure, and Logout sub-objects. The
System subject allows you configuring basic setting of the RS-2500. Please refer to
chapter 5 Administration and chapter 6 Configure.
Interface: It includes WAN, LAN and DMZ sub-objects. For more configuration
information please refer to chapter 7.
AirLive RS-2500 User’s Manual
18
4. Web Management
Policy Object: It includes Address, Service, Schedule, QoS, Authentication,
Content Blocking, Application Blocking, Virtual Server, and VPN sub-objects.
Before to enable the function at Policy, you need to configure the Policy Object
setting first. Please refer to chapter 8 ~ 17.
Policy: It includes Outgoing, Incoming, WAN To DMZ, LAN To DMZ, DMZ To
WAN, and DMZ To LAN sub-objects. Please make sure to Logout after you finish
all settings. You must configure Policy setting to enable the Policy Object settings.
Please refer to chapter 18.
Web VPN / SSL VPN: RS-2500 provides Web VPN / SSL VPN function to allow
remote user connecting and accessing to router’s LAN resource. Please refer to
chapter 20.
Anomaly IP Flow: It works to define the rule to block hacker from Internet or
Intranet. Please refer to chapter 21.
Monitor: It includes Log, Accounting Report, Statistic, Diagnostic, Wake on Lan,
and Status sub-objects. The function works to offer the report or log for user to
realize device and network’s current status. Please refer to chapter 22.
4.2 Remote Web Management
RS-2500 allows you accessing the web management page from remote site, and you can
choose to use HTTP or HTTPS. In Interface WAN, enable HTTP or HTTPS or both.
19 AirLive RS-2500 User’s Manual
5. Administration
5. Administration
5
“System” is the managing of settings such as the privileges of packets that pass through
the RS-2500 and monitoring controls. The System Administrators can manage, monitor,
and configure RS-2500 settings. But all configurations are “read-only” for all users other
than the System Administrator; those users are not able to change any setting of the
RS-2500.
5.1 Admin
Admin Name: The username of Administrators and Sub Administrator for the RS-2500.
The admin user name cannot be removed; and the sub-admin user can be removed or
modified.
The default Account: admin; Password: airlive
Privilege: The privileges of Administrators (Admin or Sub Admin). The username of
the main Administrator is Administrator with reading / writing privilege. Administrator
also can change the system setting, log system status, and to increase or delete
sub-administrator. Sub-Admin may be created by the Admin by clicking New Sub Admin. Sub Admin have only read and monitor privilege and cannot change any
system setting value.
Configure: Click Modify to change the “Sub-Administrator’s” password or click
Remove to delete a “Sub Administrator.”
AirLive RS-2500 User’s Manual
20
Adding a new Sub Administrator
5. Administration
STEP 1
STEP 2
STEP 3
﹒
In the Admin WebUI, click the New Sub Admin button to create a new Sub
Administrator.
﹒
In the Add New Sub Administrator WebUI (Figure 5-1) and enter the following
setting:
Add the following setting in Permitted IPs of Administration: (Figure 5-3)
Name: Enter master
IP Address: Enter 163.173.56.11
Netmask: Enter 255.255.255.255
Service: Select Ping, HTTP and HTTPS
Click OK
Complete add new permitted IPs (Figure 5-4)
Figure 5-3 Setting Permitted IPs WebUI
To make Permitted IPs be effective, it is suggested to cancel the Ping,
HTTP, and HTTPS selection in LAN, WAN, or DMZ Interface setting.
Before canceling the WebUI selection of Interface, user must set up
the Permitted IPs first, otherwise, it would cause the situation that
user cannot enter WebUI by appointed Interface.
AirLive RS-2500 User’s Manual
Figure 5-4 Complete Add New Permitted IPs
22
5.3 Software Update
5. Administration
STEP 1
﹒
Select Software Update in System, and follow the steps below:
To obtain the version number from Version Number and obtain the latest
version from Internet. And save the latest version in the hardware of the PC,
which manage the RS-2500
Click Browse and choose the latest software version file.
Click OK and the system will update automatically. (Figure 5-5)
Figure 5-5 Software Update
It takes 4 minutes to update software. The system will reboot after
update. During the updating time, please don’t turn off the PC or close
WebUI. It may cause some unexpected mistakes. (Strong suggests
updating the software from LAN to avoid unexpected mistakes.)
5.4 Logout
STEP 1
STEP 2
﹒
Click Logout in System to protect the system while admin is away. (Figure 5-6)
﹒
Click OK and the logout message will appear in WebUI. (Figure 5-7)
Figure 5-6 Confirm Logout WebUI
Figure 5-7 Logout WebUI Message
23 AirLive RS-2500 User’s Manual
6. Configure
6. Configure
6
The Configure is according to the basic setting of the RS-2500. In this chapter the definition
is Setting, Date/Time, Multiple Subnet, Route Table, DHCP, Dynamic DNS, Hosts Table,
and Language settings.
6.1 Setting
System Settings- Exporting
STEP 1
STEP 2
﹒
In System Setting WebUI, click on button next to Export System
Setting to Client.
﹒
When the File Download pop-up window appears, choose the destination place
where to save the exported file and click on Save. The setting value of RS-2500
will copy to the appointed site instantly. (Figure 6-1)
Figure 6-1 Select the Destination Place to Save the Exported File
AirLive RS-2500 User’s Manual
24
System Settings- Importing
6. Configure
STEP 1
STEP 2
﹒
In System Setting WebUI, click on the Browse button next to Import System
Setting from Client. When the Choose File pop-up window appears, select the file to which contains the saved RS-2500 Settings, then click OK. (Figure 6-2)
﹒
Click OK to import the file into the RS-2500 (Figure 6-3)
Figure 6-2 Enter the File Name and Destination of the Imported File
Figure 6-3 Upload the Setting File WebUI
25 AirLive RS-2500 User’s Manual
Loading...
+ 217 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.